WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,001–9,050 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 181 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Activity Reactions For Buddypress Plugin activity-reactions-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.22 CVE-2025-31006 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion Local File Inclusion via CSRF No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-31030 Patchstack
7.1 High FireDrum Email Marketing Plugin firedrum-email-marketing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.64 Fixed in 1.65 CVE-2025-31018 Patchstack
9.8 Critical Paid Videochat Turnkey Site Plugin ppv-live-webcams Authentication Bypass Broken Authentication No login needed ≤ 7.3.11 Fixed in 7.3.12 CVE-2025-31380 Patchstack
7.1 High Silvasoft boekhouden Plugin silvasoft-boekhouden Cross-Site Scripting No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-32504 Patchstack
7.1 High wp secure Plugin wp-secure-by-sitesecuritymonitorcom Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-32490 Patchstack
7.1 High Event Espresso – Custom Email Template Shortcode Plugin email-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-32507 Patchstack
7.1 High AT Internet SmartTag Plugin at-internet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-32506 Patchstack
7.1 High Course Booking System Plugin course-booking-system Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-32508 Patchstack
7.1 High Revamp CRM for WooCommerce Plugin revampcrm-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-32512 Patchstack
7.1 High Make Email Customizer for WooCommerce Plugin make-email-customizer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 CVE-2025-32511 Patchstack
7.1 High WooCommerce Estimate and Quote Plugin wc-estimate-and-quote Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2.5 CVE-2025-32514 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack
7.1 High Terminal Africa Plugin terminal-africa Cross-Site Scripting No login needed ≤ 1.13.24 CVE-2025-32515 Patchstack
7.1 High WordPress Health and Server Condition – Integrated with Google Page Speed Plugin wp-condition Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.1 CVE-2025-32520 Patchstack
7.1 High Related Videos for JW Player Plugin related-videos-for-jw-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-32516 Patchstack
7.1 High Cool Flipbox – Shortcode & Gutenberg Block Plugin flip-boxes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-32521 Patchstack
7.1 High Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting No login needed ≤ 3.3.101 Fixed in 3.3.102 CVE-2025-32526 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-32522 Patchstack
7.1 High T&P Gallery Slider Plugin tp-gallery-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-32527 Patchstack
7.1 High iONE360 configurator Plugin ione360-configurator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.57 CVE-2025-32529 Patchstack
7.1 High iCal Feeds Plugin ical-feeds Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32528 Patchstack
7.1 High Arconix FAQ Plugin arconix-faq Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-32531 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2025-32530 Patchstack
7.1 High UXsniff Plugin ux-sniff Cross-Site Scripting No login needed ≤ 1.3.3 CVE-2025-32532 Patchstack
7.1 High DN Shipping by Weight for WooCommerce Plugin dn-shipping-by-weight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-32535 Patchstack
7.1 High Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.7 Fixed in 2.2.0 CVE-2025-32533 Patchstack
7.1 High Feedify – Web Push Notifications Plugin push-notification-by-feedify Cross-Site Scripting Web Push Notifications plugin <= 2.4.5 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-32540 Patchstack
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack
7.5 High WooCommerce Loyal Customers Plugin woocommerce-loyal-customer Broken Access Control No login needed ≤ 2.6 CVE-2025-32544 Patchstack
7.1 High All push notification for WP Plugin all-push-notification Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32546 Patchstack
7.1 High MSRP (RRP) Pricing for WooCommerce Plugin msrp-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 Fixed in 2.0.0 CVE-2025-32552 Patchstack
7.1 High Hamburger Icon Menu Lite Plugin hamburger-icon-menu-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-32548 Patchstack
7.1 High WP Featured Screenshot Plugin wp-featured-screenshot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-32557 Patchstack
7.1 High Raptive Ads Plugin adthrive-ads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-32554 Patchstack
7.1 High WP_DEBUG Toggle Plugin enable-wp-debug-toggle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-32561 Patchstack
7.1 High WP-Hijri Plugin wp-hijri Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32560 Patchstack
7.1 High WP Easy Poll Plugin wp-easy-poll-afo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.9 CVE-2025-32562 Patchstack
7.1 High License For Envato Plugin license-envato Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 Fixed in 1.1.0 CVE-2025-32566 Patchstack
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.24 CVE-2025-32564 Patchstack
8.8 High TuriTop Booking System Plugin turitop-booking-system PHP Object Injection ≤ 1.0.10 CVE-2025-32571 Patchstack
8.5 High KiotViet Sync Plugin kiotvietsync SQL Injection ≤ 1.8.3 CVE-2025-32573 Patchstack
9.8 Critical Kata Plus Plugin kata-plus PHP Object Injection No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-32572 Patchstack
7.1 High WP AutoKeyword Plugin wp-autokeyword Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-32582 Patchstack
7.1 High Coming Soon Countdown Plugin coming-soon-countdown Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-32578 Patchstack
9.9 Critical PDF 2 Post Plugin pdf2post Remote Code Execution ≤ 2.4.0 CVE-2025-32583 Patchstack
7.1 High Web2application Plugin web2application Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1 CVE-2025-32590 Patchstack
7.1 High Credova_Financial Plugin credova-financial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-32588 Patchstack
8.2 High Add Product Frontend for WooCommerce Plugin add-product-frontend-for-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.8 CVE-2025-32593 Patchstack
7.1 High TableOn Plugin posts-table-filterable Cross-Site Scripting No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-32592 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only