WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 217 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Podlove Subscribe button Plugin podlove-subscribe-button Cross-Site Scripting ≤ 1.3.11 Fixed in 1.3.12 CVE-2025-58227 Patchstack
4.3 Medium Website Chat Button: Kommo integration Plugin website-chat-button-kommo-integration Broken Access Control ≤ 1.3.1 CVE-2025-58666 Patchstack
6.4 Medium Html Social share buttons Plugin html-social-share-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.16 CVE-2025-9849 Wordfence
6.4 Medium OSM Map Widget for Elementor Plugin osm-map-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL ≤ 1.3.0 CVE-2025-8619 Wordfence
6.4 Medium Anber Elementor Addon Plugin anber-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Banner button link ≤ 1.0.1 CVE-2025-7439 Wordfence
6.4 Medium Anber Elementor Addon Plugin anber-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Carousel button link ≤ 1.0.1 CVE-2025-7440 Wordfence
4.3 Medium Button Block Plugin button-block Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-54694 Patchstack
5.3 Medium WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons Plugin easy-sticky-sidebar Broken Access Control Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unauthenticated Sticky Status Update No login needed ≤ 1.7.0 CVE-2025-8152 Wordfence
6.1 Medium Avishi WP PayPal Payment Button Plugin avishi-wp-paypal-payment-button Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-7669 Wordfence
6.4 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit <= 2.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via button+modal Widget ≤ 2.5.4 CVE-2025-2330 Wordfence
6.4 Medium Magic Buttons for Elementor Plugin magic-buttons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode ≤ 1.0 CVE-2025-6686 Wordfence
6.4 Medium Magic Buttons for Elementor Plugin magic-buttons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode ≤ 1.0 CVE-2025-6687 Wordfence
6.4 Medium e.nigma buttons Plugin enigma-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.3 CVE-2025-5535 Wordfence
6.4 Medium TableOn – WordPress Posts Table Filterable Plugin posts-table-filterable Cross-Site Scripting WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode ≤ 1.0.4.1 CVE-2025-5143 Wordfence
5.4 Medium WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily Plugin innovs-woo-manager Broken Access Control Customize and Control Cart page, Add to Cart button, Checkout fields easily plugin <= 1.2.4.5 - Broken Access Control ≤ 1.2.4.5 CVE-2025-50008 Patchstack
6.4 Medium Minimal Share Buttons Plugin minimal-share-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter ≤ 1.7.3 CVE-2025-5259 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link ≤ 2.0.0 CVE-2024-13427 Wordfence
6.5 Medium Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget Broken Access Control Call To Action, Sticky CTA, Floating Button Plugin <= 1.1.1 - Settings Change No login needed ≤ 1.1.1 Fixed in 1.2.1 CVE-2025-47529 Patchstack
6.4 Medium Animated Buttons Plugin animated-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-4221 Wordfence
6.5 Medium Change Add to Cart Button Text for WooCommerce Plugin add-to-cart-button-labels-for-woocommerce Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-48254 Patchstack
6.5 Medium Back Button Widget Plugin back-button-widget Cross-Site Scripting ≤ 1.6.8 Fixed in 1.7.0 CVE-2025-48252 Patchstack
4.8 Medium Better Follow Button for Jetpack Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 8.0 CVE-2023-7168 WPScan
6.1 Medium Download HTML TinyMCE Button Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2 CVE-2025-1286 WPScan
4.8 Medium Social Media Share Buttons Plugin Cross-Site Scripting Admin+ Stored XSS < 2.9.1 Fixed in 2.9.1 CVE-2024-10362 WPScan
6.5 Medium BNS Twitter Follow Button Plugin bns-twitter-follow-button Cross-Site Scripting ≤ 0.3.8 CVE-2025-47578 Patchstack
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets ≤ 2.6.12 CVE-2025-2944 Wordfence
5.9 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting ≤ 2.0 Fixed in 2.0.1 CVE-2025-47623 Patchstack
4.3 Medium LessButtons Social Sharing and Statistics Plugin lessbuttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.6.1 CVE-2025-47614 Patchstack
6.1 Medium Add Google +1 (Plus one) social share Button Plugin add-google-plus-one-social-share-button Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-3866 Wordfence
6.5 Medium Peadig’s Google +1 Button Plugin google-1 Cross-Site Scripting ≤ 0.1.2 CVE-2025-46483 Patchstack
5.9 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting ≤ 9.8.3 Fixed in 9.8.4 CVE-2025-39444 Patchstack
4.8 Medium Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Scripting Admin+ Stored XSS < 6.0.0 Fixed in 6.0.0 CVE-2024-13610 WPScan
4.3 Medium Social Share Buttons & Analytics Plugin – GetSocial.io Plugin wp-share-buttons-analytics-by-getsocial Broken Access Control ≤ 4.5 CVE-2025-32239 Patchstack
5.9 Medium Beam me up Scotty Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) ≤ 1.0.23 CVE-2025-31864 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
6.1 Medium Razorpay Subscription Button Elementor Plugin razorpay-subscription-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed ≤ 1.0.3 CVE-2024-13827 Wordfence
6.4 Medium Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Plugin chaty Cross-Site Scripting Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.3.5 CVE-2025-1450 Wordfence
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
6.5 Medium Hover Image Button Plugin hover-image-button Cross-Site Scripting ≤ 1.1.2 CVE-2025-27266 Patchstack
4.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Cross-Site Request Forgery Cross-Site Request Forgery to Custom CSS Update No login needed ≤ 3.51 CVE-2024-13883 Wordfence
6.4 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting Get Paid with PayPal, Square & Stripe <= 3.20.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.0 CVE-2024-11895 Wordfence
5.5 Medium Reaction Buttons Plugin reaction-buttons Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.1.6 CVE-2024-13848 Wordfence
4.8 Medium Social Share Buttons Plugin share-button Cross-Site Scripting Admin+ Stored XSS ≤ 2.7 CVE-2024-12807 WPScan
6.5 Medium Social Share Buttons Plugin share-button Path Traversal Unauthenticated Image Upload & Path Traversal No login needed ≤ 2.7 CVE-2024-13117 WPScan
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
6.5 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting ≤ 3.20.0 Fixed in 3.30.0 CVE-2025-22661 Patchstack
6.4 Medium FireCask Like & Share Button Plugin facebook-like-send-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 1.2 CVE-2024-11226 Wordfence
6.4 Medium Payment Button for PayPal Plugin wp-paypal Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3.35 CVE-2024-13401 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only