WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 179 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Elementor Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path ≤ 3.33.3 CVE-2025-11220 Wordfence
4.3 Medium Resource Library for Logged In Users Plugin doubledome-resource-link-library Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed ≤ 1.5 CVE-2025-14354 Wordfence
5.4 Medium Listdom Plugin listdom Broken Access Control ≤ 5.0.1 Fixed in 5.1.0 CVE-2025-67560 Patchstack
6.4 Medium Multiple Plugins and Themes <= (Various Versions) Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library ≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … CVE-2025-5092 Wordfence
5.5 Medium RandomQuotr Plugin randomquotr Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2025-12632 Wordfence
5.3 Medium DominoKit Plugin dominokit Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.1.0 CVE-2025-12350 Wordfence
6.5 Medium Woo superb slideshow transition gallery with random effect Plugin woo-superb-slideshow-transition-gallery-with-random-effect SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.1 CVE-2025-9199 Wordfence
6.4 Medium Easy Social Feed – Social Photos Gallery – Post Feed – Like Box Plugin easy-facebook-likebox Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.6.7 CVE-2025-6067 Wordfence
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.4.7 CVE-2025-7496 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' ≤ 6.2.2 CVE-2025-8451 Wordfence
6.4 Medium MetForm Plugin metform Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element ≤ 4.0.1 CVE-2025-5684 Wordfence
6.4 Medium Wonder Slider Lite & Wonder Slider Plugin wonderplugin-slider-lite Cross-Site Scripting Authenticated (Contributor+) Dom-based Stored Cross-Site Scripting ≤ 14.4 CVE-2025-7501 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 CVE-2025-6068 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library ≤ 2.6.7, ≤ 3.5, ≤ 3.59.11 CVE-2025-2537 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin wp-video-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via prettyPhoto JavaScript Library ≤ 1.0, ≤ 1.5.2, ≤ 1.8.6.6, … CVE-2025-2540 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library ≤ 2.0.5, ≤ 2.2.14, ≤ 2.5.52, … CVE-2024-5647 Wordfence
6.4 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute 8.0.0 CVE-2025-5944 Wordfence
6.1 Medium Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer Plugin 3d-flipbook-dflip-lite Cross-Site Scripting PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source' No login needed ≤ 2.3.65 CVE-2025-5314 Wordfence
8.1 High Domnoo Plugin domnoo Local File Inclusion No login needed ≤ 1.49 Fixed in 1.52.1 CVE-2025-52812 Patchstack
6.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets ≤ 1.7.1028 CVE-2025-5338 Wordfence
6.4 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `data-url` DOM Element Attribute ≤ 1.68.5 CVE-2025-5585 Wordfence
5.9 Medium Better Random Redirect Plugin better-random-redirect Cross-Site Scripting ≤ 1.3.20 CVE-2025-50021 Patchstack
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
6.4 Medium Click to Chat Plugin click-to-chat-for-whatsapp Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via data-no_number Parameter ≤ 4.22 CVE-2025-5336 Wordfence
6.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.13.2 CVE-2025-5144 Wordfence
6.4 Medium Domain For Sale Plugin domain-for-sale Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class_name Parameter ≤ 3.0.10 CVE-2025-5239 Wordfence
6.4 Medium Forminator Plugin forminator Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters ≤ 1.44.1 CVE-2025-5341 Wordfence
6.4 Medium Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder Plugin Cross-Site Scripting Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.11.2 CVE-2025-5292 Wordfence
9.8 Critical PSW Front-end Login & Registration Plugin psw-login-and-registration Privilege Escalation Insufficiently Random Values to Unauthenticated Account Takeover/Privilege Escalation via customer_registration Function No login needed ≤ 1.12 CVE-2025-4607 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter ≤ 1.5.2 CVE-2025-4943 Wordfence
6.4 Medium TablePress Plugin tablepress Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters ≤ 3.1.2 CVE-2025-5096 Wordfence
4.3 Medium Hot Random Image Plugin hot-random-image Path Traversal Path Traversal to Authenticated (Contributor+) Limited Arbitrary Image Access via path Parameter ≤ 1.9.2 CVE-2025-4419 Wordfence
4.9 Medium Hot Random Image Plugin hot-random-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via link Parameter ≤ 1.9.2 CVE-2025-4405 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library ≤ 2.14.4, ≤ 3.59.4 CVE-2024-5878 Wordfence
5.9 Medium Submission DOM tracking for Contact Form 7 Plugin cf7-submission-dom-tracking Cross-Site Scripting ≤ 2.1 Fixed in 2.2 CVE-2025-47626 Patchstack
5.9 Medium Landing pages and Domain aliases Plugin landing-pages-and-domain-aliases Cross-Site Scripting ≤ 0.8 CVE-2025-46533 Patchstack
6.4 Medium WP Import Export Lite Plugin wp-import-export-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.9.27 CVE-2025-2839 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.28 CVE-2025-1457 Wordfence
4.7 Medium Listdom Plugin listdom Open Redirect No login needed ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-39599 Patchstack
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1012 CVE-2025-1456 Wordfence
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-31903 Patchstack
6.4 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library ≤ 2.10.1 CVE-2024-9416 Wordfence
9.3 Critical XV Random Quotes Plugin xv-random-quotes SQL Injection No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-30971 Patchstack
7.1 High Random Quotes Plugin random-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-27267 Patchstack
7.1 High Random Image Selector Plugin random-image-selector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26548 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
6.4 Medium Finale Lite – Sales Countdown Timer & Discount for WooCommerce Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer ≤ 2.19.0 CVE-2024-12589 Wordfence
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
4.3 Medium XV Random Quotes Plugin xv-random-quotes Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 1.40 CVE-2024-13580 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only