WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 951–1,000 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium CM Answers Plugin cm-answers Cross-Site Request Forgery No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-46246 Patchstack
4.3 Medium CM Ad Changer Plugin cm-ad-changer Cross-Site Request Forgery No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-46245 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
5.4 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Cross-Site Request Forgery No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-46231 Patchstack
7.1 High Fontsampler Plugin fontsampler Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.14 CVE-2025-27337 Patchstack
7.1 High List Urls Plugin list-urls Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-27338 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion Local File Inclusion via CSRF No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-31030 Patchstack
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack
7.1 High All push notification for WP Plugin all-push-notification Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32546 Patchstack
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
7.1 High Restrict User Registration Plugin restrict-user-registration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-32655 Patchstack
8.8 High Starfish Review Generation & Marketing Plugin starfish-reviews Privilege Escalation ≤ 3.1.19 Fixed in 3.1.20 CVE-2025-39533 Patchstack
7.1 High Social Media Links Plugin social-media-links Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.3 CVE-2025-39415 Patchstack
7.1 High spam-stopper Plugin spam-stopper Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.1.3 CVE-2025-39414 Patchstack
7.1 High translit it! Plugin translit-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6 CVE-2025-39416 Patchstack
7.1 High Redirect wordpress to welcome or landing page Plugin redirect-to-welcome-or-landing-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-39417 Patchstack
7.1 High RSS Manager Plugin rss-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.06 CVE-2025-39418 Patchstack
7.1 High Revision Diet Plugin revision-diet Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-39419 Patchstack
7.1 High WP Twitter Button Plugin wp-twitter-button Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-39420 Patchstack
7.1 High WP Social Bookmarking Plugin wp-social-bookmarking Cross-Site Request Forgery No login needed ≤ 3.6 CVE-2025-39422 Patchstack
7.1 High WP Sticky Side Buttons Plugin wp-sticky-side-buttons Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-39421 Patchstack
7.1 High Add to Header Plugin add-to-header Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.0 CVE-2025-39423 Patchstack
7.1 High Simple Maps Plugin interactive-maps Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.98 Fixed in 0.99 CVE-2025-39424 Patchstack
4.3 Medium Style Manager Plugin style-manager Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.2.7 CVE-2025-39425 Patchstack
4.3 Medium illow – Cookies Consent Plugin lgpd-compliant-cookie-banner Cross-Site Request Forgery Cookies Consent plugin <= 0.2.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 0.2.0 CVE-2025-39426 Patchstack
7.1 High mLanguage Plugin mlanguage Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-39430 Patchstack
7.1 High Amazon Showcase Plugin amazon-showcase-wordpress-widget Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.2 CVE-2025-39431 Patchstack
7.1 High bbPress2 shortcode whitelist Plugin bbpress2-shortcode-whitelist Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.2.1 CVE-2025-39432 Patchstack
7.1 High Bknewsticker Plugin bknewsticker Cross-Site Request Forgery No login needed ≤ 1.0.5 CVE-2025-39433 Patchstack
7.1 High My Marginalia Plugin my-marginalia Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.6 CVE-2025-39435 Patchstack
4.3 Medium Anthologize Plugin anthologize Cross-Site Request Forgery No login needed ≤ 0.8.3 CVE-2025-39437 Patchstack
4.3 Medium Theme Changer Plugin theme-changer Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-39438 Patchstack
7.1 High Broken Links Remover Plugin broken-links-remover Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.2 CVE-2025-39440 Patchstack
7.1 High Dashboard Notepads Plugin dashboard-notepads Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 CVE-2025-39441 Patchstack
7.1 High Review Wave – Google Places Reviews Plugin review-wave-google-places-reviews Cross-Site Request Forgery Google Places Reviews plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.4.7 CVE-2025-39442 Patchstack
4.3 Medium Verge3D Plugin verge3d Cross-Site Request Forgery No login needed ≤ 4.9.0 Fixed in 4.9.3 CVE-2025-39443 Patchstack
4.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.9.3 Fixed in 4.9.5 CVE-2025-39453 Patchstack
7.1 High IP2Location Variables Plugin ip2location-variables Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.9.5 Fixed in 2.9.6 CVE-2025-39455 Patchstack
4.3 Medium WooCommerce Social Login Plugin woo-social-login Cross-Site Request Forgery No login needed ≤ 2.8.3 Fixed in 2.8.3 CVE-2025-39472 Patchstack
4.3 Medium Bulk Term Editor Plugin bulk-term-editor Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-39512 Patchstack
4.3 Medium Basic Interactive World Map Plugin basic-interactive-world-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.7 CVE-2025-39517 Patchstack
7.1 High Site Search 360 Plugin site-search-360 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to stored XSS No login needed ≤ 2.1.8 CVE-2025-39530 Patchstack
7.4 High WP Tools Plugin wptools Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 5.18 Fixed in 5.19 CVE-2025-39544 Patchstack
7.1 High Internal Link Optimiser Plugin internal-link-finder Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.1.3 Fixed in 5.1.4 CVE-2025-39547 Patchstack
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Request Forgery No login needed ≤ 6.6.2 Fixed in 6.6.3 CVE-2025-39546 Patchstack
7.1 High Right Click Disable OR Ban Plugin right-click-disable-or-ban Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.17 Fixed in 1.2.0 CVE-2025-39548 Patchstack
6.5 Medium Conditional Payments for WooCommerce Plugin conditional-payments-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-39563 Patchstack
6.5 Medium Conditional Shipping for WooCommerce Plugin conditional-shipping-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-39564 Patchstack
4.3 Medium Ever Accounting Plugin wp-ever-accounting Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-39593 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only