WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 901–950 of 1,928 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Year Make Model Search for WooCommerce | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.0.11 Fixed in 1.0.12 |
CVE-2025-48265 |
Patchstack | |
| 4.3 Medium | WP Mapa Politico España | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 3.8.0 Fixed in 3.8.1 |
CVE-2025-48259 |
Patchstack | |
| 4.3 Medium | Broadcast Live Video | Cross-Site Request Forgery Live Streaming : WebRTC, HLS, RTSP, RTMP plugin <= 6.2.4 - Cross Site Request Forgery (CSRF) No login needed |
≤ 6.2.4 Fixed in 6.2.5 |
CVE-2025-48255 |
Patchstack | |
| 4.3 Medium | reCAPTCHA for all | Cross-Site Request Forgery No login needed |
≤ 2.26 Fixed in 2.27 |
CVE-2025-48243 |
Patchstack | |
| 6.1 Medium | AlT Monitoring | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0.3 |
CVE-2025-4194 |
Wordfence | |
| 6.1 Medium | Audio Comments | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0.4 |
CVE-2025-4189 |
Wordfence | |
| 4.3 Medium | Seven Stars | Cross-Site Request Forgery No login needed |
≤ 1.4.4 |
CVE-2025-31068 |
Patchstack | |
| 4.3 Medium | Spare | Cross-Site Request Forgery No login needed |
≤ 1.7 |
CVE-2025-31639 |
Patchstack | |
| 4.3 Medium | WP Ultimate Tours Builder | Cross-Site Request Forgery No login needed |
≤ 1.055 |
CVE-2025-31921 |
Patchstack | |
| 5.4 Medium | Pixel WordPress Form BuilderPlugin & Autoresponder | Cross-Site Request Forgery No login needed |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2025-31915 |
Patchstack | |
| 4.3 Medium | ValidateCertify | Cross-Site Request Forgery No login needed |
≤ 1.6.4 Fixed in 1.6.5 |
CVE-2025-48115 |
Patchstack | |
| 4.3 Medium | GS Logo Slider | Cross-Site Request Forgery Settings Update via Cross-Site Request Forgery No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2024-9233 |
WPScan | |
| 5.5 Medium | Ninja Forms Webhooks | Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via Form Webhook |
≤ 3.0.7 |
CVE-2024-13940 |
Wordfence | |
| 5.4 Medium | Smaily for WP | Cross-Site Request Forgery No login needed |
≤ 3.1.7 |
CVE-2025-47684 |
Patchstack | |
| 4.3 Medium | Web Accessibility with Max Access | Cross-Site Request Forgery No login needed |
≤ 2.0.9 Fixed in 2.1.0 |
CVE-2025-47681 |
Patchstack | |
| 4.3 Medium | Credova_Financial | Cross-Site Request Forgery No login needed |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2025-47674 |
Patchstack | |
| 5.4 Medium | LiveAgent | Cross-Site Request Forgery No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2025-47667 |
Patchstack | |
| 4.4 Medium | WP Pipes | Server-Side Request Forgery |
≤ 1.4.2 |
CVE-2025-47664 |
Patchstack | |
| 5.4 Medium | 워드프레스 결제 심플페이 | Cross-Site Request Forgery No login needed |
≤ 5.2.11 Fixed in 5.3.3 |
CVE-2025-47661 |
Patchstack | |
| 4.3 Medium | Sidebar Manager Light | Cross-Site Request Forgery No login needed |
≤ 1.18 |
CVE-2025-47647 |
Patchstack | |
| 5.5 Medium | WebinarPress | Server-Side Request Forgery |
≤ 1.33.28 |
CVE-2025-47635 |
Patchstack | |
| 4.3 Medium | DoFollow Case by Case | Cross-Site Request Forgery No login needed |
≤ 3.5.1 Fixed in 3.6.0 |
CVE-2025-47624 |
Patchstack | |
| 4.3 Medium | LessButtons Social Sharing and Statistics | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.6.1 |
CVE-2025-47614 |
Patchstack | |
| 4.3 Medium | EasyMe Connect | Cross-Site Request Forgery No login needed |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2025-47609 |
Patchstack | |
| 4.3 Medium | Simple Giveaways | Cross-Site Request Forgery No login needed |
≤ 2.49.0 |
CVE-2025-47606 |
Patchstack | |
| 4.3 Medium | WP Podcasts Manager | Cross-Site Request Forgery No login needed |
≤ 1.3 Fixed in 1.4 |
CVE-2025-47597 |
Patchstack | |
| 4.3 Medium | Beacon Lead Magnets and Lead Capture | Cross-Site Request Forgery No login needed |
≤ 1.5.8 Fixed in 1.5.9 |
CVE-2025-47596 |
Patchstack | |
| 4.3 Medium | Soccer Live Scores | Cross-Site Request Forgery No login needed |
≤ 1.0.5 |
CVE-2025-47594 |
Patchstack | |
| 4.3 Medium | WPSpeed | Cross-Site Request Forgery No login needed |
≤ 2.6.5 Fixed in 2.6.6 |
CVE-2025-47590 |
Patchstack | |
| 4.3 Medium | Wiki Embed | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.4.6 Fixed in 1.4.7 |
CVE-2025-47551 |
Patchstack | |
| 5.4 Medium | Wbcom Designs - Activity Link Preview For BuddyPress | Server-Side Request Forgery Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) No login needed |
≤ 1.4.4 Fixed in 1.6.0 |
CVE-2025-47548 |
Patchstack | |
| 4.3 Medium | TrueBooker | Cross-Site Request Forgery No login needed |
≤ 1.0.7 Fixed in 1.0.8 |
CVE-2025-47543 |
Patchstack | |
| 4.3 Medium | Simple calendar for Elementor | Cross-Site Request Forgery No login needed |
≤ 1.6.5 Fixed in 1.6.6 |
CVE-2025-47542 |
Patchstack | |
| 4.3 Medium | Seznam Webmaster | Cross-Site Request Forgery No login needed |
≤ 1.4.7 Fixed in 1.4.8 |
CVE-2025-47523 |
Patchstack | |
| 4.3 Medium | Easy PayPal Events | Cross-Site Request Forgery No login needed |
≤ 1.2.2 Fixed in 1.3 |
CVE-2025-47519 |
Patchstack | |
| 6.4 Medium | Display Remote Posts Block | Server-Side Request Forgery |
≤ 1.1.0 Fixed in 1.1.1 |
CVE-2025-47484 |
Patchstack | |
| 4.9 Medium | Easy Replace Image | Server-Side Request Forgery |
≤ 3.5.0 Fixed in 3.5.1 |
CVE-2025-47483 |
Patchstack | |
| 5.4 Medium | PW WooCommerce Bulk Edit | Cross-Site Request Forgery No login needed |
≤ 2.134 Fixed in 2.135 |
CVE-2025-47473 |
Patchstack | |
| 4.3 Medium | GPT3 AI Content Writer | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Prompt Generation No login needed |
≤ 1.9.14 Fixed in 1.9.15 |
CVE-2025-47470 |
Patchstack | |
| 4.3 Medium | Hash Form | Cross-Site Request Forgery No login needed |
≤ 1.2.8 Fixed in 1.2.9 |
CVE-2025-47468 |
Patchstack | |
| 5.4 Medium | Ultimate WP Mail | Cross-Site Request Forgery No login needed |
≤ 1.3.4 Fixed in 1.3.5 |
CVE-2025-47466 |
Patchstack | |
| 4.9 Medium | Solace Extra | Server-Side Request Forgery |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-47464 |
Patchstack | |
| 4.3 Medium | FundEngine | Cross-Site Request Forgery No login needed |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2025-47459 |
Patchstack | |
| 4.3 Medium | Product Quantity Dropdown For Woocommerce | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.2 Fixed in 1.3 |
CVE-2025-47451 |
Patchstack | |
| 4.3 Medium | WP Hotel Booking | Cross-Site Request Forgery No login needed |
≤ 2.1.9 Fixed in 2.2.0 |
CVE-2025-47448 |
Patchstack | |
| 4.3 Medium | Cool Author Box | Cross-Site Request Forgery No login needed |
≤ 3.0.0 Fixed in 3.0.1 |
CVE-2025-47447 |
Patchstack | |
| 4.3 Medium | Listamester | Cross-Site Request Forgery No login needed |
≤ 2.3.6 Fixed in 2.3.7 |
CVE-2025-47446 |
Patchstack | |
| 4.3 Medium | AHAthat | Cross-Site Request Forgery Cross-Site Request Forgery to AHA Page Deletion No login needed |
≤ 1.6 |
CVE-2025-4337 |
Wordfence | |
| 6.1 Medium | Abundatrade | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.8.02 |
CVE-2025-4199 |
Wordfence | |
| 6.1 Medium | Alink Tap | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.3.1 |
CVE-2025-4198 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.