WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 166 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High ORDER POST Plugin order-post Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.2 CVE-2025-2805 Wordfence
7.3 High azurecurve Shortcodes in Comments Plugin azurecurve-shortcodes-in-comments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.2 CVE-2025-2809 Wordfence
7.3 High So-Called Air Quotes Plugin so-called-air-quotes Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.1 CVE-2025-2803 Wordfence
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
8.8 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed 4.11.13 – 5.25.08 CVE-2025-2319 Wordfence
8.8 High s2Member Pro Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion to Remote Code Execution via Shortcode ≤ 250214 CVE-2024-12563 Wordfence
7.3 High Logo Slider Plugin gs-logo-slider Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.7.3 CVE-2025-2262 Wordfence
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
8.8 High Traveler Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.1.9 CVE-2024-12811 Wordfence
7.3 High Custom Post Type Date Archives Plugin custom-post-type-date-archives Broken Access Control Missing Authorization to Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.7.1 CVE-2025-1510 Wordfence
7.3 High Show Me The Cookies Plugin show-me-the-cookies Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0 CVE-2025-1509 Wordfence
7.3 High WooCommerce Food - Restaurant Menu & Food ordering Plugin Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed ≤ 3.3.2 CVE-2024-13792 Wordfence
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
7.1 High Contact Form With Shortcode Plugin contact-form-with-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-24564 Patchstack
7.3 High Avada Builder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.11.13 CVE-2024-13345 Wordfence
7.3 High Avada Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.11.13 CVE-2024-13346 Wordfence
7.5 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Authentication Bypass via Shortcode ≤ 2.9.5 CVE-2024-13528 Wordfence
7.1 High Fyrebox Quizzes Plugin fyrebox-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.1 CVE-2025-25125 Patchstack
7.3 High CURCY – Multi Currency for WooCommerce Plugin woo-multi-currency Arbitrary Shortcode Execution Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function No login needed ≤ 2.2.5 CVE-2024-13487 Wordfence
8.8 High BoomBox Theme Extensions Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 1.8.0 CVE-2024-12859 Wordfence
7.1 High AIO Shortcodes Plugin aio-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-24620 Patchstack
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2024-13472 Wordfence
7.3 High Contact Form & SMTP Plugin for WordPress by PirateForms Plugin pirate-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.6.0 CVE-2024-13453 Wordfence
7.1 High Bulk Me Now Plugin Cross-Site Scripting Stored XSS via Shortcode No login needed ≤ 2.0 CVE-2024-12708 WPScan
7.3 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10633 Wordfence
8.8 High ThemeREX Addons Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.33.0 CVE-2025-0682 Wordfence
7.1 High MachForm Shortcode Plugin machform-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-24636 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function No login needed ≤ 7.2.1 CVE-2024-13499 Wordfence
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function No login needed ≤ 7.2.1 CVE-2024-13495 Wordfence
7.1 High Twitter Shortcode Plugin twitter-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-23618 Patchstack
7.1 High Shortcode in Comment Plugin shortcode-in-comment Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-23569 Patchstack
7.5 High CF Internal Link Shortcode Plugin internal-link-shortcode SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.1.0 CVE-2024-12404 Wordfence
7.1 High Better User Shortcodes Plugin better-user-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22594 Patchstack
7.1 High Smoothness Slider Shortcode Plugin smoothness-slider-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ v1.2.2 CVE-2025-22555 Patchstack
7.3 High WordPress Popular Posts Plugin wordpress-popular-posts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.0 CVE-2024-11733 Wordfence
7.1 High My Shortcodes Plugin my-shortcodes Broken Access Control ≤ 2.3 CVE-2023-46632 Patchstack
7.3 High kk Star Ratings – Rate Post & Collect User Feedbacks Plugin kk-star-ratings Arbitrary Shortcode Execution Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.4.10 CVE-2024-11977 Wordfence
7.3 High Download Manager Plugin download-manager Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.3.03 CVE-2024-11740 Wordfence
7.1 High Geoportail Shortcode Plugin geoportail-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.4.4 CVE-2024-54414 Patchstack
7.1 High Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-54264 Patchstack
7.3 High Grid Plus – Unlimited grid layout Plugin grid-plus Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed ≤ 1.3.5 CVE-2024-10910 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
7.1 High Awesome Shortcodes Plugin awesome-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-54209 Patchstack
7.3 High Authors List Plugin authors-list Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax No login needed ≤ 2.0.4 CVE-2024-10952 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only