WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 9,701–9,750 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 195 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium GDPR Cookie Notice Plugin gdpr-cookie-notice Broken Access Control No login needed ≤ 1.2.0 CVE-2025-31765 Patchstack
5.9 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Scripting ≤ 5.4.1 CVE-2025-31764 Patchstack
4.3 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Request Forgery No login needed ≤ 5.4.1 CVE-2025-31763 Patchstack
6.5 Medium Sheet2Site Plugin sheet2site Cross-Site Scripting ≤ 1.0.18 CVE-2025-31762 Patchstack
6.5 Medium Hypotext Plugin hypotext Cross-Site Scripting ≤ 1.0.1 CVE-2025-31761 Patchstack
6.5 Medium SnapWidget Social Photo Feed Widget Plugin snapwidget-wp-instagram-widget Cross-Site Scripting ≤ 1.1.0 CVE-2025-31760 Patchstack
6.5 Medium Boo Recipes Plugin boo-recipes Cross-Site Scripting ≤ 2.4.1 CVE-2025-31759 Patchstack
5.4 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control ≤ 1.78 CVE-2025-31757 Patchstack
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
4.3 Medium pCloud Backup Plugin pcloud-backup Broken Access Control ≤ 1.0.1 CVE-2025-31755 Patchstack
6.5 Medium DobsonDev Shortcodes Plugin dobsondev-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.12 CVE-2025-31754 Patchstack
4.3 Medium Bulk Fields Editor Plugin bulk-user-editor Broken Access Control ≤ 1.8.0 CVE-2025-31752 Patchstack
6.5 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.3 CVE-2025-31751 Patchstack
5.9 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Scripting ≤ 1.3 CVE-2025-31750 Patchstack
6.5 Medium HMH Footer Builder For Elementor Plugin hmh-footer-builder-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2025-31749 Patchstack
6.5 Medium Opal Portfolio Plugin opal-portfolios Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-31748 Patchstack
6.5 Medium WP Chrono Plugin wp-chrono Cross-Site Scripting ≤ 1.5.4 CVE-2025-31747 Patchstack
6.5 Medium Subscription Form for Feedblitz Plugin feedblitz-email-subscription Cross-Site Scripting ≤ 1.0.9 CVE-2025-31745 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31744 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31743 Patchstack
5.9 Medium Dima Take Action Plugin dima-take-action Cross-Site Scripting ≤ 1.0.5 CVE-2025-31742 Patchstack
6.5 Medium Easy Magazine Plugin filtr8-magazine Cross-Site Scripting ≤ 2.1.13 CVE-2025-31741 Patchstack
6.5 Medium News, Magazine and Blog Elements Plugin news-magazine-and-blog-elements Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-31740 Patchstack
6.5 Medium LeadQuizzes Plugin leadquizzes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-31738 Patchstack
6.5 Medium Client Showcase Plugin client-showcase Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2025-31737 Patchstack
6.5 Medium Footnotes Plugin footnotes-for-wordpress Cross-Site Scripting ≤ 2016.1230 CVE-2025-31735 Patchstack
6.5 Medium Simple Post Expiration Plugin simple-post-expiration Cross-Site Scripting ≤ 1.0.1 CVE-2025-31734 Patchstack
6.5 Medium WP Sitemap Plugin wpsitemap Cross-Site Scripting ≤ 1.0.0 CVE-2025-31733 Patchstack
4.3 Medium GB Gallery Slideshow Plugin gb-gallery-slideshow Broken Access Control ≤ 1.3 CVE-2025-31732 Patchstack
6.5 Medium Author Bio Shortcode Plugin author-bio-shortcode Cross-Site Scripting ≤ 2.5.3 CVE-2025-31731 Patchstack
6.5 Medium Marketer Addons Plugin marketer-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.1 CVE-2025-31730 Patchstack
4.3 Medium Zoho Flow Plugin zoho-flow Broken Access Control ≤ 2.13.3 Fixed in 2.13.4 CVE-2025-31408 Patchstack
6.5 Medium Bridge Core Plugin bridge-core Cross-Site Scripting < 3.3.1 Fixed in 3.3.1 CVE-2025-31409 Patchstack
8.5 High RJ Quickcharts Plugin rj-quickcharts SQL Injection ≤ 0.6.1 CVE-2025-31024 Patchstack
7.5 High GTM Kit Plugin gtm-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-31001 Patchstack
9.3 Critical XV Random Quotes Plugin xv-random-quotes SQL Injection No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-30971 Patchstack
8.8 High Vitepos Plugin vitepos-lite Authentication Bypass Broken Authentication ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-22277 Patchstack
7.6 High YayExtra Plugin yayextra Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-31415 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31095 Patchstack
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
9.8 Critical Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection No login needed ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-31084 Patchstack
8.8 High Mobile DJ Manager Plugin mobile-dj-manager PHP Object Injection ≤ 1.7.5.2 Fixed in 1.7.5.3 CVE-2025-31074 Patchstack
4.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control ≤ 24.12.58 Fixed in 24.12.59 CVE-2025-30926 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.4 Fixed in 4.2.4 CVE-2025-30924 Patchstack
7.1 High SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30917 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
8.6 High CM Download Manager Plugin cm-download-manager Arbitrary File Deletion No login needed ≤ 2.9.6 Fixed in 3.0.0 CVE-2025-30910 Patchstack
7.1 High AEC Kiosque Plugin aec-kiosque Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.3 Fixed in 1.9.4 CVE-2025-30902 Patchstack
8.1 High JS Help Desk Plugin js-support-ticket Local File Inclusion No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30901 Patchstack
9.3 Critical JS Help Desk Plugin js-support-ticket SQL Injection No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30886 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only