WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,401–9,450 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 189 of 594
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Makesweat Plugin makesweat Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'makesweat_clubid' Setting ≤ 0.1 CVE-2025-13627 Wordfence
5.3 Medium Netcash WooCommerce Payment Gateway Plugin netcash-pay-now-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 4.1.3 CVE-2025-14880 Wordfence
4.3 Medium Crush.pics Image Optimizer Plugin crush-pics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update ≤ 1.8.7 CVE-2025-14482 Wordfence
4.9 Medium Shipping Rates by City for WooCommerce Plugin flat-shipping-rate-by-city-for-woocommerce SQL Injection Authenticated (Shop Manager+) SQL Injection via 'cities' Parameter ≤ 1.0.3 CVE-2026-0678 Wordfence
4.3 Medium Responsive Accordion Slider Plugin responsive-accordion-slider Broken Access Control Missing Authorization to Authenticated (Contributor+) Slider Update via 'resp_accordion_silder_save_images' ≤ 1.2.2 CVE-2026-0635 Wordfence
7.2 High AJS Footnotes Plugin ajs-footnotes Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-15378 Wordfence
6.4 Medium SearchWiz Plugin searchwiz Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 1.0.0 CVE-2026-0694 Wordfence
7.2 High Name Directory Plugin name-directory Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 1.30.3 CVE-2025-15283 Wordfence
4.4 Medium Testimonials Creator Plugin testimonials-creator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting 1.6 CVE-2025-14379 Wordfence
4.3 Medium Sosh Share Buttons Plugin sosh-share-buttons Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-15377 Wordfence
4.4 Medium Real Post Slider Lite Plugin real-post-slider-lite Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings ≤ 2.4 CVE-2026-0680 Wordfence
4.4 Medium Internal Link Builder Plugin internal-link-builder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Settings ≤ 1.0 CVE-2025-14725 Wordfence
9.8 Critical Integration Opvius AI for WooCommerce Plugin woosa-ai-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion/Read via Path Traversal No login needed ≤ 1.3.0 CVE-2025-14301 Wordfence
5.3 Medium LottieFiles – Lottie block for Gutenberg Plugin lottiefiles Information Disclosure Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.0.0 CVE-2026-0717 Wordfence
4.3 Medium WPBlogSyn Plugin wpblogsync Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Remote Sync Configuration Update No login needed ≤ 1.0 CVE-2025-14389 Wordfence
7.1 High DASHBOARD BUILDER Plugin dashboard-builder Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed ≤ 1.5.7 CVE-2025-14615 Wordfence
6.1 Medium List Site Contributors Plugin list-site-contributors Cross-Site Scripting Reflected Cross-Site Scripting via alpha No login needed ≤ 1.1.8 CVE-2026-0594 Wordfence
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting No login needed 11.4 CVE-2023-54332 VulnCheck
6.1 Medium WPForms Plugin wpforms-lite Cross-Site Scripting No login needed ≤ 1.7.8 CVE-2020-36919 VulnCheck
5.3 Medium EventPrime - Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Information Disclosure Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.0 CVE-2025-14507 Wordfence
4.3 Medium CP Image Store with Slideshow Plugin cp-image-store Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import ≤ 1.1.9 CVE-2026-0684 Wordfence
5.4 Medium WP Duplicate Page Plugin wp-duplicate-page Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication ≤ 1.8 CVE-2025-14001 Wordfence
9.1 Critical e-xact-hosted-payment Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.0 CVE-2025-14829 WPScan
9.8 Critical Dreamer Blog Theme Broken Access Control Subscriber+ Arbitrary Plugin Installation ≤ 1.2 CVE-2025-10915 WPScan
4.8 Medium Quiz Maker Plugin quiz-maker Cross-Site Scripting Admin+ Stored XSS < 6.7.0.89 Fixed in 6.7.0.89 CVE-2025-14579 WPScan
4.3 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url' ≤ 5.3.1 CVE-2025-13393 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget ≤ 2.17.13 Fixed in 2.17.14 CVE-2025-12379 Wordfence
6.4 Medium Countdown Timer - Widget Countdown Plugin widget-countdown Cross-Site Scripting Widget Countdown <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.7.7 CVE-2025-14555 Wordfence
6.4 Medium ConvertForce Popup Builder Plugin convertforce-popup-builder Cross-Site Scripting Stored Cross-Site Scripting via entrance_animation ≤ 0.0.7 CVE-2025-14506 Wordfence
5.3 Medium Templately Plugin templately Broken Access Control Unauthenticated Limited Arbitrary JSON File Write No login needed ≤ 3.4.8 CVE-2026-0831 Wordfence
5.4 Medium User Registration & Membership Plugin user-registration Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 4.4.8 Fixed in 4.4.9 CVE-2025-14976 Wordfence
5.3 Medium miniOrange OTP Verification and SMS Notification for WooCommerce Plugin miniorange-sms-order-notification-otp-verification Broken Access Control Missing Authorization to Unauthenticated Notification Settings Modification No login needed ≤ 4.3.8 CVE-2025-14948 Wordfence
4.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 8.7.2 CVE-2025-14943 Wordfence
7.5 High WooCommerce Square Plugin woocommerce-square Broken Access Control Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id No login needed 4.2.0 – < 4.2.3, 4.3.0 – < 4.3.2, 4.4.0 – < 4.4.2, … Fixed in 4.2.3 CVE-2025-13457 Wordfence
9.3 Critical AccessAlly Plugin Remote Code Execution AccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution No login needed < 3.3.2 Fixed in 3.3.2 CVE-2020-36875 VulnCheck
6.4 Medium Header and Footer Scripts Plugin header-and-footer-scripts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 Fixed in 2.4.1 CVE-2025-11453 Wordfence
6.4 Medium The Tooltip Plugin the-tooltip Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.2 CVE-2025-13908 Wordfence
6.4 Medium Menu Card Plugin menu-card Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.8.0 CVE-2025-13862 Wordfence
6.5 Medium WP Page Permalink Extension Plugin change-wp-page-permalinks Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Rewrite Rules Flush ≤ 1.5.4 CVE-2025-14172 Wordfence
5.3 Medium Contact Form vCard Generator Plugin contact-form-vcard-generator Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'wp-gvc-cf-download-id' Parameter No login needed ≤ 2.4 CVE-2025-13717 Wordfence
6.4 Medium Autogen Headers Menu Plugin autogen-headers-menu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'head_class' Shortcode Parameter ≤ 1.0.1 CVE-2025-13704 Wordfence
6.4 Medium Client Testimonial Slider Plugin wp-client-testimonial Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aft_testimonial_meta_name' Metabox Field ≤ 2.0 CVE-2025-13897 Wordfence
6.1 Medium MG AdvancedOptions Plugin mg-advancedoptions Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-13892 Wordfence
6.4 Medium Curved Text Plugin curved-text Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.1 CVE-2025-13854 Wordfence
6.1 Medium Shabat Keeper Plugin shabat-keeper Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.4.4 CVE-2025-13701 Wordfence
6.4 Medium Woodpecker Plugin woodpecker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_name' Shortcode Attribute ≤ 3.0.4 CVE-2025-13967 Wordfence
6.4 Medium Debt.com Business in a Box Plugin debtcom-business-in-a-box Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.1.0 CVE-2025-13852 Wordfence
6.4 Medium PullQuote Plugin pullquote Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2025-13903 Wordfence
6.1 Medium Lesson Plan Book Plugin lesson-plan-book Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-13893 Wordfence
6.1 Medium Top Position Google Finance Plugin top-position-google-finance Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.1.0 CVE-2025-13895 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only