WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–100 of 251 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Responsive Pricing Table | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 5.1.12 |
CVE-2025-13418 |
Wordfence | |
| 6.5 Medium | Responsive Addons for Elementor | Broken Access Control |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2025-69363 |
Patchstack | |
| 6.5 Medium | Responsive Block Control | Cross-Site Scripting |
≤ 1.3.0 Fixed in 1.3.1 |
CVE-2025-62135 |
Patchstack | |
| 7.5 High | Responsive Posts Carousel Pro | Local File Inclusion |
≤ 15.1 |
CVE-2025-68996 |
Patchstack | |
| 5.9 Medium | Google AdSense for Responsive Design – GARD | Cross-Site Scripting GARD plugin <= 2.23 - Cross Site Scripting (XSS) |
≤ 2.23 |
CVE-2025-67632 |
Patchstack | |
| 6.5 Medium | Responsive Posts Carousel Pro | Cross-Site Scripting |
≤ 15.2 Fixed in 15.3 |
CVE-2025-68548 |
Patchstack | |
| 5.5 Medium | Responsive and Swipe slider | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.2 |
CVE-2025-14721 |
Wordfence | |
| 6.5 Medium | Molla | Remote Code Execution Multipurpose Responsive Shopify theme <= 1.5.13 - Arbitrary Code Execution No login needed |
≤ 1.5.13 |
CVE-2025-60070 |
Patchstack | |
| 4.3 Medium | Image Slider by Ays- Responsive Slider and Carousel | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed |
≤ 2.7.0 |
CVE-2025-14454 |
Wordfence | |
| 5.4 Medium | Responsive Lightbox & Gallery | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery |
≤ 2.5.3 |
CVE-2025-12359 |
Wordfence | |
| 5.4 Medium | Slippy Slider – Responsive Touch Navigation Slider | Cross-Site Scripting Responsive Touch Navigation Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0 |
CVE-2025-11874 |
Wordfence | |
| 7.5 High | Responsive Sidebar | Local File Inclusion No login needed |
≤ 1.2.2 |
CVE-2025-60073 |
Patchstack | |
| 6.4 Medium | B Carousel Block – Responsive Image and Content Carousel | Broken Access Control Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 1.1.5 |
CVE-2025-12388 |
Wordfence | |
| 4.4 Medium | Multi-language Responsive Portfolio | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11753 |
Wordfence | |
| 4.9 Medium | Thumbnail Slider With Lightbox | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.4 |
CVE-2015-10146 |
Wordfence | |
| 5.9 Medium | Photospace Responsive | Cross-Site Scripting |
≤ 2.2.0 |
CVE-2025-62899 |
Patchstack | |
| 6.1 Medium | Multi Item Responsive Slider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-11992 |
Wordfence | |
| 7.1 High | Toast Mobile Menu | Cross-Site Scripting No login needed |
≤ 1.0.8 Fixed in 1.0.9 |
CVE-2025-53238 |
Patchstack | |
| 6.4 Medium | Responsive Progress Bar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11883 |
Wordfence | |
| 6.4 Medium | Responsive iframe GoogleMap | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.2 |
CVE-2025-11813 |
Wordfence | |
| 6.4 Medium | WP Responsive Meet The Team | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.1 |
CVE-2025-11818 |
Wordfence | |
| 6.3 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed |
< 2.5.3 Fixed in 2.5.3 |
CVE-2025-9710 |
WPScan | |
| 6.1 Medium | Side Slide Responsive Menu | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-9880 |
Wordfence | |
| 6.4 Medium | Responsive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.0.1 |
CVE-2025-8215 |
Wordfence | |
| 7.2 High | Responsive Filterable Portfolio | Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload |
≤ 1.0.24 |
CVE-2025-10049 |
Wordfence | |
| 7.2 High | eDS Responsive Menu | PHP Object Injection |
≤ 1.2 |
CVE-2025-58839 |
Patchstack | |
| 6.5 Medium | Responsive Mobile-Friendly Tooltip | Cross-Site Scripting |
≤ 1.6.6 |
CVE-2025-48316 |
Patchstack | |
| 7.1 High | Responsive HTML5 Audio Player PRO With Playlist | Cross-Site Scripting No login needed |
≤ 3.5.8 Fixed in 3.5.9 |
CVE-2025-54056 |
Patchstack | |
| 7.5 High | Responsive Posts Carousel Pro | Local File Inclusion |
≤ 15.0 Fixed in 15.1 |
CVE-2025-52728 |
Patchstack | |
| 6.4 Medium | Simple Responsive Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0 |
CVE-2025-8690 |
Wordfence | |
| 8.8 High | Responsive Thumbnail Slider | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
< 1.0.1 Fixed in 1.0.1 |
CVE-2015-10144 |
Wordfence | |
| 6.4 Medium | Useful Tab Block – Responsive & AMP-Compatible | Cross-Site Scripting Responsive & AMP-Compatible <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter |
≤ 1.3.2 |
CVE-2025-5754 |
Wordfence | |
| 7.5 High | Multi-language Responsive Contact Form | Broken Access Control No login needed |
≤ 2.8 |
CVE-2025-29000 |
Patchstack | |
| 6.5 Medium | Responsive Addons for Elementor | Cross-Site Scripting |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2025-54050 |
Patchstack | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.4.31 |
CVE-2025-6068 |
Wordfence | |
| 7.1 High | Beautiful Cookie Consent Banner | Cross-Site Scripting No login needed |
≤ 4.6.1 Fixed in 4.6.2 |
CVE-2025-49866 |
Patchstack | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.6 Fixed in 2.0.7 |
CVE-2025-53202 |
Patchstack | |
| 7.1 High | FastBook | Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-25173 |
Patchstack | |
| 5.4 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 2.5.2 Fixed in 2.5.2 |
CVE-2025-5093 |
WPScan | |
| 6.4 Medium | Responsive Food and Drink Menu | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via display_pdf_menus Shortcode |
≤ 2.3 |
CVE-2025-6378 |
Wordfence | |
| 8.8 High | Owl carousel responsive | SQL Injection Authenticated (Contributor+) SQL Injection via id Parameter |
≤ 1.9 |
CVE-2025-5590 |
Wordfence | |
| 4.3 Medium | eDS Responsive Menu | Broken Access Control |
≤ 1.2 |
CVE-2025-49971 |
Patchstack | |
| 4.3 Medium | Responsive Plus | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2025-49856 |
Patchstack | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2025-49881 |
Patchstack | |
| 5.4 Medium | Responsive Flipbooks | Broken Access Control |
≤ 1.0 |
CVE-2025-24776 |
Patchstack | |
| 4.3 Medium | FastBook | Cross-Site Request Forgery No login needed |
≤ 1.1 |
CVE-2025-26593 |
Patchstack | |
| 7.1 High | Recent Posts Slider Responsive | Cross-Site Request Forgery No login needed |
≤ 1.0.1 |
CVE-2025-28966 |
Patchstack | |
| 6.5 Medium | ShiftNav – Responsive Mobile Menu | Cross-Site Scripting Responsive Mobile Menu plugin <= 1.8 - Cross Site Scripting (XSS) |
≤ 1.8 Fixed in 1.8.1 |
CVE-2025-49243 |
Patchstack | |
| 5.4 Medium | Responsive Plus | Broken Access Control |
≤ 3.2.0 Fixed in 3.2.1 |
CVE-2025-48335 |
Patchstack | |
| 8.1 High | Enzio - Responsive Business | Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed |
≤ 1.2.6 Fixed in 1.2.6 |
CVE-2025-31912 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.