WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,201–9,250 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 185 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Checkout for PayPal Plugin checkout-for-paypal Cross-Site Scripting ≤ 1.0.38 Fixed in 1.0.39 CVE-2025-39572 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control ≤ 4.2.4 Fixed in 4.2.5 CVE-2025-39571 Patchstack
6.5 Medium Uix Shortcodes Plugin uix-shortcodes Cross-Site Scripting ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-39574 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.10 Fixed in 1.3.11 CVE-2025-39573 Patchstack
6.5 Medium WPCasa Plugin wpcasa Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-39575 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-39577 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-39576 Patchstack
6.5 Medium Membership For WooCommerce Plugin membership-for-woocommerce Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2025-39579 Patchstack
6.5 Medium Responsive Blocks Plugin responsive-block-editor-addons Cross-Site Scripting ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-39578 Patchstack
6.5 Medium Themify Shortcodes Plugin themify-shortcodes Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-39581 Patchstack
6.5 Medium WP Data Access Plugin wp-data-access Cross-Site Scripting ≤ 5.5.36 Fixed in 5.5.37 CVE-2025-39582 Patchstack
6.5 Medium Travelfic Toolkit Plugin travelfic-toolkit Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.3 CVE-2025-39585 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion ≤ 4.0.25 Fixed in 4.0.26 CVE-2025-39584 Patchstack
4.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Information Disclosure Sensitive Data Exposure ≤ 6.1.9 Fixed in 6.1.10 CVE-2025-39589 Patchstack
5.4 Medium WP Subscription Forms Plugin wp-subscription-forms Broken Access Control ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-39591 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.1.9 Fixed in 6.1.10 CVE-2025-39590 Patchstack
4.3 Medium Ever Accounting Plugin wp-ever-accounting Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-39593 Patchstack
7.5 High Subscribe to Unlock Lite Plugin subscribe-to-unlock-lite Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-39592 Patchstack
4.7 Medium Fast eBay Listings Plugin fast-ebay-listings Open Redirect No login needed ≤ 2.12.15 Fixed in 2.12.16 CVE-2025-39597 Patchstack
4.9 Medium Administrator Z Plugin administrator-z Path Traversal Directory Traversal ≤ 2025.03.28 Fixed in 2025.03.30 CVE-2025-39598 Patchstack
4.3 Medium Integration for WooCommerce and QuickBooks Plugin wp-woocommerce-quickbooks Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-39600 Patchstack
4.7 Medium Listdom Plugin listdom Open Redirect No login needed ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-39599 Patchstack
9.6 Critical Custom CSS, JS & PHP Plugin custom-css Cross-Site Request Forgery CSRF to RCE No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-39601 Patchstack
4.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2025-39602 Patchstack
8.3 High FS Poster Plugin fs-poster Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 6.5.8 Fixed in 7.1.8 CVE-2025-30960 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.1 CVE-2025-32923 Patchstack
7.1 High SEO Tools Plugin seo-automatic-seo-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.7 CVE-2025-30984 Patchstack
6.5 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Cross-Site Scripting ≤ 1.0.8 CVE-2025-30982 Patchstack
7.1 High Easy Contact Plugin easy-contact Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.2 CVE-2025-30970 Patchstack
9.6 Critical WPJobBoard Plugin wpjobboard Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30967 Patchstack
5.4 Medium WPJobBoard Plugin wpjobboard Path Traversal < 5.11.1 Fixed in 5.11.1 CVE-2025-30966 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-27011 Patchstack
7.5 High Unlimited Timeline Plugin unlimited-timeline Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.1 CVE-2025-27008 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.9 CVE-2025-26998 Patchstack
6.5 Medium Sign-up Sheets Plugin sign-up-sheets Content Injection Shortcode Injection No login needed ≤ 2.3.0.1 Fixed in 2.3.1 CVE-2025-26996 Patchstack
7.5 High JetMenu Plugin jet-menu Broken Access Control No login needed ≤ 2.4.9 Fixed in 2.4.9.1 CVE-2025-26953 Patchstack
6.5 Medium C9 Blocks Plugin c9-blocks Cross-Site Scripting ≤ 1.7.7 CVE-2025-26951 Patchstack
6.5 Medium Nepali Date Converter Plugin nepali-date-converter Cross-Site Scripting ≤ 2.0.8 Fixed in 3.0.0 CVE-2025-26950 Patchstack
6.5 Medium Glossy Blog Plugin glossy-blog Cross-Site Scripting ≤ 1.0.3 CVE-2025-26934 Patchstack
6.5 Medium Home Services Plugin home-services Cross-Site Scripting ≤ 1.2.6 CVE-2025-26930 Patchstack
10.0 Critical AI Hub Plugin aihub Arbitrary File Upload No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-26927 Patchstack
6.5 Medium Tainá Plugin taina Cross-Site Scripting ≤ 0.2.5 Fixed in 0.2.5 CVE-2025-26919 Patchstack
7.6 High Kargo Entegratör Plugin kargo-entegrator SQL Injection ≤ 1.1.14 Fixed in 1.1.15 CVE-2025-26908 Patchstack
6.5 Medium WP Delete User Accounts Plugin wp-delete-user-accounts Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-26906 Patchstack
4.3 Medium InPost Gallery Plugin inpost-gallery Cross-Site Request Forgery No login needed ≤ 2.1.4.3 Fixed in 2.1.4.4 CVE-2025-26903 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.3 Fixed in 2.4 CVE-2025-26880 Patchstack
6.5 Medium JetEngine Plugin jet-engine Cross-Site Scripting ≤ 3.6.4.1 Fixed in 3.6.5 CVE-2025-26870 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-26749 Patchstack
8.1 High Arkhe Plugin arkhe Cross-Site Request Forgery CSRF to Local File Inclusion No login needed ≤ 3.12.0 CVE-2025-26748 Patchstack
7.1 High Advanced Custom Fields: Link Picker Field Plugin acf-link-picker-field Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-26746 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only