WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,101–10,150 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 203 of 342
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium RainbowNews Theme rainbownews Cross-Site Scripting ≤ 1.0.7 CVE-2025-26747 Patchstack
6.5 Medium Build Theme build Cross-Site Scripting ≤ 1.0.3 CVE-2025-26869 Patchstack
6.5 Medium AuraMart Plugin auramart Cross-Site Scripting ≤ 2.0.7 CVE-2025-26922 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.9.8 Fixed in 5.9.9 CVE-2025-26923 Patchstack
5.9 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-26929 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.0.18 Fixed in 5.0.19 CVE-2025-26941 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 30.1 Fixed in 30.1 CVE-2025-27014 Patchstack
7.5 High Hostiko Plugin hostiko Local File Inclusion ≤ 30.1 Fixed in 30.1 CVE-2025-27015 Patchstack
9.3 Critical Product Catalog Plugin displayproduct SQL Injection No login needed ≤ 1.0.4 CVE-2025-30524 Patchstack
9.3 Critical Trust Payments Gateway for WooCommerce Plugin trust-payments-hosted-payment-pages-integration SQL Injection No login needed ≤ 1.1.4 Fixed in 2.0.0 CVE-2025-28942 Patchstack
8.5 High WP Google Calendar Manager Plugin wp-gcalendar SQL Injection ≤ 2.1 CVE-2025-28939 Patchstack
7.1 High Fancybox Plus Plugin fancybox-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-28935 Patchstack
7.1 High Simple Post Series Plugin simple-post-series Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-28934 Patchstack
7.1 High Are you robot google recaptcha Plugin are-you-robot-recaptcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-28928 Patchstack
7.1 High ZenphotoPress Plugin zenphotopress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-28924 Patchstack
7.1 High SpatialMatch IDX Plugin spatialmatch-free-lifestyle-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 CVE-2025-28921 Patchstack
7.1 High Custom Smilies Plugin custom-smilies-se Cross-Site Scripting No login needed ≤ 2.9.2 CVE-2025-28917 Patchstack
9.8 Critical Docpro Plugin docpro Local File Inclusion No login needed ≤ 2.0.1 CVE-2025-28916 Patchstack
7.1 High Gravity 2 PDF Plugin gf2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28911 Patchstack
7.1 High Driving Directions Plugin ddirections Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2025-28903 Patchstack
7.1 High WP Event Ticketing Plugin wpeventticketing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 CVE-2025-28899 Patchstack
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.2 CVE-2025-28898 Patchstack
9.9 Critical Visual Text Editor Plugin visual-text-editor Remote Code Execution ≤ 1.2.1 CVE-2025-28893 Patchstack
7.1 High Lightview Plus Plugin lightview-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28890 Patchstack
7.1 High Custom Product Stickers for Woocommerce Plugin custom-product-stickers-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 CVE-2025-28889 Patchstack
6.5 Medium Fiverr.com Official Search Box Plugin fiverr-official-search-box Cross-Site Scripting ≤ 1.0.8 CVE-2025-28885 Patchstack
7.1 High Omnify Plugin omnify-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-28882 Patchstack
7.1 High Blue Captcha Plugin blue-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.4 Fixed in 2.0.0 CVE-2025-28880 Patchstack
7.1 High Key4ce osTicket Bridge Plugin key4ce-osticket-bridge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-28877 Patchstack
8.5 High Shuffle Theme shuffle SQL Injection ≤ 0.5 CVE-2025-28873 Patchstack
7.1 High NextGEN Gallery Voting Plugin nextgen-gallery-voting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 CVE-2025-28869 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.1 High Arrow Maps Plugin ap-google-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28858 Patchstack
7.1 High Teleport Plugin teleport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2025-28855 Patchstack
7.1 High Random Quotes Plugin random-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-27267 Patchstack
7.1 High TBTestimonials Plugin tb-testimonials Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-26584 Patchstack
7.1 High Video Share VOD Plugin video-share-vod Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2025-26583 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.1 High MicroPayments Plugin paid-membership Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-26579 Patchstack
7.1 High WP Simple Slideshow Plugin wp-simple-slideshow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26576 Patchstack
7.1 High Display Post Meta Plugin display-post-meta Cross-Site Scripting WordPress Display Post Meta plugin <= 1.5- Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-26575 Patchstack
7.1 High Rizzi Guestbook Plugin rizzi-guestbook Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-26573 Patchstack
7.1 High In Stock Mailer for WooCommerce Plugin in-stock-mailer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-26566 Patchstack
7.1 High GNUPress Plugin gnupress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-26565 Patchstack
7.1 High GNUCommerce Plugin gnucommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 CVE-2025-26564 Patchstack
7.1 High WP Contact Form III Plugin wp-contact-form-iii Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2d CVE-2025-26560 Patchstack
6.5 Medium Secure Invites Plugin wordpress-mu-secure-invites Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-26559 Patchstack
7.1 High Cookies Pro Plugin cookies-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-26546 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only