WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 901–950 of 2,548 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Ultimate WP Mail Plugin ultimate-wp-mail Cross-Site Request Forgery No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-47466 Patchstack
4.9 Medium Solace Extra Plugin solace-extra Server-Side Request Forgery ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-47464 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
4.3 Medium FundEngine Plugin wp-fundraising-donation Cross-Site Request Forgery No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-47459 Patchstack
4.3 Medium Product Quantity Dropdown For Woocommerce Plugin product-quantity-dropdown-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-47451 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-47448 Patchstack
4.3 Medium Cool Author Box Plugin hm-cool-author-box-widget Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2025-47447 Patchstack
4.3 Medium Listamester Plugin listamester Cross-Site Request Forgery No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-47446 Patchstack
5.4 Medium Zalo Official Live Chat Plugin zalo-official-live-chat Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-46498 Patchstack
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
4.9 Medium WP AVCL Automation Helper (formerly WPFlyLeads) Plugin woozap Server-Side Request Forgery ≤ 3.4 CVE-2025-46531 Patchstack
6.4 Medium BeerXML Shortcode Plugin beerxml-shortcode Server-Side Request Forgery ≤ 0.7.1 Fixed in 0.8 CVE-2025-46511 Patchstack
4.9 Medium Simple Google Photos Grid Plugin simple-google-photos-grid Server-Side Request Forgery ≤ 1.5 Fixed in 1.6 CVE-2025-46503 Patchstack
7.1 High Loan Calculator Plugin repayment-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-46442 Patchstack
4.3 Medium All in One Time Clock Lite Plugin aio-time-clock-lite Cross-Site Request Forgery No login needed ≤ 1.3.326 Fixed in 1.3.326 CVE-2025-46513 Patchstack
7.1 High Wp Custom CMS Block Plugin wp-custom-cms-block Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-46457 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High Milat jQuery Automatic Popup Plugin milat-jquery-automatic-popup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2025-46514 Patchstack
7.1 High Custom Functions Plugin custom-functions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-46512 Patchstack
7.1 High Contact Form 7 Calendar Plugin cf7-calendar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.1 CVE-2025-46510 Patchstack
7.1 High Advanced lazy load Plugin advanced-lazy-load Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.0 CVE-2025-46508 Patchstack
7.1 High WpZon – Amazon Affiliate Plugin wpzon Cross-Site Request Forgery Amazon Affiliate Plugin plugin <= 1.3 - CSRF to XSS No login needed ≤ 1.3 CVE-2025-46506 Patchstack
7.1 High Vasaio QR Code Plugin vasaio-qr-code Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.2.5 CVE-2025-46504 Patchstack
7.1 High LSD Custom taxonomy and category meta Plugin custom-taxonomy-category-and-term-fields Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.2 CVE-2025-46502 Patchstack
7.1 High PayPal Express Checkout Plugin paypal-express-checkout Cross-Site Request Forgery No login needed ≤ 2.1.2 CVE-2025-46499 Patchstack
7.1 High Navegg Analytics Plugin navegg Cross-Site Request Forgery No login needed ≤ 3.3.3 CVE-2025-46497 Patchstack
6.5 Medium Drop Caps Plugin drop-caps Cross-Site Request Forgery CSRF to XSS ≤ 2.1 CVE-2025-46495 Patchstack
7.1 High Call Now PHT Blog Plugin call-now-coccoc-pht-blog Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.4.1 CVE-2025-46492 Patchstack
7.1 High Modern Polls Plugin modern-polls Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.10 CVE-2025-46466 Patchstack
7.1 High Print Science Designer Plugin print-science-designer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.155 CVE-2025-46465 Patchstack
4.3 Medium WPVN Plugin wpvn-username-changer Cross-Site Request Forgery No login needed ≤ 0.7.8 CVE-2025-46462 Patchstack
7.1 High Google News Plugin google-news Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-46452 Patchstack
7.1 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.3.0 CVE-2025-46450 Patchstack
4.9 Medium Animate Plugin animate Server-Side Request Forgery ≤ 0.5 CVE-2025-46443 Patchstack
4.3 Medium SCSS-Library Plugin scss-library Cross-Site Request Forgery No login needed ≤ 0.4.1 CVE-2025-46436 Patchstack
7.4 High Plugin Central Plugin plugin-central Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.5.1 CVE-2025-46439 Patchstack
7.1 High Time Based Greeting Plugin time-based-greeting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-46435 Patchstack
7.1 High KiotViet Sync Plugin kiotvietsync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8.4 CVE-2025-39381 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.3 Fixed in 1.4 CVE-2025-46251 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-46249 Patchstack
4.3 Medium CM Answers Plugin cm-answers Cross-Site Request Forgery No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-46246 Patchstack
4.3 Medium CM Ad Changer Plugin cm-ad-changer Cross-Site Request Forgery No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-46245 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
5.4 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Cross-Site Request Forgery No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-46231 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only