WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 246 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-62063 Patchstack
6.5 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2025-62019 Patchstack
6.4 Medium Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Cross-Site Scripting Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.7.1 CVE-2025-11270 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
6.3 Medium Schema Plugin For Divi, Gutenberg & Shortcodes Plugin wp-structured-data-schema PHP Object Injection Authenticated (Contributor+) Object Instantiation ≤ 4.3.2 CVE-2025-7825 Wordfence
6.4 Medium ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Plugin zoloblocks Cross-Site Scripting Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.10 CVE-2025-9075 Wordfence
6.4 Medium GutenBee – Gutenberg Blocks Plugin gutenbee Cross-Site Scripting Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.18.0 CVE-2025-8566 Wordfence
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Information Disclosure Sensitive Data Exposure ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60095 Patchstack
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Broken Access Control ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60094 Patchstack
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.0 CVE-2025-8607 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Server-Side Request Forgery Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 2.0.0 CVE-2025-8680 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 2.0.0 CVE-2025-8676 Wordfence
5.9 Medium OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.2.0 CVE-2025-6572 WPScan
6.4 Medium BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites Plugin blockspare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets ≤ 3.2.13.1 CVE-2025-4684 Wordfence
6.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.4.8 CVE-2025-4685 Wordfence
6.4 Medium Kadence Blocks – Gutenberg Blocks for Page Builder Features Plugin kadence-blocks Cross-Site Scripting Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter ≤ 3.5.10 CVE-2025-5678 Wordfence
6.5 Medium Gutenberg Blocks Plugin advanced-gutenberg Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-49032 Patchstack
6.5 Medium Enhanced Blocks – Page Builder Blocks for Gutenberg Plugin enhanced-blocks Broken Access Control Page Builder Blocks for Gutenberg plugin <= 1.4.1 - Broken Access Control ≤ 1.4.1 CVE-2025-50034 Patchstack
6.5 Medium Gutenberg Blocks – ACF Blocks Suite Plugin acf-blocks Cross-Site Scripting ACF Blocks Suite plugin <= 2.6.11 - Cross Site Scripting (XSS) ≤ 2.6.11 CVE-2025-50041 Patchstack
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
5.4 Medium Post Grid and Gutenberg Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.2.93 Fixed in 2.2.93 CVE-2024-9645 WPScan
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) ≤ 2.7.7.25 Fixed in 2.7.7.26 CVE-2025-47677 Patchstack
5.3 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control No login needed ≤ 3.1.9 Fixed in 3.2.0 CVE-2025-47486 Patchstack
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.4 Medium Advanced Accordion Gutenberg Block Plugin advanced-accordion-block Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 5.0.2 CVE-2025-2543 Wordfence
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 2.1 CVE-2025-46235 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.9 CVE-2025-26998 Patchstack
6.4 Medium Logo Carousel Gutenberg Block Plugin awesome-logo-carousel-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter ≤ 2.1.6 CVE-2025-2083 Wordfence
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2025-3276 Wordfence
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence
6.5 Medium Gutena Kit – Gutenberg Blocks and Templates Plugin gutena-kit Cross-Site Scripting ≤ 2.0.7 CVE-2025-31805 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.19.0 CVE-2025-1784 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
4.3 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Information Disclosure Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content ≤ 1.8.13 CVE-2024-13228 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 CVE-2025-1664 Wordfence
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.0 CVE-2024-13675 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' ≤ 3.4.9 CVE-2025-1291 Wordfence
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Information Disclosure ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure No login needed ≤ 2.3.6 CVE-2024-13796 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.3 CVE-2024-13803 Wordfence
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-26983 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.8.3 Fixed in 4.8.4 CVE-2025-26871 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin Broken Access Control ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation No login needed ≤ 2.3.5 CVE-2024-13798 Wordfence
6.4 Medium UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included Plugin ultraembed-advanced-iframe Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11335 Wordfence
6.4 Medium aBlocks – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.1 CVE-2024-13465 Wordfence
6.5 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Cross-Site Scripting Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID' ≤ 1.8.12 CVE-2024-9601 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleTag Parameter ≤ 3.6 CVE-2025-0506 Wordfence
6.5 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-25080 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only