WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 118 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Bulk Theme bulk Broken Access Control No login needed ≤ 1.0.11 CVE-2025-26867 Patchstack
6.5 Medium GDPR Cookie Consent Plugin Cross-Site Request Forgery Bulk Delete via CSRF No login needed < 2.6.1 Fixed in 2.6.1 CVE-2024-8286 WPScan
4.3 Medium Bulk Featured Image Plugin bulk-featured-image Broken Access Control ≤ 1.2.4 CVE-2025-47591 Patchstack
5.4 Medium PW WooCommerce Bulk Edit Plugin pw-bulk-edit Cross-Site Request Forgery No login needed ≤ 2.134 Fixed in 2.135 CVE-2025-47473 Patchstack
5.3 Medium Bulk Assign Linked Products For WooCommerce Plugin wc-bulk-assign-linked-products Broken Access Control No login needed ≤ 2.1 CVE-2025-46489 Patchstack
6.5 Medium ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.4.9 CVE-2025-3280 Wordfence
7.1 High Product Excel Import Export & Bulk Edit for WooCommerce Plugin webd-woocommerce-product-excel-importer-bulk-edit Cross-Site Scripting No login needed ≤ 4.7 CVE-2025-32674 Patchstack
7.1 High Bulk Page Stub Creator Plugin bulk-page-stub-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-39519 Patchstack
4.3 Medium Bulk Term Editor Plugin bulk-term-editor Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-39512 Patchstack
9.3 Critical Bulk Product Sync Plugin sync-wc-google SQL Injection No login needed ≤ 8.6 Fixed in 9.0 CVE-2025-31599 Patchstack
7.1 High Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16 Fixed in 2.20 CVE-2025-31537 Patchstack
4.3 Medium Bulk Product Sync Plugin sync-wc-google Cross-Site Request Forgery No login needed ≤ 8.6 Fixed in 9.0 CVE-2025-31852 Patchstack
4.3 Medium Bulk Fields Editor Plugin bulk-user-editor Broken Access Control ≤ 1.8.0 CVE-2025-31752 Patchstack
6.5 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-31598 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
4.3 Medium easy-broken-link-checker Plugin Cross-Site Request Forgery Bulk Actions via CSRF ≤ 9.0.2 CVE-2025-1362 WPScan
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
5.9 Medium BEAR Plugin woo-bulk-editor Cross-Site Scripting ≤ 1.1.4.4 Fixed in 1.1.4.5 CVE-2025-26775 Patchstack
7.1 High Bulk Menu Edit Plugin bulk-menu-edit Broken Access Control ≤ 1.3 Fixed in 1.3.1 CVE-2025-24692 Patchstack
7.5 High WOLF Plugin bulk-editor Path Traversal ≤ 1.0.8.5 Fixed in 1.0.8.6 CVE-2025-24605 Patchstack
7.1 High Bulk Categories Assign Plugin bulk-categories-assign Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23582 Patchstack
4.3 Medium Bulk Me Now Plugin Cross-Site Request Forgery Message Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12709 WPScan
7.1 High Bulk Me Now Plugin Cross-Site Scripting Stored XSS via Shortcode No login needed ≤ 2.0 CVE-2024-12708 WPScan
7.1 High Bulk Me Now Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2024-12638 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Bulk Delete via CSRF No login needed ≤ 8.2.4 CVE-2024-12436 WPScan
6.5 Medium SEO Bulk Editor Plugin seo-bulk-editor Cross-Site Scripting ≤ 1.1.0 CVE-2025-22587 Patchstack
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
6.1 Medium WP – Bulk SMS – by SMS.to Plugin wp-bulk-sms Cross-Site Scripting Bulk SMS – by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting No login needed ≤ 1.0.12 CVE-2024-11434 Wordfence
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack
5.4 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Broken Access Control ≤ 1.5 Fixed in 1.51 CVE-2023-41688 Patchstack
6.1 Medium Seraphinite Bulk Discounts for WooCommerce Plugin seraphinite-discount-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-12160 Wordfence
4.3 Medium Bulk Edit Post Titles Plugin bulk-edit-post-titles Broken Access Control ≤ 5.0.0 CVE-2023-49754 Patchstack
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
6.1 Medium BulkPress Plugin bulkpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.3.5 CVE-2024-9615 Wordfence
9.9 Critical Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation Plugin ai-content-generator Arbitrary File Upload ≤ 2.4.9 CVE-2024-52384 Patchstack
4.9 Medium WOLF Plugin bulk-editor Path Traversal CSV Limited Path Traversal ≤ 1.0.8.3 Fixed in 1.0.8.4 CVE-2024-52396 Patchstack
8.8 High Bulk Change Role Plugin bulk-role-change Privilege Escalation ≤ 1.1 CVE-2024-50504 Patchstack
4.3 Medium Bulk images optimizer: Resize, optimize, convert to webp, rename ... Plugin bulk-image-resizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Options Update ≤ 2.0.1 CVE-2024-9361 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
7.1 High WP Bulk Delete Plugin wp-bulk-delete Cross-Site Scripting No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-47352 Patchstack
6.1 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-9384 Wordfence
6.1 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.15 CVE-2024-8803 Wordfence
8.1 High WooCommerce Customers Manager Plugin Cross-Site Request Forgery Bulk Action via CSRF No login needed < 30.1 Fixed in 30.1 CVE-2024-3983 WPScan
6.5 Medium HTML Forms – Simple WordPress Forms Plugin Cross-Site Request Forgery Simple WordPress Forms Plugin < 1.3.34 - Bulk Delete via CSRF No login needed < 1.3.34 Fixed in 1.3.34 CVE-2024-6412 WPScan
8.8 High WP eMember Plugin Cross-Site Request Forgery Bulk Delete via CSRF No login needed < 10.6.6 Fixed in 10.6.6 CVE-2024-5076 WPScan
5.4 Medium Astra Bulk Edit Plugin astra-bulk-edit Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2023-44148 Patchstack
5.4 Medium BulkGate SMS Plugin for WooCommerce Plugin woosms-sms-module-for-woocommerce Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2023-51679 Patchstack
4.3 Medium Bulk Posts Editing Plugin Cross-Site Request Forgery No login needed ≤ 4.2.3 CVE-2024-4204 Wordfence
4.3 Medium Bulk Posts Editing Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization ≤ 4.2.3 CVE-2024-4199 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only