WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,951–9,000 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 180 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Editor Wysiwyg Background Color Plugin editor-wysiwyg-background-color Broken Access Control No login needed ≤ 1.0 CVE-2025-23958 Patchstack
7.1 High DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.5 Fixed in 5.6.6 CVE-2025-24539 Patchstack
7.1 High Autoglot – Automatic WordPress Translation Plugin autoglot Cross-Site Scripting Automatic WordPress Translation plugin <=2.4.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2025-24548 Patchstack
6.5 Medium Job Manager Plugin job-manager-by-jobscore Cross-Site Scripting ≤ 2.2 Fixed in 2.3 CVE-2025-24550 Patchstack
7.1 High Shipping with Venipak for WooCommerce Plugin wc-venipak-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.3 Fixed in 1.22.5 CVE-2025-24553 Patchstack
6.5 Medium Instantio Plugin instantio Broken Access Control Settings Change No login needed ≤ 3.3.7 Fixed in 3.3.8 CVE-2025-24581 Patchstack
6.5 Medium Poll Maker Plugin poll-maker Broken Access Control No login needed ≤ 5.5.0 Fixed in 5.5.1 CVE-2025-24577 Patchstack
6.5 Medium 12 Step Meeting List Plugin 12-step-meeting-list Broken Access Control Settings Change No login needed ≤ 3.16.5 Fixed in 3.16.6 CVE-2025-24583 Patchstack
7.1 High WP Log Action Plugin wp-log-action Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.51 Fixed in 0.52 CVE-2025-24619 Patchstack
7.1 High Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.23 Fixed in 1.4.23.1 CVE-2025-24586 Patchstack
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-24621 Patchstack
7.1 High Beacon Lead Magnets and Lead Capture Plugin beacon-by Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-24637 Patchstack
7.1 High HT Event Plugin ht-event Cross-Site Scripting WordPress Event Manager Plugin for Elementor Plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-24624 Patchstack
7.1 High Empty Tags Remover Plugin empty-tags-remover Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.1.0 CVE-2025-24640 Patchstack
5.9 Medium WordPress Backup & Migration Plugin wp-migration-duplicator Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-24651 Patchstack
7.1 High Eazy Under Construction Plugin eazy-under-construction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 2.0 CVE-2025-24645 Patchstack
7.1 High Term Taxonomy Converter Plugin term-taxonomy-converter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-24670 Patchstack
7.1 High Wishlist Plugin wishlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.39 Fixed in 1.0.40 CVE-2025-24655 Patchstack
6.5 Medium WP Helper Premium Plugin wp-helper-lite Broken Access Control No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-24737 Patchstack
7.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.14 Fixed in 6.0.15 CVE-2025-24752 Patchstack
7.1 High Classified Listing Plugin classified-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-24745 Patchstack
6.5 Medium Theme File Duplicator Plugin theme-file-duplicator Path Traversal Arbitrary File Download ≤ 1.3 CVE-2025-27283 Patchstack
9.9 Critical Theme File Duplicator Plugin theme-file-duplicator Arbitrary File Upload ≤ 1.3 CVE-2025-27282 Patchstack
7.1 High Flagged Content Plugin flagged-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-27284 Patchstack
9.8 Critical Saoshyant Slider Plugin saoshyant-slider PHP Object Injection No login needed ≤ 3.0 CVE-2025-27286 Patchstack
7.1 High Easy Form Plugin easy-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-27285 Patchstack
7.1 High File Icons Plugin file-icons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-27288 Patchstack
9.8 Critical SS Quiz Plugin ssquiz PHP Object Injection No login needed ≤ 2.0.5 CVE-2025-27287 Patchstack
7.1 High Restrict Taxonomies Plugin restrict-taxonomies Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-27289 Patchstack
7.1 High WPYog Documents Plugin wpyog-documents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-27292 Patchstack
7.1 High WordPress Photo Gallery – Image Gallery Plugin photo-image-gallery Cross-Site Scripting Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-27291 Patchstack
7.1 High Live css Plugin css-live Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-27295 Patchstack
7.1 High Shipmozo Courier Tracking Plugin webparex Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-27293 Patchstack
5.3 Medium MyTicket Events Plugin myticket-events Path Traversal Non-Arbitrary File Read No login needed ≤ 1.2.4 CVE-2025-27299 Patchstack
7.1 High WP Video Posts Plugin wp-video-posts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.1 CVE-2025-27308 Patchstack
9.3 Critical CHATLIVE Plugin chatlive SQL Injection No login needed ≤ 2.0.1 CVE-2025-27302 Patchstack
7.1 High flickr-slideshow-wrapper Plugin flickr-slideshow-wrapper Cross-Site Scripting No login needed ≤ 5.4.6 CVE-2025-27309 Patchstack
7.1 High Google Maps GPX Viewer Plugin google-maps-gpx-viewer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6 CVE-2025-27313 Patchstack
6.5 Medium Page and Post Lister Plugin page-and-post-lister Broken Access Control Arbitrary Content Deletion ≤ 1.2.1 CVE-2025-27310 Patchstack
7.1 High Kush Micro News Plugin kush-micro-news Cross-Site Scripting No login needed ≤ 1.6.7 CVE-2025-27314 Patchstack
7.1 High QR Code for WooCommerce Plugin wc-qr-codes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-27322 Patchstack
7.1 High User List Plugin user-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-27319 Patchstack
7.1 High 17TRACK for WooCommerce Plugin 17track Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 CVE-2025-27324 Patchstack
7.1 High Fontsampler Plugin fontsampler Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.14 CVE-2025-27337 Patchstack
7.1 High Protected wp-login Plugin protected-wp-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-27333 Patchstack
7.1 High List Urls Plugin list-urls Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-27338 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.1.20 CVE-2025-27345 Patchstack
7.1 High WooCommerce HTML5 Video Plugin woocommerce-html5-video Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.10 CVE-2025-27343 Patchstack
7.1 High Simple Email Subscriber Plugin simple-email-subscriber Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-27354 Patchstack
7.1 High Rebuild Permalinks Plugin rebuild-permalinks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-27346 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only