WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–100 of 114 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App | SQL Injection Your native, mobile iPhone App and Android App <= 0.8.8.8 - Unauthenticated SQL Injection No login needed |
≤ 0.8.8.8 |
CVE-2025-9200 |
Wordfence | |
| 7.1 High | Conditional Cart Messages for WooCommerce – YourPlugins.com | Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.10 |
CVE-2025-60171 |
Patchstack | |
| 7.1 High | Auto Last Youtube Video | Cross-Site Request Forgery No login needed |
≤ 1.0.7 |
CVE-2025-58843 |
Patchstack | |
| 8.1 High | YouTube Showcase | PHP Object Injection No login needed |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2025-54731 |
Patchstack | |
| 7.1 High | ATT YouTube Widget | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.0 |
CVE-2025-48359 |
Patchstack | |
| 7.1 High | Savyour Affiliate Partner | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1.4 |
CVE-2025-48306 |
Patchstack | |
| 7.1 High | Multimedia Playlist Slider Addon for WPBakery Page Builder | Cross-Site Scripting No login needed |
≤ 2.1 Fixed in 2.2 |
CVE-2025-48154 |
Patchstack | |
| 7.1 High | Youtube Vimeo Video Player and Slider WP | Cross-Site Scripting No login needed |
≤ 3.8 Fixed in 3.9 |
CVE-2025-48159 |
Patchstack | |
| 7.1 High | Youtube Vimeo Video Player and Slider | Cross-Site Scripting No login needed |
≤ 3.8 Fixed in 3.9 |
CVE-2025-53563 |
Patchstack | |
| 8.8 High | Soledad | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'header_layout' |
≤ 8.6.7 |
CVE-2025-8142 |
Wordfence | |
| 7.1 High | Multimedia Playlist Slider Addon for WPBakery Page Builder | Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2025-30626 |
Patchstack | |
| 7.2 High | Use-your-Drive | Google Drive | Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed |
≤ 3.3.1 |
CVE-2025-7050 |
Wordfence | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.1.0 |
CVE-2025-7725 |
Wordfence | |
| 8.8 High | Yogi | PHP Object Injection |
≤ 2.9.3 Fixed in 2.9.3 |
CVE-2025-24779 |
Patchstack | |
| 7.1 High | Bulk YouTube Post Creator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-49423 |
Patchstack | |
| 7.5 High | Import YouTube videos as WP Posts | Broken Access Control No login needed |
≤ 2.1 |
CVE-2025-52802 |
Patchstack | |
| 8.1 High | Yozi | Local File Inclusion No login needed |
≤ 2.0.63 Fixed in 2.0.66.1 |
CVE-2025-32289 |
Patchstack | |
| 7.1 High | Tayori Form | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.9 |
CVE-2025-46437 |
Patchstack | |
| 7.3 High | Travelpayouts | Cross-Site Request Forgery Settings Update via CSRF No login needed |
< 1.1.13 Fixed in 1.1.13 |
CVE-2023-5934 |
WPScan | |
| 7.3 High | LayoutBoxx | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 0.3.1 |
CVE-2025-2802 |
Wordfence | |
| 7.5 High | Mayosis Core | Path Traversal Unauthenticated Arbitrary File Read No login needed |
≤ 5.4.1 |
CVE-2025-1565 |
Wordfence | |
| 7.5 High | Capturly | Local File Inclusion No login needed |
≤ 2.0.1 Fixed in 2.0.2 |
CVE-2025-39379 |
Patchstack | |
| 7.1 High | WPYog Documents | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.5 Fixed in 1.3.6 |
CVE-2025-27292 |
Patchstack | |
| 7.1 High | Lock Your Updates | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-32537 |
Patchstack | |
| 7.1 High | Workbox Video from Vimeo & Youtube | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.2 |
CVE-2025-32534 |
Patchstack | |
| 7.1 High | Are you robot google recaptcha | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2 |
CVE-2025-28928 |
Patchstack | |
| 7.1 High | Your Lightbox | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-23704 |
Patchstack | |
| 7.1 High | WP Find Your Nearest | Cross-Site Request Forgery CSRF to Settings Change No login needed |
≤ 0.3.1 |
CVE-2025-25161 |
Patchstack | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.0.0.1 |
CVE-2025-1513 |
Wordfence | |
| 7.1 High | QMean – WordPress Did You Mean | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0 |
CVE-2025-23428 |
Patchstack | |
| 7.1 High | Passwordless WP – Login with your glance or fingerprint | Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.6 |
CVE-2025-23792 |
Patchstack | |
| 7.1 High | Youtube Video Grid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.9 |
CVE-2025-23634 |
Patchstack | |
| 7.1 High | Hack me if you can | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2 |
CVE-2025-23713 |
Patchstack | |
| 7.1 High | Shabbos and Yom Tov | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.9 |
CVE-2025-23694 |
Patchstack | |
| 7.1 High | MDC YouTube Downloader | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 3.0.0 |
CVE-2025-23639 |
Patchstack | |
| 7.1 High | Find Your Reps | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2 |
CVE-2025-23557 |
Patchstack | |
| 8.8 High | PlugVersions – Easily rollback to previous versions of your plugins | Broken Access Control Easily rollback to previous versions of your plugins <= 0.0.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation |
≤ 0.0.7 |
CVE-2024-12881 |
Wordfence | |
| 7.5 High | Video Gallery – YouTube Gallery | Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2023-25988 |
Patchstack | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed |
≤ 3.8.19 |
CVE-2024-11052 |
Wordfence | |
| 7.3 High | Grid Plus – Unlimited grid layout | Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed |
≤ 1.3.5 |
CVE-2024-10910 |
Wordfence | |
| 7.2 High | YouTube Gallery and Vimeo Gallery | SQL Injection Authenticated (Administrator+) SQL Injection |
≤ 2.4.2 |
CVE-2024-10247 |
Wordfence | |
| 7.1 High | Youneeq Recommendations | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.0.7 |
CVE-2024-52457 |
Patchstack | |
| 7.1 High | Protect Your Content | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.0.2 |
CVE-2024-53728 |
Patchstack | |
| 7.1 High | Footer Flyout Widget | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1 |
CVE-2024-53732 |
Patchstack | |
| 7.2 High | Activity Log – Monitor & Record User Changes | Cross-Site Scripting Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scripting via Event Context No login needed |
≤ 2.11.1 |
CVE-2024-10788 |
Wordfence | |
| 8.5 High | Website price calculator | SQL Injection |
≤ 4.1 |
CVE-2024-51601 |
Patchstack | |
| 7.5 High | Masteriyo - LMS | Broken Access Control No login needed |
≤ 1.11.4 Fixed in 1.11.5 |
CVE-2024-43158 |
Patchstack | |
| 7.1 High | DocumentPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1 |
CVE-2024-49656 |
Patchstack | |
| 8.8 High | Masteriyo LMS – eLearning and Online Course Builder | Broken Access Control eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation |
≤ 1.13.3 |
CVE-2024-10008 |
Wordfence | |
| 7.2 High | WordPress Post Grid Layouts with Pagination – Sogrid | Local File Inclusion Sogrid <= 1.5.6 - Authenticated (Admin+) Local File Inclusion |
≤ 1.5.6 |
CVE-2024-8392 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.