WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,901–8,950 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 179 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.7 Medium Sassy Social Share Plugin sassy-social-share Open Redirect No login needed ≤ 3.3.73 Fixed in 3.3.74 CVE-2025-39404 Patchstack
9.9 Critical PowerPress Podcasting Plugin powerpress Arbitrary File Upload ≤ 11.12.5 Fixed in 11.12.6 CVE-2025-46264 Patchstack
7.1 High BruteGuard – Brute Force Login Protection Plugin bruteguard Cross-Site Scripting Brute Force Login Protection plugin <= 0.1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.4 CVE-2025-39408 Patchstack
7.1 High Control Listings Plugin control-listings Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4.1 Fixed in 1.0.5 CVE-2025-46234 Patchstack
7.5 High Popup Builder Plugin easy-notify-lite Local File Inclusion ≤ 1.1.35 Fixed in 1.1.37 CVE-2025-46230 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 3.0.1 Fixed in 3.0.3 CVE-2025-46260 Patchstack
9.3 Critical Frontend Dashboard Plugin frontend-dashboard SQL Injection No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-46248 Patchstack
5.9 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting ≤ 3.9.0 Fixed in 3.10.0 CVE-2025-46261 Patchstack
5.3 Medium Reales WP - Real Estate Theme Broken Access Control Real Estate WordPress Theme <= 2.1.2 - Missing Authorization to Unauthenticated Attachment Deletion and Favorite Property Updates No login needed ≤ 2.1.2 CVE-2024-13307 Wordfence
7.5 High WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Price Manipulation Unauthenticated Product Price Manipulation No login needed ≤ 5.1.2 CVE-2025-3530 Wordfence
8.2 High WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Information Disclosure Unauthenticated Information Exposure via file_url Parameter No login needed ≤ 5.1.2 CVE-2025-3529 Wordfence
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.10.0 Fixed in 45.11.0 CVE-2025-46254 Patchstack
6.5 Medium GutenKit Plugin gutenkit-blocks-addon Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-46253 Patchstack
7.6 High Message Filter for Contact Form 7 Plugin cf7-message-filter SQL Injection ≤ 1.6.3.2 Fixed in 1.6.3.3 CVE-2025-46252 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.3 Fixed in 1.4 CVE-2025-46251 Patchstack
5.9 Medium VPSUForm Plugin v-form Cross-Site Scripting ≤ 3.1.14 Fixed in 3.1.15 CVE-2025-46250 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-46249 Patchstack
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46247 Patchstack
4.3 Medium CM Answers Plugin cm-answers Cross-Site Request Forgery No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-46246 Patchstack
4.3 Medium CM Ad Changer Plugin cm-ad-changer Cross-Site Request Forgery No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-46245 Patchstack
5.3 Medium Advanced Linked Variations for Woocommerce Plugin linked-variation Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-46244 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
7.6 High Watu Quiz Plugin watu SQL Injection ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-46242 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
6.5 Medium Simple Download Counter Plugin simple-download-counter Cross-Site Scripting ≤ 2.2 Fixed in 2.2.1 CVE-2025-46240 Patchstack
6.5 Medium Theme Switcha Plugin theme-switcha Cross-Site Scripting ≤ 3.4 Fixed in 3.4.1 CVE-2025-46239 Patchstack
6.5 Medium List Last Changes Plugin list-last-changes Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-46238 Patchstack
6.5 Medium Link Library Plugin link-library Cross-Site Scripting ≤ 7.8 Fixed in 7.8.1 CVE-2025-46237 Patchstack
6.5 Medium HTML Forms Plugin html-forms Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-46236 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 2.1 CVE-2025-46235 Patchstack
6.5 Medium Sirv Plugin sirv Cross-Site Scripting ≤ 7.5.3 Fixed in 7.5.4 CVE-2025-46233 Patchstack
4.3 Medium Download Alt Text AI Plugin alttext-ai Broken Access Control ≤ 1.9.93 Fixed in 1.9.94 CVE-2025-46232 Patchstack
5.4 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Cross-Site Request Forgery No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-46231 Patchstack
5.9 Medium Textmetrics Plugin webtexttool Cross-Site Scripting ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-46229 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.9.11 Fixed in 5.10.0 CVE-2025-46228 Patchstack
6.5 Medium Custom Related Posts Plugin custom-related-posts Cross-Site Scripting ≤ 1.7.4 Fixed in 1.7.5 CVE-2025-46227 Patchstack
6.5 Medium MPL-Publisher Plugin mpl-publisher Cross-Site Scripting ≤ 2.18.0 Fixed in 2.18.1 CVE-2025-46226 Patchstack
6.5 Medium Post in page for Elementor Plugin post-in-page-for-elementor Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-46225 Patchstack
9.8 Critical Wordpress Plugin Smart Product Review Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2021-4455 Wordfence
4.8 Medium MapPress Maps Plugin Cross-Site Scripting Admin+ Stored XSS 2.94.9 – < 2.94.10 Fixed in 2.94.10 CVE-2025-2162 WPScan
7.1 High Modal Survey Plugin modal-survey Cross-Site Scripting No login needed ≤ 2.0.2.0.1 CVE-2025-39469 Patchstack
8.1 High Ivy School Plugin ivy-school Local File Inclusion No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-39470 Patchstack
9.3 Critical Modal Survey Plugin modal-survey SQL Injection No login needed ≤ 2.0.2.0.1 CVE-2025-39471 Patchstack
7.1 High visualslider Sldier Plugin visual-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.4 CVE-2025-23448 Patchstack
7.1 High Author Showcase Plugin author-showcase Cross-Site Scripting No login needed ≤ 1.4.3 CVE-2025-23443 Patchstack
6.5 Medium Delete All Posts Plugin delele-all Broken Access Control No login needed ≤ 1.1.1 CVE-2025-23773 Patchstack
7.1 High SpiderDisplay Plugin spiderdisplay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23855 Patchstack
7.1 High TotalContest Lite Plugin totalcontest-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.1 Fixed in 2.9.0 CVE-2025-23782 Patchstack
7.1 High Custom Users Order Plugin custom-users-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2 CVE-2025-23858 Patchstack
6.5 Medium WordPress Dashboard Tweeter Plugin wordpress-dashboard-twitter Broken Access Control Settings Change No login needed ≤ 1.3.2 CVE-2025-23906 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only