WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 131 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Canadian Nutrition Facts Label Plugin canadian-nutrition-facts-label Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Nutrition Label Custom Post Type ≤ 3.0 CVE-2025-12715 Wordfence
9.8 Critical Atarim Plugin atarim-visual-collaboration Privilege Escalation No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60195 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60188 Patchstack
4.8 Medium Atarim Plugin atarim-visual-collaboration Arbitrary File Upload No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60187 Patchstack
6.1 Medium Label Plugins Plugin label-plugins Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.5 CVE-2025-12401 Wordfence
5.3 Medium Atarim Plugin atarim-visual-collaboration Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-62895 Patchstack
6.4 Medium Countdown Timer for Elementor Plugin countdown-timer-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'countdown_label' ≤ 1.3.9 CVE-2025-8445 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox ≤ 2.0.9.0 CVE-2025-8874 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.8.2 CVE-2025-5284 Wordfence
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
4.3 Medium AI Image Lab – Free AI Image Generator Plugin ai-image-generator-lab Cross-Site Request Forgery Free AI Image Generator <= 1.0.6 - Cross-Site Request Forgery to API Key Update No login needed ≤ 1.0.6 CVE-2025-4592 Wordfence
8.1 High Lab Plugin lab Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-26592 Patchstack
5.3 Medium FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Broken Access Control No login needed ≤ 2.22.11 Fixed in 2.22.12 CVE-2025-49320 Patchstack
8.1 High La Boom Theme laboom Local File Inclusion No login needed ≤ 2.7 CVE-2025-31632 Patchstack
6.5 Medium Change Add to Cart Button Text for WooCommerce Plugin add-to-cart-button-labels-for-woocommerce Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-48254 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High CRUDLab Scroll to Top Plugin crudlab-scroll-to-top Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-22774 Patchstack
6.5 Medium Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) Plugin swatchly Broken Access Control WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) 1.2.8 - 1.4.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update 1.2.8 – 1.4.0 CVE-2025-2719 Wordfence
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.15 Fixed in 2.16 CVE-2025-32188 Patchstack
7.1 High LeadLab by wiredminds Plugin wiredminds-leadlab Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-31568 Patchstack
4.3 Medium Labinator Content Types Duplicator Plugin labinator-content-types-duplicator Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31809 Patchstack
5.5 Medium Groundhogg Plugin groundhogg Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter ≤ 3.7.4.1 CVE-2025-1267 Wordfence
6.5 Medium Shipmondo – A complete shipping solution for WooCommerce Plugin pakkelabels-for-woocommerce Information Disclosure A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated Arbitrary WordPress Option Disclosure ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-27001 Patchstack
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.9 Fixed in 1.5.9 CVE-2024-12109 WPScan
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.11 Fixed in 1.5.11 CVE-2024-10638 WPScan
4.3 Medium I Am Gloria Plugin gloria-assistant-by-webtronic-labs Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-0990 Wordfence
7.1 High Local Shipping Labels for WooCommerce Plugin local-shipping-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23903 Patchstack
7.1 High CRUDLab Like Box Plugin crudlab-facebook-like-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.9 CVE-2025-23814 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-26993 Patchstack
6.5 Medium WP Responsive Auto Fit Text Plugin wp-responsive-slab-text Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2025-26904 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.9 Fixed in 4.1.0 CVE-2025-22657 Patchstack
7.1 High DK White Label Plugin dk-white-label Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-24541 Patchstack
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting No login needed ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-24570 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
5.3 Medium Visual Website Collaboration, Feedback & Project Management – Atarim Plugin Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed ≤ 4.0.9 CVE-2024-12104 Wordfence
6.4 Medium Page Builder by SiteOrigin Plugin siteorigin-panels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter ≤ 2.31.0 CVE-2024-12240 Wordfence
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
5.4 Medium WP iCal Availability Plugin wp-ical-availability Broken Access Control No login needed ≤ 1.0.3 CVE-2023-46607 Patchstack
7.1 High CRUDLab Google Plus Button Plugin crudlab-google-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2024-54399 Patchstack
7.1 High LabelGrid Tools Plugin label-grid-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.58 Fixed in 1.3.59 CVE-2024-54341 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
6.1 Medium Branda – White Label & Branding, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scripting No login needed ≤ 3.4.21 CVE-2024-9371 Wordfence
7.1 High FraudLabs Pro SMS Verification Plugin fraudlabs-pro-sms-verification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2024-51688 Patchstack
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2024-38771 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-43290 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only