WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 269 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium NextMove Lite - Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'xlwcty_current_date' Shortcode ≤ 2.23.0 CVE-2026-0703 Wordfence
6.4 Medium Youzify Plugin youzify Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter ≤ 1.3.6 CVE-2026-1559 Wordfence
6.4 Medium WP YouTube Lyte Plugin wp-youtube-lyte Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode ≤ 1.7.29 CVE-2026-3299 Wordfence
6.5 Medium YouTube Showcase Plugin youtube-showcase Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-15636 Patchstack
4.3 Medium Youtube Embed Plus Plugin youtube-embed-plus Broken Access Control ≤ 14.2.4 Fixed in 14.2.5 CVE-2026-39485 Patchstack
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint No login needed ≤ 2.1.7 CVE-2026-5167 Wordfence
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute ≤ 27.1.1 CVE-2026-3427 Wordfence
5.4 Medium Yoast Duplicate Post Plugin duplicate-post Broken Access Control Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite ≤ 4.5 CVE-2026-1217 Wordfence
5.3 Medium Pranayama Yoga Plugin pranayama-yoga Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-32377 Patchstack
6.4 Medium Show YouTube video Plugin show-youtube-video Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.1 CVE-2026-1825 Wordfence
6.5 Medium Travelpayouts Plugin travelpayouts Broken Access Control ≤ 1.2.2 CVE-2025-68042 Patchstack
4.3 Medium Serious Slider Plugin cryout-serious-slider Broken Access Control ≤ 1.2.7 Fixed in 1.3.0 CVE-2026-25399 Patchstack
6.4 Medium Ravelry Designs Widget Plugin ravelry-designs-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sb_ravelry_designs' Shortcode 'layout' Attribute ≤ 1.0.0 CVE-2026-1903 Wordfence
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute ≤ 26.8 CVE-2026-1293 Wordfence
4.3 Medium WP Youtube Video Gallery Plugin wp-youtube-video-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0 CVE-2025-14906 Wordfence
5.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2026-24599 Patchstack
6.5 Medium Turn Yoast SEO FAQ Block to Accordion Plugin faq-schema-block-to-accordion Cross-Site Scripting ≤ 1.0.6 CVE-2026-24591 Patchstack
5.3 Medium Custom Fonts – Host Your Fonts Locally Plugin custom-fonts Broken Access Control Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion No login needed ≤ 2.1.16 CVE-2025-14351 Wordfence
5.9 Medium Feeds for YouTube Pro Plugin feeds-for-youtube Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed ≤ 2.6.0 CVE-2025-12002 Wordfence
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
4.9 Medium Youzify Plugin youzify Server-Side Request Forgery ≤ 1.3.7 CVE-2025-69014 Patchstack
5.3 Medium PixelYourSite Plugin pixelyoursite Information Disclosure Sensitive Information Exposure via Log File No login needed ≤ 11.1.5 CVE-2025-14280 Wordfence
6.5 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.4 CVE-2025-68599 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
6.5 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Broken Access Control Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification No login needed ≤ 4.0.1 CVE-2025-13880 Wordfence
5.3 Medium Feeds for YouTube Plugin feeds-for-youtube Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.6.1 CVE-2025-64635 Patchstack
6.4 Medium Kingcabs Theme kingcabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.1.9 CVE-2025-7058 Wordfence
6.4 Medium Ayo Shortcodes Plugin ayo-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute ≤ 0.2 CVE-2025-14143 Wordfence
5.8 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 5.1.1 CVE-2025-11467 Wordfence
4.3 Medium Custom Layouts – Post + Product grids made easy Plugin custom-layouts Broken Access Control Post + Product grids made easy plugin <= 1.4.12 - Broken Access Control ≤ 1.4.12 Fixed in 1.5.0 CVE-2025-62996 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Backup, Restore and Migrate your sites with XCloner Plugin xcloner-backup-and-restore Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed ≤ 4.8.2 CVE-2025-11759 Wordfence
6.1 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Cross-Site Scripting Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import No login needed ≤ 3.20.3 CVE-2025-13007 Wordfence
4.4 Medium YouTube Subscribe Plugin easy-youtube-subscribe Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Title and Channel ID ≤ 3.0.0 CVE-2025-12025 Wordfence
6.5 Medium ACF Flexible Layouts Manager Plugin acf-flexible-layouts-manager Broken Access Control Missing Authorization to Unauthenticated Custom Field Update No login needed ≤ 1.1.6 CVE-2025-12937 Wordfence
5.3 Medium YOP Poll Plugin yop-poll Broken Access Control No login needed ≤ 6.5.38 Fixed in 6.5.39 CVE-2025-64370 Patchstack
4.3 Medium Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed Plugin quicq Broken Access Control Missing Authorization to Authenticated (Subscriber+) Afosto Disconnect ≤ 2.0.0 CVE-2025-12015 Wordfence
6.5 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting ≤ 2.23.0 Fixed in 2.24.0 CVE-2025-62969 Patchstack
6.4 Medium Simple Youtube Shortcode Plugin simple-youtube-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.3 CVE-2025-11811 Wordfence
4.3 Medium PixelYourSite Plugin pixelyoursite Cross-Site Request Forgery Cross-Site Request Forgery to GDPR Options Modification No login needed ≤ 11.1.2 CVE-2025-10588 Wordfence
5.3 Medium Login with YourMembership - YM SSO Login Plugin login-with-yourmembership Broken Access Control YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes' No login needed ≤ 1.1.7 CVE-2025-10648 Wordfence
6.4 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field ≤ 1.0.16 CVE-2025-9204 Wordfence
6.4 Medium Yoast SEO Premium Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting 25.7 – 25.9 CVE-2025-11241 Wordfence
6.4 Medium Yoga Schedule Momoyoga Plugin momoyoga-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 CVE-2025-9852 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
5.4 Medium payOS Plugin payos Cross-Site Request Forgery No login needed ≤ 1.0.73 CVE-2025-57946 Patchstack
4.3 Medium Interact: Embed A Quiz On Your Site Plugin interact-quiz-embed Cross-Site Request Forgery No login needed ≤ 3.1 Fixed in 3.2 CVE-2025-58675 Patchstack
6.5 Medium CatFolders – Tame Your WordPress Media Library by Category Plugin catfolders SQL Injection Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Injection via CSV Import ≤ 2.5.2 CVE-2025-9776 Wordfence
4.3 Medium Payoneer Checkout Plugin payoneer-checkout Content Injection Content Spoofing No login needed ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-58795 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only