WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 51–100 of 179 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path |
≤ 3.33.3 |
CVE-2025-11220 |
Wordfence | |
| 4.3 Medium | Resource Library for Logged In Users | Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed |
≤ 1.5 |
CVE-2025-14354 |
Wordfence | |
| 5.4 Medium | Listdom | Broken Access Control |
≤ 5.0.1 Fixed in 5.1.0 |
CVE-2025-67560 |
Patchstack | |
| 6.4 Medium | Multiple Plugins and Themes <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library |
≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … |
CVE-2025-5092 |
Wordfence | |
| 5.5 Medium | RandomQuotr | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0.4 |
CVE-2025-12632 |
Wordfence | |
| 5.3 Medium | DominoKit | Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-12350 |
Wordfence | |
| 6.5 Medium | Woo superb slideshow transition gallery with random effect | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 9.1 |
CVE-2025-9199 |
Wordfence | |
| 6.4 Medium | Easy Social Feed – Social Photos Gallery – Post Feed – Like Box | Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 6.6.7 |
CVE-2025-6067 |
Wordfence | |
| 6.4 Medium | WPC Smart Compare for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 6.4.7 |
CVE-2025-7496 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Popular Elementor Templates and Widgets | Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' |
≤ 6.2.2 |
CVE-2025-8451 |
Wordfence | |
| 6.4 Medium | MetForm | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element |
≤ 4.0.1 |
CVE-2025-5684 |
Wordfence | |
| 6.4 Medium | Wonder Slider Lite & Wonder Slider | Cross-Site Scripting Authenticated (Contributor+) Dom-based Stored Cross-Site Scripting |
≤ 14.4 |
CVE-2025-7501 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.4.31 |
CVE-2025-6068 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library |
≤ 2.6.7, ≤ 3.5, ≤ 3.59.11 |
CVE-2025-2537 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via prettyPhoto JavaScript Library |
≤ 1.0, ≤ 1.5.2, ≤ 1.8.6.6, … |
CVE-2025-2540 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library |
≤ 2.0.5, ≤ 2.2.14, ≤ 2.5.52, … |
CVE-2024-5647 |
Wordfence | |
| 6.4 Medium | Element Pack Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute |
8.0.0 |
CVE-2025-5944 |
Wordfence | |
| 6.1 Medium | Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer | Cross-Site Scripting PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source' No login needed |
≤ 2.3.65 |
CVE-2025-5314 |
Wordfence | |
| 8.1 High | Domnoo | Local File Inclusion No login needed |
≤ 1.49 Fixed in 1.52.1 |
CVE-2025-52812 |
Patchstack | |
| 6.4 Medium | Royal Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets |
≤ 1.7.1028 |
CVE-2025-5338 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `data-url` DOM Element Attribute |
≤ 1.68.5 |
CVE-2025-5585 |
Wordfence | |
| 5.9 Medium | Better Random Redirect | Cross-Site Scripting |
≤ 1.3.20 |
CVE-2025-50021 |
Patchstack | |
| 6.4 Medium | Slider, Gallery, and Carousel by MetaSlider | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter |
≤ 3.98.0 |
CVE-2025-5337 |
Wordfence | |
| 6.4 Medium | Click to Chat | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via data-no_number Parameter |
≤ 4.22 |
CVE-2025-5336 |
Wordfence | |
| 6.4 Medium | The Events Calendar | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 6.13.2 |
CVE-2025-5144 |
Wordfence | |
| 6.4 Medium | Domain For Sale | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class_name Parameter |
≤ 3.0.10 |
CVE-2025-5239 |
Wordfence | |
| 6.4 Medium | Forminator | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters |
≤ 1.44.1 |
CVE-2025-5341 |
Wordfence | |
| 6.4 Medium | Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder | Cross-Site Scripting Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 5.11.2 |
CVE-2025-5292 |
Wordfence | |
| 9.8 Critical | PSW Front-end Login & Registration | Privilege Escalation Insufficiently Random Values to Unauthenticated Account Takeover/Privilege Escalation via customer_registration Function No login needed |
≤ 1.12 |
CVE-2025-4607 |
Wordfence | |
| 6.4 Medium | LA-Studio Element Kit for Elementor | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter |
≤ 1.5.2 |
CVE-2025-4943 |
Wordfence | |
| 6.4 Medium | TablePress | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters |
≤ 3.1.2 |
CVE-2025-5096 |
Wordfence | |
| 4.3 Medium | Hot Random Image | Path Traversal Path Traversal to Authenticated (Contributor+) Limited Arbitrary Image Access via path Parameter |
≤ 1.9.2 |
CVE-2025-4419 |
Wordfence | |
| 4.9 Medium | Hot Random Image | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via link Parameter |
≤ 1.9.2 |
CVE-2025-4405 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library |
≤ 2.14.4, ≤ 3.59.4 |
CVE-2024-5878 |
Wordfence | |
| 5.9 Medium | Submission DOM tracking for Contact Form 7 | Cross-Site Scripting |
≤ 2.1 Fixed in 2.2 |
CVE-2025-47626 |
Patchstack | |
| 5.9 Medium | Landing pages and Domain aliases | Cross-Site Scripting |
≤ 0.8 |
CVE-2025-46533 |
Patchstack | |
| 6.4 Medium | WP Import Export Lite | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 3.9.27 |
CVE-2025-2839 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 5.10.28 |
CVE-2025-1457 |
Wordfence | |
| 4.7 Medium | Listdom | Open Redirect No login needed |
≤ 4.0.0 Fixed in 4.1.0 |
CVE-2025-39599 |
Patchstack | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.1012 |
CVE-2025-1456 |
Wordfence | |
| 7.1 High | XV Random Quotes | Cross-Site Scripting No login needed |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2025-31903 |
Patchstack | |
| 6.4 Medium | Modula Image Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library |
≤ 2.10.1 |
CVE-2024-9416 |
Wordfence | |
| 9.3 Critical | XV Random Quotes | SQL Injection No login needed |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2025-30971 |
Patchstack | |
| 7.1 High | Random Quotes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3 |
CVE-2025-27267 |
Patchstack | |
| 7.1 High | Random Image Selector | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.4 |
CVE-2025-26548 |
Patchstack | |
| 7.1 High | Random Posts, Mp3 Player + ShareButton | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.1 |
CVE-2025-23744 |
Patchstack | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module |
≤ 3.1.0 |
CVE-2025-1527 |
Wordfence | |
| 6.4 Medium | Finale Lite – Sales Countdown Timer & Discount for WooCommerce | Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer |
≤ 2.19.0 |
CVE-2024-12589 |
Wordfence | |
| 7.1 High | Domain | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3 |
CVE-2025-28897 |
Patchstack | |
| 4.3 Medium | XV Random Quotes | Cross-Site Request Forgery Settings Reset via CSRF No login needed |
≤ 1.40 |
CVE-2024-13580 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.