WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,051–10,100 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 202 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.8.3 CVE-2025-1802 Wordfence
6.4 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Cross-Site Scripting FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget ≤ 1.4.7.1 CVE-2025-2108 Wordfence
5.3 Medium Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update No login needed ≤ 4.0.24 CVE-2025-1766 Wordfence
4.3 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function No login needed ≤ 2.2.5 CVE-2025-1314 Wordfence
4.9 Medium AHAthat Plugin ahathat SQL Injection Authenticated (Administrator+) SQL Injection via id Parameter ≤ 1.6 CVE-2025-2511 Wordfence
5.3 Medium LifterLMS Plugin lifterlms Broken Access Control Missing Authorization to Unauthenticated Post Trashing No login needed ≤ 8.0.1 Fixed in 8.0.2 CVE-2025-2290 Wordfence
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1621 WPScan
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1620 WPScan
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1619 WPScan
4.8 Medium Poll Maker Plugin poll-maker Cross-Site Scripting Admin+ Stored XSS < 5.5.4 Fixed in 5.5.4 CVE-2024-13602 WPScan
4.6 Medium Download Manager Plugin download-manager Information Disclosure Unauthenticated Data Exposure No login needed < 3.3.07 Fixed in 3.3.07 CVE-2024-13126 WPScan
6.3 Medium Pie Register Premium Plugin pie-register-premium Path Traversal Path Traversal to Non-Arbitrary File Deletion ≤ 3.8.3.2 Fixed in 3.8.3.3 CVE-2025-26940 Patchstack
6.5 Medium Ohio Extra Plugin ohio-extra Content Injection Shortcode Injection No login needed ≤ 3.4.7 CVE-2025-26924 Patchstack
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
6.5 Medium m1.DownloadList Plugin m1downloadlist Cross-Site Scripting ≤ 0.19 Fixed in 0.20 CVE-2025-26895 Patchstack
4.3 Medium Tripetto Plugin tripetto Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Results Deletion No login needed ≤ 8.0.9 CVE-2025-1530 Wordfence
6.5 Medium Give Plugin give Broken Access Control Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function No login needed ≤ 3.22.0 CVE-2025-2025 Wordfence
4.9 Medium Thumbnail carousel slider Plugin wp-responsive-thumbnail-slider SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 Fixed in 1.0.5 CVE-2019-25222 Wordfence
6.1 Medium Traveler Theme Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.1.8 CVE-2025-1773 Wordfence
6.5 Medium School Management System – WPSchoolPress Plugin wpschoolpress SQL Injection WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-1670 Wordfence
4.3 Medium School Management System – WPSchoolPress Plugin wpschoolpress Broken Access Control WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-1668 Wordfence
6.5 Medium School Management System – WPSchoolPress Plugin wpschoolpress SQL Injection WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection ≤ 2.2.17 Fixed in 2.2.18 CVE-2025-1669 Wordfence
6.5 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Broken Access Control A Complete WooCommerce Affiliate Plugin <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via wf-export-all ≤ 2.5.3 Fixed in 2.6 CVE-2024-12336 Wordfence
6.5 Medium WP01 – Speed, Security, SEO consultant Plugin wp01 Path Traversal Speed, Security, SEO consultant <= 2.6.2 - Authenticated (Subscriber+) Arbitrary File Download ≤ 2.6.2 CVE-2025-2267 Wordfence
6.1 Medium pixelstats Plugin pixelstats Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.8.2 CVE-2025-2164 Wordfence
6.1 Medium Zoorum Comments Plugin zoorum-comments Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-2163 Wordfence
5.6 Medium Civi - Job Board & Freelance Marketplace Theme Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypass No login needed ≤ 2.1.6.1 CVE-2024-13772 Wordfence
5.3 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Broken Access Control Missing Authorization to Unauthenticated Feature Deactivation No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-1507 Wordfence
4.3 Medium Omnipress Plugin omnipress Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-13407 Wordfence
6.4 Medium DethemeKit for Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.9 CVE-2025-1526 Wordfence
4.3 Medium Zegen - Church Theme Broken Access Control Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates ≤ 1.1.9 CVE-2025-2289 Wordfence
5.3 Medium VidoRev Extensions Plugin Broken Access Control Missing Authorization to Unauthenticated Youtube Video Import No login needed ≤ 2.9.9.9.9.9.5 CVE-2025-0955 Wordfence
6.1 Medium CM FAQ – Simplify support with an intuitive FAQ management tool Plugin cm-faq Cross-Site Scripting Simplify support with an intuitive FAQ management tool <= 1.2.5 - Reflected Cross-Site Scripting No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-2166 Wordfence
4.3 Medium Search and filter pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Meta Exposure ≤ 2.5.19 CVE-2025-1528 Wordfence
5.3 Medium Resido - Real Estate Theme Broken Access Control Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update No login needed ≤ 3.6 CVE-2025-1285 Wordfence
5.4 Medium Download Manager Plugin download-manager Path Traversal Authenticated (Author+) Path Traversal to Limited File Overwrite ≤ 3.3.08 CVE-2025-1785 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.8.0 Fixed in 9.8.3 CVE-2025-1503 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication ≤ 1.9.8 CVE-2025-2104 Wordfence
4.9 Medium WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins Plugin reportattacks SQL Injection Authenticated (Admin+) SQL Injection ≤ 2.32 CVE-2025-2250 Wordfence
5.3 Medium Business Directory Plugin - Easy Listing Directories Plugin business-directory-plugin Broken Access Control Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition No login needed ≤ 6.4.14 Fixed in 6.4.15 CVE-2024-13887 Wordfence
6.4 Medium CC-IMG-Shortcode Plugin cc-img-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2025-1559 Wordfence
4.3 Medium CRM and Lead Management by vcita Plugin crm-customer-relationship-management-by-vcita Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Widget Toggle ≤ 2.7.5 CVE-2024-13703 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-1527 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 Fixed in 1.9.9 CVE-2024-13430 Wordfence
5.5 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 6.2 Fixed in 7.3.2 CVE-2024-13838 Wordfence
6.4 Medium Finale Lite – Sales Countdown Timer & Discount for WooCommerce Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer ≤ 2.19.0 Fixed in 2.20.0 CVE-2024-12589 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Information Disclosure Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.8.1 Fixed in 8.8.2 CVE-2024-13498 Wordfence
4.4 Medium BlogBuzzTime-for-wp Plugin blogbuzztime-for-wp Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-2078 Wordfence
6.1 Medium Simple Amazon Affiliate Plugin simple-amazon-affiliate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.9 CVE-2025-2077 Wordfence
4.4 Medium binlayerpress Plugin binlayerpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-2076 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only