WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 10,051–10,100 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.8.3 |
CVE-2025-1802 |
Wordfence | |
| 6.4 Medium | 140+ Widgets | Xpro Addons For Elementor – FREE | Cross-Site Scripting FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget |
≤ 1.4.7.1 |
CVE-2025-2108 |
Wordfence | |
| 5.3 Medium | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Broken Access Control Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update No login needed |
≤ 4.0.24 |
CVE-2025-1766 |
Wordfence | |
| 4.3 Medium | Custom Twitter Feeds | Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function No login needed |
≤ 2.2.5 |
CVE-2025-1314 |
Wordfence | |
| 4.9 Medium | AHAthat | SQL Injection Authenticated (Administrator+) SQL Injection via id Parameter |
≤ 1.6 |
CVE-2025-2511 |
Wordfence | |
| 5.3 Medium | LifterLMS | Broken Access Control Missing Authorization to Unauthenticated Post Trashing No login needed |
≤ 8.0.1 Fixed in 8.0.2 |
CVE-2025-2290 |
Wordfence | |
| 4.8 Medium | GDPR Cookie Compliance | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.7 Fixed in 4.15.7 |
CVE-2025-1621 |
WPScan | |
| 4.8 Medium | GDPR Cookie Compliance | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.7 Fixed in 4.15.7 |
CVE-2025-1620 |
WPScan | |
| 4.8 Medium | GDPR Cookie Compliance | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.7 Fixed in 4.15.7 |
CVE-2025-1619 |
WPScan | |
| 4.8 Medium | Poll Maker | Cross-Site Scripting Admin+ Stored XSS |
< 5.5.4 Fixed in 5.5.4 |
CVE-2024-13602 |
WPScan | |
| 4.6 Medium | Download Manager | Information Disclosure Unauthenticated Data Exposure No login needed |
< 3.3.07 Fixed in 3.3.07 |
CVE-2024-13126 |
WPScan | |
| 6.3 Medium | Pie Register Premium | Path Traversal Path Traversal to Non-Arbitrary File Deletion |
≤ 3.8.3.2 Fixed in 3.8.3.3 |
CVE-2025-26940 |
Patchstack | |
| 6.5 Medium | Ohio Extra | Content Injection Shortcode Injection No login needed |
≤ 3.4.7 |
CVE-2025-26924 |
Patchstack | |
| 6.5 Medium | Recapture for WooCommerce | Cross-Site Request Forgery CSRF to Settings Change No login needed |
≤ 1.0.43 Fixed in 1.0.44 |
CVE-2025-26899 |
Patchstack | |
| 6.5 Medium | m1.DownloadList | Cross-Site Scripting |
≤ 0.19 Fixed in 0.20 |
CVE-2025-26895 |
Patchstack | |
| 4.3 Medium | Tripetto | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Results Deletion No login needed |
≤ 8.0.9 |
CVE-2025-1530 |
Wordfence | |
| 6.5 Medium | Give | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function No login needed |
≤ 3.22.0 |
CVE-2025-2025 |
Wordfence | |
| 4.9 Medium | Thumbnail carousel slider | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.4 Fixed in 1.0.5 |
CVE-2019-25222 |
Wordfence | |
| 6.1 Medium | Traveler | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.1.8 |
CVE-2025-1773 |
Wordfence | |
| 6.5 Medium | School Management System – WPSchoolPress | SQL Injection WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection |
≤ 2.2.16 Fixed in 2.2.17 |
CVE-2025-1670 |
Wordfence | |
| 4.3 Medium | School Management System – WPSchoolPress | Broken Access Control WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion |
≤ 2.2.16 Fixed in 2.2.17 |
CVE-2025-1668 |
Wordfence | |
| 6.5 Medium | School Management System – WPSchoolPress | SQL Injection WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection |
≤ 2.2.17 Fixed in 2.2.18 |
CVE-2025-1669 |
Wordfence | |
| 6.5 Medium | WC Affiliate – A Complete WooCommerce Affiliate | Broken Access Control A Complete WooCommerce Affiliate Plugin <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via wf-export-all |
≤ 2.5.3 Fixed in 2.6 |
CVE-2024-12336 |
Wordfence | |
| 6.5 Medium | WP01 – Speed, Security, SEO consultant | Path Traversal Speed, Security, SEO consultant <= 2.6.2 - Authenticated (Subscriber+) Arbitrary File Download |
≤ 2.6.2 |
CVE-2025-2267 |
Wordfence | |
| 6.1 Medium | pixelstats | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.8.2 |
CVE-2025-2164 |
Wordfence | |
| 6.1 Medium | Zoorum Comments | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.9 |
CVE-2025-2163 |
Wordfence | |
| 5.6 Medium | Civi - Job Board & Freelance Marketplace | Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypass No login needed |
≤ 2.1.6.1 |
CVE-2024-13772 |
Wordfence | |
| 5.3 Medium | ShareThis Dashboard for Google Analytics | Broken Access Control Missing Authorization to Unauthenticated Feature Deactivation No login needed |
≤ 3.2.1 Fixed in 3.2.2 |
CVE-2025-1507 |
Wordfence | |
| 4.3 Medium | Omnipress | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.5.4 Fixed in 1.5.5 |
CVE-2024-13407 |
Wordfence | |
| 6.4 Medium | DethemeKit for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.9 |
CVE-2025-1526 |
Wordfence | |
| 4.3 Medium | Zegen - Church | Broken Access Control Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates |
≤ 1.1.9 |
CVE-2025-2289 |
Wordfence | |
| 5.3 Medium | VidoRev Extensions | Broken Access Control Missing Authorization to Unauthenticated Youtube Video Import No login needed |
≤ 2.9.9.9.9.9.5 |
CVE-2025-0955 |
Wordfence | |
| 6.1 Medium | CM FAQ – Simplify support with an intuitive FAQ management tool | Cross-Site Scripting Simplify support with an intuitive FAQ management tool <= 1.2.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.2.5 Fixed in 1.2.6 |
CVE-2025-2166 |
Wordfence | |
| 4.3 Medium | Search and filter pro | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Meta Exposure |
≤ 2.5.19 |
CVE-2025-1528 |
Wordfence | |
| 5.3 Medium | Resido - Real Estate | Broken Access Control Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update No login needed |
≤ 3.6 |
CVE-2025-1285 |
Wordfence | |
| 5.4 Medium | Download Manager | Path Traversal Authenticated (Author+) Path Traversal to Limited File Overwrite |
≤ 3.3.08 |
CVE-2025-1785 |
Wordfence | |
| 6.4 Medium | WP Recipe Maker | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 9.8.0 Fixed in 9.8.3 |
CVE-2025-1503 |
Wordfence | |
| 4.3 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication |
≤ 1.9.8 |
CVE-2025-2104 |
Wordfence | |
| 4.9 Medium | WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 2.32 |
CVE-2025-2250 |
Wordfence | |
| 5.3 Medium | Business Directory Plugin - Easy Listing Directories | Broken Access Control Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition No login needed |
≤ 6.4.14 Fixed in 6.4.15 |
CVE-2024-13887 |
Wordfence | |
| 6.4 Medium | CC-IMG-Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2025-1559 |
Wordfence | |
| 4.3 Medium | CRM and Lead Management by vcita | Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Widget Toggle |
≤ 2.7.5 |
CVE-2024-13703 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module |
≤ 3.1.0 Fixed in 3.1.1 |
CVE-2025-1527 |
Wordfence | |
| 4.3 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2024-13430 |
Wordfence | |
| 5.5 Medium | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder | Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook |
≤ 6.2 Fixed in 7.3.2 |
CVE-2024-13838 |
Wordfence | |
| 6.4 Medium | Finale Lite – Sales Countdown Timer & Discount for WooCommerce | Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer |
≤ 2.19.0 Fixed in 2.20.0 |
CVE-2024-12589 |
Wordfence | |
| 5.3 Medium | NEX-Forms – Ultimate Form Builder – Contact forms and much more | Information Disclosure Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure No login needed |
≤ 8.8.1 Fixed in 8.8.2 |
CVE-2024-13498 |
Wordfence | |
| 4.4 Medium | BlogBuzzTime-for-wp | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-2078 |
Wordfence | |
| 6.1 Medium | Simple Amazon Affiliate | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.9 |
CVE-2025-2077 |
Wordfence | |
| 4.4 Medium | binlayerpress | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-2076 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.