WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 51–100 of 226 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | WP Attractive Donations System - Easy Stripe & Paypal donations | Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.25 |
CVE-2025-58999 |
Patchstack | |
| 4.3 Medium | Porto Theme - Functionality | Broken Access Control Functionality plugin < 3.7.3 - Broken Access Control |
≤ 3.7.3 Fixed in 3.7.3 |
CVE-2025-63067 |
Patchstack | |
| 6.5 Medium | Porto Theme - Functionality | Cross-Site Scripting Functionality plugin < 3.7.3 - Cross Site Scripting (XSS) |
≤ 3.7.3 Fixed in 3.7.3 |
CVE-2025-63066 |
Patchstack | |
| 5.3 Medium | IDonate | Broken Access Control No login needed |
≤ 2.1.15 Fixed in 2.1.16 |
CVE-2025-67583 |
Patchstack | |
| 6.5 Medium | Donation Thermometer | Cross-Site Scripting |
≤ 2.2.6 Fixed in 2.2.7 |
CVE-2025-67550 |
Patchstack | |
| 6.1 Medium | WP-SOS-Donate Donation Sidebar | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 0.9.2 |
CVE-2025-13625 |
Wordfence | |
| 4.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' |
≤ 1.3.7.2 |
CVE-2025-13109 |
Wordfence | |
| 4.1 Medium | Donation | SQL Injection Admin+ SQLi |
≤ 1.0 |
CVE-2025-13001 |
WPScan | |
| 4.3 Medium | Admin and Customer Messages After Order for WooCommerce: OrderConvo | Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages |
≤ 14 |
CVE-2025-13452 |
Wordfence | |
| 4.3 Medium | Conditional Maintenance Mode | Cross-Site Request Forgery No login needed |
≤ 1.0.0 |
CVE-2025-12586 |
Wordfence | |
| 5.3 Medium | IDonate – Blood Donation, Request And Donor Management System | Broken Access Control Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 2.1.14 |
CVE-2025-12877 |
Wordfence | |
| 6.4 Medium | Simple Donate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11882 |
Wordfence | |
| 6.4 Medium | Paypal Donation Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1 |
CVE-2025-11859 |
Wordfence | |
| 4.9 Medium | Double the Donation | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 3.0.0 |
CVE-2025-12020 |
Wordfence | |
| 6.4 Medium | Nonaki – Drag and Drop Email Template builder and Newsletter | Cross-Site Scripting Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields |
≤ 1.0.11 |
CVE-2025-12644 |
Wordfence | |
| 6.4 Medium | Saphali LiqPay for donate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.2 |
CVE-2025-12643 |
Wordfence | |
| 6.5 Medium | IDonate | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function |
2.0.0 – 2.1.9 |
CVE-2025-4522 |
Wordfence | |
| 5.4 Medium | IDonate | Cross-Site Request Forgery Unauthenticated User Deletion |
< 2.1.13 Fixed in 2.1.13 |
CVE-2025-11154 |
WPScan | |
| 6.5 Medium | Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More | SQL Injection Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection |
≤ 1.8.8.4 |
CVE-2025-11893 |
Wordfence | |
| 6.5 Medium | Houzez Theme - Functionality | Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) |
≤ 4.2.0 Fixed in 4.2.0 |
CVE-2025-62058 |
Patchstack | |
| 6.5 Medium | IDonatePro | Information Disclosure Sensitive Data Exposure |
≤ 2.1.9 |
CVE-2025-52752 |
Patchstack | |
| 5.3 Medium | Whydonate | Broken Access Control No login needed |
≤ 4.0.15 Fixed in 4.0.16 |
CVE-2025-49899 |
Patchstack | |
| 5.3 Medium | WhyDonate – FREE Donate button – Crowdfunding – Fundraising | Broken Access Control FREE Donate button – Crowdfunding – Fundraising <= 4.0.15 - Missing Authorization to Unauthenticated wp_wdplugin_style Rww Deletion No login needed |
≤ 4.0.15 |
CVE-2025-10186 |
Wordfence | |
| 5.3 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association No login needed |
≤ 4.10.0 |
CVE-2025-11228 |
Wordfence | |
| 6.5 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure No login needed |
≤ 4.10.0 |
CVE-2025-11227 |
Wordfence | |
| 4.3 Medium | Professional Contact Form | Cross-Site Request Forgery Cross-Site Request Forgery to Test Email Sending No login needed |
≤ 1.0.0 |
CVE-2025-9944 |
Wordfence | |
| 5.9 Medium | WooCommerce Additional Fees On Checkout (Free) | Cross-Site Scripting |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-57903 |
Patchstack | |
| 5.9 Medium | Double the Donation | Cross-Site Scripting |
≤ 2.0.0 Fixed in 3.0.0 |
CVE-2025-57929 |
Patchstack | |
| 4.3 Medium | Double the Donation | Cross-Site Request Forgery No login needed |
≤ 2.0.0 Fixed in 3.0.0 |
CVE-2025-57930 |
Patchstack | |
| 4.9 Medium | Coupon API | SQL Injection Authenticated (Administrator+) SQL Injection via 'log_duration' |
≤ 6.2.12 |
CVE-2025-8692 |
Wordfence | |
| 6.5 Medium | Additional Custom Product Tabs for WooCommerce | Cross-Site Scripting |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2025-58985 |
Patchstack | |
| 6.5 Medium | Donation Forms WP by Givecloud | Cross-Site Scripting |
≤ 1.0.9 Fixed in 1.0.10 |
CVE-2025-58842 |
Patchstack | |
| 6.5 Medium | If-So Dynamic Content Personalization | Cross-Site Scripting |
≤ 1.9.4 Fixed in 1.9.4.1 |
CVE-2025-58602 |
Patchstack | |
| 6.5 Medium | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read |
5.1.16 – 6.1.1 |
CVE-2025-9260 |
Wordfence | |
| 6.5 Medium | Simple Download Monitor | SQL Injection Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality |
≤ 3.9.33 |
CVE-2025-8977 |
Wordfence | |
| 5.4 Medium | Pronamic Google Maps | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4.1 |
CVE-2025-9352 |
Wordfence | |
| 5.9 Medium | Recurring PayPal Donations | Cross-Site Scripting |
≤ 1.8 Fixed in 1.9 |
CVE-2025-57891 |
Patchstack | |
| 4.3 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update |
≤ 4.5.0 |
CVE-2025-7221 |
Wordfence | |
| 6.1 Medium | Linux Promotional | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.4 |
CVE-2025-7668 |
Wordfence | |
| 5.3 Medium | GiveWP – Donation Plugin and Fundraising Platform | Information Disclosure Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure No login needed |
≤ 4.6.0 |
CVE-2025-8620 |
Wordfence | |
| 6.5 Medium | IDonate | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function |
2.0.0 – 2.1.9 |
CVE-2025-4523 |
Wordfence | |
| 5.4 Medium | GiveWP – Donation Plugin and Fundraising Platform | Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting |
≤ 4.5.0 |
CVE-2025-7205 |
Wordfence | |
| 4.3 Medium | Bonanza – WooCommerce Free Gifts Lite | Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success |
≤ 1.0.0 |
CVE-2025-6730 |
Wordfence | |
| 6.4 Medium | WP-PhotoNav | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via photonav Shortcode |
≤ 1.2.2 |
CVE-2025-6383 |
Wordfence | |
| 5.4 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification |
≤ 4.3.0 |
CVE-2025-4571 |
Wordfence | |
| 4.7 Medium | FunnelKit Automations | Open Redirect No login needed |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2025-49868 |
Patchstack | |
| 6.5 Medium | If-So Dynamic Content Personalization | Cross-Site Scripting |
≤ 1.9.3.1 Fixed in 1.9.3.2 |
CVE-2025-49875 |
Patchstack | |
| 5.3 Medium | Interactive Regional Map of Florida | Broken Access Control No login needed |
≤ 1.0 |
CVE-2025-49441 |
Patchstack | |
| 4.3 Medium | Interactive UK Regional Map | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 2.0 |
CVE-2025-49445 |
Patchstack | |
| 4.3 Medium | Interactive Regional Map of Africa | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-49449 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.