WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 901–950 of 1,457 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High AIO Shortcodes Plugin aio-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-24620 Patchstack
6.4 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.6.9 CVE-2024-13612 Wordfence
6.5 Medium AI Infographic Maker Plugin infographic-and-list-builder-ilist Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.9.0 CVE-2024-12415 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2024-13472 Wordfence
6.4 Medium Ticketmeo – Sell Tickets – Event Ticketing Plugin ploxel Cross-Site Scripting Sell Tickets – Event Ticketing <= 2.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.3.6 CVE-2025-0507 Wordfence
4.3 Medium Elementor Website Builder Pro – More than Just a Page Builder Plugin Information Disclosure More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 3.25.10 CVE-2024-8494 Wordfence
6.4 Medium Alex Reservations: Smart Restaurant Booking Plugin alex-reservations Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.0.5 CVE-2024-13380 Wordfence
7.3 High Contact Form & SMTP Plugin for WordPress by PirateForms Plugin pirate-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.6.0 CVE-2024-13453 Wordfence
6.4 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.8.24 CVE-2024-13470 Wordfence
7.1 High Bulk Me Now Plugin Cross-Site Scripting Stored XSS via Shortcode No login needed ≤ 2.0 CVE-2024-12708 WPScan
6.4 Medium EthereumICO Plugin ethereumico Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ethereum-ico Shortcode ≤ 2.4.6 CVE-2024-12921 Wordfence
6.4 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via brid_override_yt Shortcode ≤ 3.8.3 CVE-2024-13561 Wordfence
6.4 Medium Philantro – Donations and Donor Management Plugin philantro Cross-Site Scripting Donations and Donor Management <= 5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via donate Shortcode ≤ 5.3 CVE-2024-13527 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
7.3 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10633 Wordfence
8.8 High ThemeREX Addons Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.33.0 CVE-2025-0682 Wordfence
6.5 Medium Show/Hide Shortcode Plugin showhide-shortcode Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-24687 Patchstack
6.5 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting ≤ 0.1.2 Fixed in 0.2.1 CVE-2025-24673 Patchstack
7.1 High MachForm Shortcode Plugin machform-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-24636 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function No login needed ≤ 7.2.1 CVE-2024-13499 Wordfence
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function No login needed ≤ 7.2.1 CVE-2024-13495 Wordfence
6.3 Medium AI Power: Complete AI Pack Plugin gpt3-ai-content-generator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.8.96 CVE-2024-13361 Wordfence
6.4 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.2 CVE-2024-13590 Wordfence
5.9 Medium Related Post Shortcode Plugin related-post-shortcode Cross-Site Scripting ≤ 1.2 CVE-2025-22276 Patchstack
6.5 Medium Weaver Themes Shortcode Compatibility Plugin weaver-themes-shortcode-compatibility Cross-Site Scripting ≤ 1.0.4 CVE-2025-22267 Patchstack
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode ≤ 1.5.22 CVE-2024-12696 Wordfence
6.4 Medium JSM Screenshot Machine Shortcode Plugin screenshot-machine-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 CVE-2024-13385 Wordfence
6.4 Medium Glofox Shortcodes Plugin glofox-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6 CVE-2024-12508 Wordfence
6.5 Medium Enhanced YouTube Shortcode Plugin enhanced-youtube-shortcode Cross-Site Scripting ≤ 2.0.1 CVE-2025-23946 Patchstack
6.5 Medium PDF.js Shortcode Plugin pdfjs-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23943 Patchstack
6.5 Medium Mindmeister Shortcode Plugin mindmeister-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23896 Patchstack
6.5 Medium GMap Shortcode Plugin gmap-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23893 Patchstack
6.5 Medium Nite Shortcodes Plugin nite-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23877 Patchstack
6.5 Medium FontAwesome.io ShortCodes Plugin fontawesomeio-shortcodes Cross-Site Scripting ≤ 1.0 CVE-2025-23824 Patchstack
6.5 Medium Easy Shortcode Buttons Plugin easy-shortcode-buttons Cross-Site Scripting ≤ 1.2 CVE-2025-23825 Patchstack
6.5 Medium Horizontal Line Shortcode Plugin horizontal-line-shortcode Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23791 Patchstack
6.5 Medium Sidebar-Content from Shortcode Plugin sidebar-content-from-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23642 Patchstack
7.1 High Twitter Shortcode Plugin twitter-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-23618 Patchstack
7.1 High Shortcode in Comment Plugin shortcode-in-comment Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-23569 Patchstack
5.4 Medium Motors – Car Dealer, Classifieds & Listing Plugin motors-car-dealership-classified-listings Arbitrary Shortcode Execution Car Dealer, Classifieds & Listing <= 1.4.43 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Custom Title ≤ 1.4.43 CVE-2024-10970 Wordfence
6.5 Medium Twitter Bootstrap Collapse aka Accordian Shortcode Plugin twitter-bootstrap-collapse-aka-accordian-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-22743 Patchstack
6.4 Medium PDF for WPForms + Drag and Drop Template Builder Plugin pdf-for-wpforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yeepdf_dotab Shortcode ≤ 4.6.0 CVE-2024-12593 Wordfence
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'booking' Shortcode ≤ 10.9.2 CVE-2024-13323 Wordfence
7.5 High CF Internal Link Shortcode Plugin internal-link-shortcode SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.1.0 CVE-2024-12404 Wordfence
7.1 High Better User Shortcodes Plugin better-user-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22594 Patchstack
6.5 Medium BP Profile Shortcodes Extra Plugin bp-profile-shortcodes-extra Cross-Site Scripting ≤ 2.6.0 CVE-2025-22817 Patchstack
6.5 Medium Genesis Style Shortcodes Plugin genesis-style-shortcodes Cross-Site Scripting ≤ 1.0 CVE-2025-22823 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only