WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 9,951–10,000 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 200 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium iNET Webkit Plugin inet-webkit Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-22629 Patchstack
5.4 Medium Easy Booked – Appointment Booking and Scheduling Management System Plugin easy-booked Cross-Site Request Forgery No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-22634 Patchstack
4.3 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22637 Patchstack
6.5 Medium Product Table For WooCommerce Plugin product-table-for-woocommerce Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-22638 Patchstack
5.9 Medium Paytm Payment Donation Plugin paytm-donation Cross-Site Scripting ≤ 2.3.3 CVE-2025-22640 Patchstack
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-22646 Patchstack
4.3 Medium AIO Performance Profiler, Monitor, Optimize, Compress & Debug Plugin all-in-one-performance-accelerator Broken Access Control ≤ 1.2 Fixed in 1.3 CVE-2025-22647 Patchstack
6.5 Medium Blog, Posts and Category Filter for Elementor Plugin blog-posts-and-category-for-elementor Cross-Site Scripting ≤ 2.0.1 Fixed in 2.1.0 CVE-2025-22648 Patchstack
5.9 Medium WP Project Manager Plugin wedevs-project-manager Cross-Site Scripting ≤ 2.6.22 Fixed in 2.6.23 CVE-2025-22649 Patchstack
7.6 High Payment Forms for Paystack Plugin payment-forms-for-paystack SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-22652 Patchstack
7.1 High Listings for Appfolio Plugin listings-for-appfolio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22658 Patchstack
6.5 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 2.10.44 Fixed in 2.10.45 CVE-2025-22659 Patchstack
6.5 Medium Include Mastodon Feed Plugin include-mastodon-feed Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2025-22660 Patchstack
4.3 Medium RapidLoad Plugin unusedcss Broken Access Control ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-22665 Patchstack
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
6.5 Medium Awesome Event Booking Plugin awesome-event-booking Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.5 CVE-2025-22668 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
6.5 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-22670 Patchstack
4.3 Medium Disable Elementor Editor Translation Plugin disable-elementor-editor-translation Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-22671 Patchstack
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control ≤ 5.3.5 Fixed in 5.4.0 CVE-2025-22673 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
5.4 Medium Envo Multipurpose Theme envo-multipurpose Broken Access Control ≤ 1.1.6 CVE-2025-22770 Patchstack
7.1 High Secret Meta Plugin facebook-secret-meta Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-25086 Patchstack
6.5 Medium Power Mag Plugin power-mag Cross-Site Scripting ≤ 1.1.5 CVE-2025-22816 Patchstack
7.1 High Cazamba Plugin cazamba Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25100 Patchstack
6.5 Medium ARPrice Plugin arprice Cross-Site Scripting ≤ 4.1.3 CVE-2025-26731 Patchstack
6.5 Medium StoreBiz Plugin storebiz Cross-Site Scripting ≤ 1.0.32 CVE-2025-26732 Patchstack
6.5 Medium Hester Plugin hester Cross-Site Scripting ≤ 1.1.10 CVE-2025-26734 Patchstack
6.5 Medium MorningTime Lite Plugin morningtime-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-26736 Patchstack
6.5 Medium City Store Theme city-store Cross-Site Scripting ≤ 1.4.5 CVE-2025-26737 Patchstack
6.5 Medium Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting ≤ 3.1.5 CVE-2025-26738 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30925 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
6.5 Medium Simplebooklet PDF Viewer and Embedder Plugin simplebooklet Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-30922 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.9.9.7 Fixed in 4.9.9.8 CVE-2025-30921 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-30920 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-30918 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.3 Fixed in 7.2.4 CVE-2025-30909 Patchstack
6.5 Medium SecuPress Free Plugin secupress Cross-Site Scripting ≤ 2.2.5.3 Fixed in 2.2.5.4 CVE-2025-30907 Patchstack
5.9 Medium Chartify Plugin chart-builder Cross-Site Scripting ≤ 3.1.7 Fixed in 3.1.9 CVE-2025-30904 Patchstack
6.5 Medium SyntaxHighlighter Evolved Plugin syntaxhighlighter Cross-Site Scripting ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30903 Patchstack
6.5 Medium Zoho Billing – Embed Payment Form Plugin zoho-subscriptions Cross-Site Scripting Embed Payment Form plugin <= 4.0 - Stored Cross Site Scripting (XSS) ≤ 4.0 Fixed in 4.1 CVE-2025-30900 Patchstack
5.9 Medium User Registration Plugin user-registration Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-30899 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-30898 Patchstack
4.3 Medium Analytify Plugin wp-analytify Broken Access Control Settings Change ≤ 5.5.1 Fixed in 6.0.0 CVE-2025-30897 Patchstack
5.4 Medium WP ERP Plugin erp Broken Access Control ≤ 1.13.4 Fixed in 1.14.0 CVE-2025-30896 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only