WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 51–100 of 166 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.3 High | ORDER POST | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.0.2 |
CVE-2025-2805 |
Wordfence | |
| 7.3 High | azurecurve Shortcodes in Comments | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.0.2 |
CVE-2025-2809 |
Wordfence | |
| 7.3 High | So-Called Air Quotes | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 0.1 |
CVE-2025-2803 |
Wordfence | |
| 8.2 High | EZ SQL Reports Shortcode Widget and DB Backup | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 5.25.08 Fixed in 5.25.10 |
CVE-2025-30788 |
Patchstack | |
| 7.1 High | EZ SQL Reports Shortcode Widget and DB Backup | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 5.25.08 Fixed in 5.25.10 |
CVE-2025-30787 |
Patchstack | |
| 7.1 High | Narnoo Operator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.0 |
CVE-2025-23680 |
Patchstack | |
| 8.8 High | EZ SQL Reports Shortcode Widget and DB Backup | Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed |
4.11.13 – 5.25.08 |
CVE-2025-2319 |
Wordfence | |
| 8.8 High | s2Member Pro | Local File Inclusion Authenticated (Contributor+) Local File Inclusion to Remote Code Execution via Shortcode |
≤ 250214 |
CVE-2024-12563 |
Wordfence | |
| 7.3 High | Logo Slider | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.7.3 |
CVE-2025-2262 |
Wordfence | |
| 7.3 High | Appointment Booking Calendar — Simply Schedule Appointments Booking | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.6.8.5 |
CVE-2025-1119 |
Wordfence | |
| 7.3 High | WPCS – WordPress Currency Switcher Professional | Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.0.4 |
CVE-2025-2169 |
Wordfence | |
| 8.8 High | Traveler | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 3.1.9 |
CVE-2024-12811 |
Wordfence | |
| 7.3 High | Custom Post Type Date Archives | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.7.1 |
CVE-2025-1510 |
Wordfence | |
| 7.3 High | Show Me The Cookies | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.0 |
CVE-2025-1509 |
Wordfence | |
| 7.3 High | WooCommerce Food - Restaurant Menu & Food ordering | Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed |
≤ 3.3.2 |
CVE-2024-13792 |
Wordfence | |
| 7.3 High | PressMart - Modern Elementor WooCommerce | Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.16 |
CVE-2024-13797 |
Wordfence | |
| 7.1 High | Contact Form With Shortcode | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.2.5 Fixed in 4.2.6 |
CVE-2025-24564 |
Patchstack | |
| 7.3 High | Avada Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.11.13 |
CVE-2024-13345 |
Wordfence | |
| 7.3 High | Avada | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 7.11.13 |
CVE-2024-13346 |
Wordfence | |
| 7.5 High | Customer Email Verification for WooCommerce | Authentication Bypass Authentication Bypass via Shortcode |
≤ 2.9.5 |
CVE-2024-13528 |
Wordfence | |
| 7.1 High | Fyrebox Quizzes | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 3.1 |
CVE-2025-25125 |
Patchstack | |
| 7.3 High | CURCY – Multi Currency for WooCommerce | Arbitrary Shortcode Execution Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function No login needed |
≤ 2.2.5 |
CVE-2024-13487 |
Wordfence | |
| 8.8 High | BoomBox Theme Extensions | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 1.8.0 |
CVE-2024-12859 |
Wordfence | |
| 7.1 High | AIO Shortcodes | Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed |
≤ 1.3 Fixed in 1.3.1 |
CVE-2025-24620 |
Patchstack | |
| 7.3 High | WooCommerce Product Table Lite | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed |
≤ 3.9.4 |
CVE-2024-13472 |
Wordfence | |
| 7.3 High | Contact Form & SMTP Plugin for WordPress by PirateForms | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.6.0 |
CVE-2024-13453 |
Wordfence | |
| 7.1 High | Bulk Me Now | Cross-Site Scripting Stored XSS via Shortcode No login needed |
≤ 2.0 |
CVE-2024-12708 |
WPScan | |
| 7.3 High | Quiz Maker Business, Developer, and Agency <= (Multiple Versions) | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed |
≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 |
CVE-2024-10633 |
Wordfence | |
| 8.8 High | ThemeREX Addons | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 2.33.0 |
CVE-2025-0682 |
Wordfence | |
| 7.1 High | MachForm Shortcode | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.4.1 Fixed in 1.5.0 |
CVE-2025-24636 |
Patchstack | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.6.10 |
CVE-2024-13408 |
Wordfence | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() |
≤ 1.6.10 |
CVE-2024-13409 |
Wordfence | |
| 7.1 High | Simple shortcode buttons | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.2 |
CVE-2025-23449 |
Patchstack | |
| 7.3 High | GamiPress | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function No login needed |
≤ 7.2.1 |
CVE-2024-13499 |
Wordfence | |
| 7.3 High | GamiPress | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function No login needed |
≤ 7.2.1 |
CVE-2024-13495 |
Wordfence | |
| 7.1 High | Twitter Shortcode | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 0.9 |
CVE-2025-23618 |
Patchstack | |
| 7.1 High | Shortcode in Comment | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1.1 |
CVE-2025-23569 |
Patchstack | |
| 7.5 High | CF Internal Link Shortcode | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.1.0 |
CVE-2024-12404 |
Wordfence | |
| 7.1 High | Better User Shortcodes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-22594 |
Patchstack | |
| 7.1 High | Smoothness Slider Shortcode | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ v1.2.2 |
CVE-2025-22555 |
Patchstack | |
| 7.3 High | WordPress Popular Posts | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 7.1.0 |
CVE-2024-11733 |
Wordfence | |
| 7.1 High | My Shortcodes | Broken Access Control |
≤ 2.3 |
CVE-2023-46632 |
Patchstack | |
| 7.3 High | kk Star Ratings – Rate Post & Collect User Feedbacks | Arbitrary Shortcode Execution Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 5.4.10 |
CVE-2024-11977 |
Wordfence | |
| 7.3 High | Download Manager | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.3.03 |
CVE-2024-11740 |
Wordfence | |
| 7.1 High | Geoportail Shortcode | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 2.4.4 |
CVE-2024-54414 |
Patchstack | |
| 7.1 High | Shortcodes Blocks Creator Ultimate | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.0 |
CVE-2024-54264 |
Patchstack | |
| 7.3 High | Grid Plus – Unlimited grid layout | Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed |
≤ 1.3.5 |
CVE-2024-10910 |
Wordfence | |
| 7.3 High | Active Products Tables for WooCommerce. Use constructor to create tables | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed |
≤ 1.0.6.5 |
CVE-2024-10959 |
Wordfence | |
| 7.1 High | Awesome Shortcodes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.7.2 Fixed in 1.7.3 |
CVE-2024-54209 |
Patchstack | |
| 7.3 High | Authors List | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax No login needed |
≤ 2.0.4 |
CVE-2024-10952 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.