WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 111 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Billplz Addon for Contact Form 7 Plugin billplz-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-31007 Patchstack
9.8 Critical Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.1.1 CVE-2025-7697 Wordfence
9.8 Critical Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.2.3 CVE-2025-7696 Wordfence
7.1 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-52777 Patchstack
4.3 Medium Contact Form 7 reCAPTCHA Plugin contact-form-7-recaptcha Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-23972 Patchstack
6.4 Medium Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode ≤ 3.5.21 CVE-2025-6756 Wordfence
5.3 Medium Accept Authorize.NET Payments Using Contact Form 7 Plugin accept-authorize-net-payments-using-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-53322 Patchstack
5.3 Medium Accept Stripe Payments Using Contact Form 7 Plugin accept-stripe-payments-using-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-53309 Patchstack
5.3 Medium Contact Form – 7 : Hide Success Message Plugin contact-form-7-hide-success-message Broken Access Control No login needed ≤ 1.1.4 CVE-2025-53304 Patchstack
8.2 High Abandoned Contact Form 7 Plugin abandoned-contact-form-7 Broken Access Control No login needed ≤ 2.2 CVE-2025-52817 Patchstack
7.2 High Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Database module No login needed 3.5.11 – 3.5.19 CVE-2025-6212 Wordfence
5.3 Medium Contact Form 7 AWeber Extension Plugin integrate-contact-form-7-and-aweber Broken Access Control No login needed ≤ 0.1.40 Fixed in 0.1.43 CVE-2025-49988 Patchstack
7.2 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'save_options' ≤ 3.5.12 CVE-2025-6220 Wordfence
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks No login needed ≤ 1.3.8.9 CVE-2025-3515 Wordfence
5.4 Medium Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Request Forgery No login needed ≤ 1.0.4 CVE-2025-24772 Patchstack
5.9 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3.4 - Cross Site Scripting (XSS) ≤ 2.3.4 Fixed in 2.4.1 CVE-2025-47518 Patchstack
5.3 Medium Contact Form 7 Plugin contact-form-7 Other Order Replay No login needed ≤ 6.0.5 CVE-2025-3247 Wordfence
5.4 Medium User Registration Using Contact Form 7 Plugin user-registration-using-contact-form-7 Cross-Site Request Forgery No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32679 Patchstack
5.3 Medium Accept SagePay Payments Using Contact Form 7 Plugin accept-sagepay-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.0 CVE-2025-2883 Wordfence
7.6 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 SQL Injection ≤ 1.0.4 CVE-2025-32126 Patchstack
4.7 Medium Integration of Zoho CRM and Contact Form 7 Plugin integration-of-zoho-crm-and-contact-form-7 Open Redirect No login needed ≤ 1.0.6 CVE-2025-31821 Patchstack
7.5 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion No login needed ≤ 1.3.8.8 CVE-2025-2485 Wordfence
8.8 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Deletion No login needed ≤ 1.3.8.7 CVE-2025-2328 Wordfence
5.9 Medium VaultRE Contact Form 7 Plugin wp-plugin-contact-form-7 Cross-Site Scripting ≤ 1.0 CVE-2025-31101 Patchstack
4.3 Medium Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-30863 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
5.9 Medium Contact Form 7 Star Rating with font Awesome Plugin contact-form-7-star-rating-with-font-awersome Cross-Site Scripting ≤ 1.3 CVE-2025-27304 Patchstack
5.9 Medium Contact Form 7 Star Rating Plugin contact-form-7-star-rating Cross-Site Scripting ≤ 1.10 CVE-2025-27303 Patchstack
5.3 Medium Drag and Drop Multiple File Upload – Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion No login needed ≤ 1.3.8.5 CVE-2024-12267 Wordfence
7.1 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23812 Patchstack
7.6 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution SQL Injection ≤ 1.2.1 CVE-2025-23784 Patchstack
5.3 Medium Contact Form 7 Anti Spambot Plugin contact-form-7-anti-spambot Broken Access Control No login needed ≤ 1.0.1 CVE-2025-23862 Patchstack
7.5 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2023-47693 Patchstack
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Request Forgery Dynamic Text Extension plugin <= 5.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.0.1 Fixed in 5.0.2 CVE-2024-56218 Patchstack
5.3 Medium Accept Authorize.NET Payments Using Contact Form 7 Plugin accept-authorize-net-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.2 CVE-2024-12250 Wordfence
7.1 High Connect Contact Form 7 to Constant Contact Plugin connect-contact-form-7-to-constant-contact-v3 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2024-54343 Patchstack
5.3 Medium Accept Stripe Payments Using Contact Form 7 Plugin accept-stripe-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.5 CVE-2024-12255 Wordfence
4.3 Medium Custom Skins Contact Form 7 Plugin custom-skins-contact-form-7 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update and Skin Creation ≤ 1.0 CVE-2024-12341 Wordfence
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
6.1 Medium Contact Form 7 - PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site Scripting No login needed ≤ 2.3.1 CVE-2024-10683 Wordfence
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Information Disclosure Dynamic Text Extension <= 4.5 - Information Disclosure via Shortcode ≤ 4.5 CVE-2024-10084 Wordfence
5.3 Medium Contact Form 7 Campaign Monitor Extension Plugin contact-form-7-campaign-monitor-extension Arbitrary File Deletion No login needed ≤ 0.4.67 CVE-2024-44019 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.3.1 CVE-2024-48021 Patchstack
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 4.1.2 CVE-2024-6317 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 4.1.2 CVE-2024-6316 Wordfence
9.6 Critical Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery CSRF to Arbitrary File Upload ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-37555 Patchstack
6.1 Medium Contact Form 7 Plugin contact-form-7 Open Redirect Unauthenticated Open Redirect No login needed < 5.9.5 Fixed in 5.9.5 CVE-2024-4704 WPScan
5.3 Medium Captcha/Honeypot for Contact Form 7 Plugin captcha-for-contact-form-7 Other Capcha Bypass No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2023-45009 Patchstack
7.2 High Frontend Registration – Contact Form 7 Plugin frontend-registration-contact-form-7 Privilege Escalation Contact Form 7 <= 5.1 - Authenticated (Editor+) Privilege Escalation ≤ 5.1 CVE-2024-4870 Wordfence
4.3 Medium Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-34817 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only