WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–100 of 151 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Frontend Dashboard | Cross-Site Scripting |
≤ 2.2.8 Fixed in 2.2.9 |
CVE-2025-49310 |
Patchstack | |
| 4.3 Medium | Broken Link Checker | Broken Access Control Missing Autorization to Authenticated (Subscriber+) Plugin Status Dashboard View |
≤ 2.4.4 |
CVE-2025-4047 |
Wordfence | |
| 6.1 Medium | WordPress Gearside Developer Dashboard | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.0.72 |
CVE-2025-4429 |
WPScan | |
| 9.8 Critical | Dash | PHP Object Injection No login needed |
≤ 1.3 |
CVE-2025-31049 |
Patchstack | |
| 6.5 Medium | Uncanny Toolkit for LearnDash | Cross-Site Scripting |
≤ 3.7.0.2 Fixed in 3.7.0.3 |
CVE-2025-48080 |
Patchstack | |
| 7.5 High | wp-dashboard-notes | Broken Access Control Contributor+ Arbitrary Private Notes Update via IDOR No login needed |
< 1.0.11 Fixed in 1.0.11 |
CVE-2023-7239 |
WPScan | |
| 5.4 Medium | LogDash Activity Log | SQL Injection Unauthenticated SQLi |
< 1.1.4 Fixed in 1.1.4 |
CVE-2023-6030 |
WPScan | |
| 8.8 High | UiPress lite | Effortless custom dashboards, admin themes and pages | Remote Code Execution Authenticated (Subscriber+) Remote Code Execution |
≤ 3.5.07 |
CVE-2025-3053 |
Wordfence | |
| 8.8 High | Frontend Dashboard | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function Function |
1.0 – 2.2.7 |
CVE-2025-4474 |
Wordfence | |
| 8.8 High | Frontend Dashboard | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via ajax_request Function |
1.5.10 – 2.2.7 |
CVE-2025-4473 |
Wordfence | |
| 9.8 Critical | Frontend Dashboard | Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function No login needed |
1.0 – 2.2.6 |
CVE-2025-4104 |
Wordfence | |
| 9.3 Critical | Frontend Dashboard | SQL Injection No login needed |
≤ 2.2.5 Fixed in 2.2.6 |
CVE-2025-46248 |
Patchstack | |
| 6.5 Medium | WordPress Dashboard Tweeter | Broken Access Control Settings Change No login needed |
≤ 1.3.2 |
CVE-2025-23906 |
Patchstack | |
| 5.8 Medium | Dashi | Broken Access Control No login needed |
≤ 3.1.8 Fixed in 3.1.9 |
CVE-2025-39580 |
Patchstack | |
| 6.5 Medium | Data Dash | Cross-Site Scripting |
≤ 1.2.3 |
CVE-2025-22340 |
Patchstack | |
| 7.1 High | Dashboard Notepads | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.1 |
CVE-2025-39441 |
Patchstack | |
| 3.5 Low | Ultimate Dashboard | Cross-Site Scripting Admin+ Stored XSS |
< 3.8.6 Fixed in 3.8.6 |
CVE-2025-1525 |
WPScan | |
| 3.5 Low | Ultimate Dashboard | Cross-Site Scripting Admin+ Stored XSS |
< 3.8.6 Fixed in 3.8.6 |
CVE-2025-1524 |
WPScan | |
| 3.5 Low | Ultimate Dashboard | Cross-Site Scripting Admin+ Stored XSS |
< 3.8.6 Fixed in 3.8.6 |
CVE-2025-1523 |
WPScan | |
| 6.5 Medium | Uncanny Toolkit for LearnDash | Cross-Site Scripting |
≤ 3.7.0.1 Fixed in 3.7.0.2 |
CVE-2025-22268 |
Patchstack | |
| 7.5 High | Material Dashboard | Local File Inclusion |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2025-31014 |
Patchstack | |
| 4.3 Medium | ShareThis Dashboard for Google Analytics | Cross-Site Request Forgery No login needed |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2025-32282 |
Patchstack | |
| 6.5 Medium | Chamber Dashboard Business Directory | Cross-Site Scripting |
≤ 3.3.11 |
CVE-2025-32162 |
Patchstack | |
| 8.1 High | Material Dashboard | Local File Inclusion No login needed |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2025-31097 |
Patchstack | |
| 9.8 Critical | Material Dashboard | Privilege Escalation No login needed |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2025-31095 |
Patchstack | |
| 4.3 Medium | Ultimate Dashboard | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Modules Activation/Deactivation |
≤ 3.8.7 |
CVE-2025-2276 |
Wordfence | |
| 5.3 Medium | ShareThis Dashboard for Google Analytics | Broken Access Control Missing Authorization to Unauthenticated Feature Deactivation No login needed |
≤ 3.2.1 |
CVE-2025-1507 |
Wordfence | |
| 4.3 Medium | Custom Dashboard Page | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-28912 |
Patchstack | |
| 8.8 High | UiPress lite | Effortless custom dashboards, admin themes and pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update |
≤ 3.5.04 |
CVE-2025-1309 |
Wordfence | |
| 4.3 Medium | System Dashboard | Information Disclosure Sensitive Data Exposure |
≤ 2.8.18 Fixed in 2.8.19 |
CVE-2025-26911 |
Patchstack | |
| 7.1 High | Fast Flow | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.16 Fixed in 1.2.18 |
CVE-2025-26868 |
Patchstack | |
| 6.4 Medium | C9 Admin Dashboard | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.3.5 |
CVE-2024-13379 |
Wordfence | |
| 6.4 Medium | ADFO – Custom data in admin dashboard | Cross-Site Scripting Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.1 |
CVE-2024-13390 |
Wordfence | |
| 7.1 High | Data Dash | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.3 |
CVE-2025-23751 |
Patchstack | |
| 7.1 High | Kv Compose Email From Dashboard | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-23525 |
Patchstack | |
| 7.1 High | Live Dashboard | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.3.3 |
CVE-2025-23474 |
Patchstack | |
| 7.1 High | Custom Links On Admin Dashboard Toolbar | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 3.3 |
CVE-2025-25135 |
Patchstack | |
| 6.1 Medium | System Dashboard | Cross-Site Scripting Reflected Cross-Site Scripting via Filename Parameter No login needed |
≤ 2.8.17 |
CVE-2024-12299 |
Wordfence | |
| 9.8 Critical | iControlWP – Multiple WordPress Site Manager | PHP Object Injection Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection No login needed |
≤ 4.4.5 |
CVE-2024-13742 |
Wordfence | |
| 5.3 Medium | LearnDash LMS | Broken Access Control No login needed |
≤ 4.20.0.1 Fixed in 4.20.0.3 |
CVE-2025-24662 |
Patchstack | |
| 5.4 Medium | ExactMetrics | Broken Access Control |
≤ 8.1.0 Fixed in 8.2.0 |
CVE-2025-24750 |
Patchstack | |
| 7.1 High | FLX Dashboard Groups | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.0.7 |
CVE-2025-23730 |
Patchstack | |
| 9.8 Critical | Muzaara Google Ads Report | PHP Object Injection No login needed |
≤ 3.1 |
CVE-2025-23914 |
Patchstack | |
| 5.4 Medium | Chamber Dashboard Business Directory | Broken Access Control |
≤ 3.3.8 |
CVE-2025-23917 |
Patchstack | |
| 6.4 Medium | Chamber Dashboard Business Directory | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.3.8 |
CVE-2024-11452 |
Wordfence | |
| 6.4 Medium | Course Migration for LearnDash | Server-Side Request Forgery |
1.0.2 |
CVE-2025-22346 |
Patchstack | |
| 5.3 Medium | Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords | Information Disclosure Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure No login needed |
≤ 3.1 |
CVE-2024-12159 |
Wordfence | |
| 6.5 Medium | Analytify | Privilege Escalation Google Analytics Dashboard plugin <= 4.2.3 - Privilege Escalation No login needed |
≤ 4.2.3 Fixed in 4.3.0 |
CVE-2022-45830 |
Patchstack | |
| 5.4 Medium | Uncanny Toolkit Pro for LearnDash | Cross-Site Request Forgery No login needed |
< 4.1.4.1 Fixed in 4.1.4.1 |
CVE-2024-37438 |
Patchstack | |
| 7.1 High | Custom Dashboard Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2024-56024 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.