WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 9,851–9,900 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 198 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Salesmate Add-On for Gravity Forms Plugin gf-salesmate-add-on Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-31533 Patchstack
6.5 Medium AtomChat Plugin atomchat Cross-Site Scripting ≤ 1.1.8 CVE-2025-31532 Patchstack
4.3 Medium Google SEO Pressor Snippet Plugin google-seo-author-snippets Broken Access Control ≤ 2.0 CVE-2025-31530 Patchstack
4.3 Medium Slider Path for Elementor Plugin slider-path Broken Access Control ≤ 3.0.0 CVE-2025-31529 Patchstack
4.3 Medium StaticPress Plugin staticpress Broken Access Control ≤ 0.4.5 CVE-2025-31528 Patchstack
6.4 Medium WP Link Preview Plugin wp-link-preview Server-Side Request Forgery ≤ 1.4.1 CVE-2025-31527 Patchstack
8.5 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-31526 Patchstack
7.1 High Tantyyellow Theme tantyyellow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0.5 CVE-2025-23995 Patchstack
6.5 Medium Churel Theme churel Cross-Site Scripting ≤ 1.0.8 CVE-2025-31419 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-30963 Patchstack
4.3 Medium NanoSupport Plugin nanosupport Broken Access Control ≤ 0.6.0 CVE-2025-31376 Patchstack
5.3 Medium Simple:Press Plugin simplepress Broken Access Control No login needed ≤ 6.11.5 Fixed in 6.11.6 CVE-2025-31386 Patchstack
6.5 Medium Trackserver Plugin trackserver Cross-Site Scripting ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-30961 Patchstack
4.3 Medium ELEX WooCommerce Request a Quote Plugin elex-request-a-quote Broken Access Control ≤ 2.3.9 CVE-2025-31406 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.65 Fixed in 3.2.66 CVE-2025-31414 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.1.22 Fixed in 2.1.22.1 CVE-2025-31412 Patchstack
7.5 High InstaWP Connect Plugin instawp-connect Local File Inclusion No login needed ≤ 0.1.0.82 Fixed in 0.1.0.83 CVE-2025-31387 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Local File Inclusion ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-31016 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-30987 Patchstack
7.5 High Ads by WPQuads Plugin quick-adsense-reloaded Broken Access Control No login needed ≤ 2.0.87.1 Fixed in 2.0.88 CVE-2025-30855 Patchstack
7.5 High Accounting for WooCommerce Plugin accounting-for-woocommerce Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-30835 Patchstack
4.3 Medium WP Docs Plugin wp-docs Broken Access Control ≤ 2.2.7 Fixed in 2.2.7 CVE-2025-31417 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.5.7 Fixed in 3.5.7.1 CVE-2025-31043 Patchstack
4.3 Medium SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Request Forgery CSRF to Multiple Admin Actions ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-31010 Patchstack
7.1 High GlobalPayments WooCommerce Plugin global-payments-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2025-22767 Patchstack
7.1 High SUPER RESPONSIVE SLIDER Plugin super-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22575 Patchstack
7.1 High ULTIMATE VIDEO GALLERY Plugin ultimate-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22566 Patchstack
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack
9.3 Critical Schedule Plugin schedule SQL Injection No login needed ≤ 1.0.0 CVE-2025-22523 Patchstack
7.1 High Improve My City Plugin improve-my-city Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-22501 Patchstack
7.1 High WP Azure offload Plugin wp-azure-offload Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-22360 Patchstack
7.1 High Stencies Plugin stencies Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.58 CVE-2025-22356 Patchstack
8.1 High GetShop ecommerce Plugin getshop-ecommerce Path Traversal No login needed ≤ 1.3 CVE-2024-54362 Patchstack
8.6 High PluginPass Plugin pluginpass-pro-plugintheme-licensing Path Traversal Arbitrary File Download/Delete No login needed ≤ 0.9.10 CVE-2024-54291 Patchstack
7.1 High Já-Já Pagamentos for WooCommerce Plugin wc-ja-ja-pagamentos-multicaixa-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51624 Patchstack
7.5 High Pop-Up Chop Chop Plugin pop-up Local File Inclusion ≤ 2.1.7 CVE-2025-31432 Patchstack
6.5 Medium Magic Embeds Plugin wp-embed-facebook Cross-Site Scripting ≤ 3.1.2 CVE-2025-31433 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
6.5 Medium FormLift for Infusionsoft Web Forms Plugin formlift Cross-Site Scripting ≤ 7.5.19 Fixed in 7.5.20 CVE-2025-31434 Patchstack
4.3 Medium WP Supersized Plugin wp-supersized Cross-Site Request Forgery No login needed ≤ 3.1.6 CVE-2025-31438 Patchstack
5.9 Medium WP-OGP Plugin wp-ogp Cross-Site Scripting ≤ 1.0.5 CVE-2025-31437 Patchstack
5.4 Medium Browser Caching with .htaccess Plugin browser-caching-with-htaccess Cross-Site Request Forgery No login needed 1.2.1 CVE-2025-31439 Patchstack
7.1 High KK I Like It Plugin kk-i-like-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.5.3 CVE-2025-31443 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
5.4 Medium Simple Trackback Disabler Plugin simple-trackback-disabler Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-31448 Patchstack
5.4 Medium NertWorks All in One Social Share Tools Plugin nertworks-all-in-one-social-share-tools Cross-Site Request Forgery No login needed ≤ 1.26 CVE-2025-31447 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
6.5 Medium wBounce Plugin wbounce Cross-Site Scripting ≤ 1.8.1 CVE-2025-31451 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only