WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 286 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
5.4 Medium Lottier Plugin lottier-gutenberg Broken Access Control ≤ 1.1.1 CVE-2025-66167 Patchstack
5.4 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Contributor+ reCAPTCHA Settings Change ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23729 Patchstack
6.5 Medium Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons Plugin gutenverse-news Broken Access Control Advanced News Magazine Blog Gutenberg Blocks Addons plugin <= 3.0.2 - Broken Access Control ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-62090 Patchstack
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute ≤ 2.2.13 CVE-2025-13697 Wordfence
5.4 Medium Progress Bar Blocks for Gutenberg Plugin progressmatify-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.0.0 CVE-2025-12880 Wordfence
6.4 Medium Spectra Plugin ultimate-addons-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS ≤ 2.19.14 CVE-2025-11162 Wordfence
6.5 Medium Gutenberg Plugin gutenberg Cross-Site Scripting ≤ 21.8.2 Fixed in 21.9.0 CVE-2025-64354 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-62924 Patchstack
6.4 Medium Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks Plugin advanced-gutenberg Cross-Site Scripting PublishPress Blocks Controls, Visibility, Reusable Blocks <= 3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.3.4 CVE-2025-8588 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-62063 Patchstack
6.5 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2025-62019 Patchstack
6.4 Medium Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Cross-Site Scripting Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.7.1 CVE-2025-11270 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
6.3 Medium Schema Plugin For Divi, Gutenberg & Shortcodes Plugin wp-structured-data-schema PHP Object Injection Authenticated (Contributor+) Object Instantiation ≤ 4.3.2 CVE-2025-7825 Wordfence
6.4 Medium ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Plugin zoloblocks Cross-Site Scripting Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.10 CVE-2025-9075 Wordfence
6.4 Medium GutenBee – Gutenberg Blocks Plugin gutenbee Cross-Site Scripting Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.18.0 CVE-2025-8566 Wordfence
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Information Disclosure Sensitive Data Exposure ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60095 Patchstack
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Broken Access Control ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60094 Patchstack
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.0 CVE-2025-8607 Wordfence
8.1 High WP Travel Gutenberg Blocks Plugin wp-travel-blocks Local File Inclusion No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2025-53207 Patchstack
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-54007 Patchstack
7.5 High Otter - Gutenberg Block Plugin otter-blocks Information Disclosure Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-55715 Patchstack
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Server-Side Request Forgery Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 2.0.0 CVE-2025-8680 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 2.0.0 CVE-2025-8676 Wordfence
7.5 High Gutenberg Blocks Plugin advanced-gutenberg Local File Inclusion No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-48332 Patchstack
8.8 High B Slider- Gutenberg Slider Block for WP Plugin b-slider Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation ≤ 1.1.30 CVE-2025-8418 Wordfence
5.9 Medium OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.2.0 CVE-2025-6572 WPScan
6.4 Medium BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites Plugin blockspare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets ≤ 3.2.13.1 CVE-2025-4684 Wordfence
6.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.4.8 CVE-2025-4685 Wordfence
9.8 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.1 CVE-2025-7340 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Path Traversal Directory Traversal to Arbitrary File Move No login needed ≤ 2.2.1 CVE-2025-7360 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.1 CVE-2025-7341 Wordfence
6.4 Medium Kadence Blocks – Gutenberg Blocks for Page Builder Features Plugin kadence-blocks Cross-Site Scripting Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter ≤ 3.5.10 CVE-2025-5678 Wordfence
6.5 Medium Gutenberg Blocks Plugin advanced-gutenberg Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-49032 Patchstack
6.5 Medium Enhanced Blocks – Page Builder Blocks for Gutenberg Plugin enhanced-blocks Broken Access Control Page Builder Blocks for Gutenberg plugin <= 1.4.1 - Broken Access Control ≤ 1.4.1 CVE-2025-50034 Patchstack
6.5 Medium Gutenberg Blocks – ACF Blocks Suite Plugin acf-blocks Cross-Site Scripting ACF Blocks Suite plugin <= 2.6.11 - Cross Site Scripting (XSS) ≤ 2.6.11 CVE-2025-50041 Patchstack
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
5.4 Medium Post Grid and Gutenberg Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.2.93 Fixed in 2.2.93 CVE-2024-9645 WPScan
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) ≤ 2.7.7.25 Fixed in 2.7.7.26 CVE-2025-47677 Patchstack
5.3 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control No login needed ≤ 3.1.9 Fixed in 3.2.0 CVE-2025-47486 Patchstack
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.4 Medium Advanced Accordion Gutenberg Block Plugin advanced-accordion-block Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 5.0.2 CVE-2025-2543 Wordfence
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 2.1 CVE-2025-46235 Patchstack
7.1 High Cool Flipbox – Shortcode & Gutenberg Block Plugin flip-boxes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-32521 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.9 CVE-2025-26998 Patchstack
6.4 Medium Logo Carousel Gutenberg Block Plugin awesome-logo-carousel-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter ≤ 2.1.6 CVE-2025-2083 Wordfence
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2025-3276 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only