WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,051–10,100 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 202 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium SNORDIAN's H5PxAPIkatchu Plugin h5pxapikatchu Broken Access Control No login needed ≤ 0.4.14 Fixed in 0.4.15 CVE-2025-30821 Patchstack
7.5 High WishSuite Plugin wishsuite Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-30820 Patchstack
8.5 High Simple Giveaways Plugin giveasap SQL Injection ≤ 2.48.1 Fixed in 2.48.2 CVE-2025-30819 Patchstack
6.5 Medium jAlbum Bridge Plugin jalbum-bridge Cross-Site Scripting ≤ 2.0.17 Fixed in 2.0.18 CVE-2025-30818 Patchstack
5.4 Medium Z Companion Plugin z-companion Broken Access Control ≤ 1.0.13 Fixed in 1.1.0 CVE-2025-30817 Patchstack
4.3 Medium publish post email notification Plugin publish-post-email-notification Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.2.3 Fixed in 1.0.2.4 CVE-2025-30816 Patchstack
4.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2025-30815 Patchstack
7.5 High The Post Grid Plugin the-post-grid Local File Inclusion ≤ 7.7.17 Fixed in 7.7.18 CVE-2025-30814 Patchstack
6.5 Medium Listamester Plugin listamester Cross-Site Scripting ≤ 2.3.5 Fixed in 2.3.6 CVE-2025-30813 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 3.5 Fixed in 3.6 CVE-2025-30812 Patchstack
4.3 Medium ValidateCertify Plugin validar-certificados-de-cursos Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-30811 Patchstack
8.5 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm SQL Injection ≤ 3.0.1 Fixed in 3.1 CVE-2025-30810 Patchstack
5.4 Medium Live Forms Plugin liveforms Broken Access Control Live Forms plugin <= 4.8.4 - Settings Change ≤ 4.8.4 Fixed in 4.8.5 CVE-2025-30809 Patchstack
8.5 High Vimeotheque Plugin codeflavors-vimeo-video-post-lite SQL Injection ≤ 2.3.4.2 Fixed in 2.3.4.3 CVE-2025-30806 Patchstack
4.3 Medium Flexible Cookies Plugin flexible-cookies Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-30805 Patchstack
4.3 Medium wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-30804 Patchstack
4.3 Medium Just Writing Statistics Plugin just-writing-statistics Broken Access Control ≤ 5.3 Fixed in 5.4 CVE-2025-30803 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.10 Fixed in 1.3.11 CVE-2025-30800 Patchstack
5.9 Medium WP Google Street View Plugin wp-google-street-view Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-30799 Patchstack
4.7 Medium FunnelKit Automations Plugin wp-marketing-automations Open Redirect No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-30795 Patchstack
5.9 Medium Comment Approved Notifier Extended Plugin comment-approved-notifier-extended Cross-Site Scripting ≤ 5.2 Fixed in 5.3 CVE-2025-30792 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
5.3 Medium Chatbox Manager Plugin wa-chatbox-manager Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-30790 Patchstack
5.9 Medium Clearout Email Validator Plugin clearout-email-validator Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-30789 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
6.5 Medium Quotes llama Plugin quotes-llama Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-30786 Patchstack
7.5 High Subscribe to Download Lite Plugin subscribe-to-download-lite Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-30785 Patchstack
8.5 High WP Subscription Forms Plugin wp-subscription-forms SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-30784 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
4.7 Medium Scheduled & Automatic Order Status Controller for WooCommerce Plugin order-status-rules-for-woocommerce Open Redirect No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30781 Patchstack
6.5 Medium Audio Album Plugin audio-album Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-30780 Patchstack
6.5 Medium Doneren met Mollie Plugin doneren-met-mollie Cross-Site Scripting ≤ 2.10.7 Fixed in 2.10.8 CVE-2025-30779 Patchstack
4.3 Medium Support Genix Plugin support-genix-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.11 Fixed in 1.4.12 CVE-2025-30777 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-30776 Patchstack
8.5 High WPGuppy Plugin wpguppy-lite SQL Injection ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-30775 Patchstack
7.2 High TranslatePress Plugin translatepress-multilingual PHP Object Injection ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-30773 Patchstack
6.5 Medium WP Cassify Plugin wp-cassify Cross-Site Scripting ≤ 2.3.5 Fixed in 2.3.6 CVE-2025-30771 Patchstack
6.5 Medium Charitable Plugin charitable Cross-Site Scripting ≤ 1.8.4.7 Fixed in 1.8.4.8 CVE-2025-30770 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
6.5 Medium jAlbum Bridge Plugin jalbum-bridge Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2025-30768 Patchstack
5.4 Medium PDF for WPForms Plugin pdf-for-wpforms Arbitrary Shortcode Execution ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-30767 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.16.2 Fixed in 3.16.3 CVE-2025-30766 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
4.3 Medium Football Pool Plugin football-pool Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2025-30764 Patchstack
6.5 Medium EO4WP Plugin fw-integration-for-emailoctopus Cross-Site Scripting ≤ 1.0.8.4 Fixed in 1.0.8.5 CVE-2025-30763 Patchstack
6.4 Medium TablePress – Tables in WordPress made easy Plugin tablepress Cross-Site Scripting Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.0.4 CVE-2025-2685 Wordfence
6.5 Medium newseqo Theme newseqo Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.1 CVE-2025-26739 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only