WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,101–10,150 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 203 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Content Download ≤ 2.1.14 Fixed in 2.1.15 CVE-2025-1508 Wordfence
4.4 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.15.6 CVE-2025-2205 Wordfence
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
5.9 Medium DP ALTerminator - Missing ALT manager Plugin dp-alterminator-missing-alt-manager Cross-Site Scripting Missing ALT manager Plugin <= 1.0.2 - Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2025-28943 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-28938 Patchstack
5.9 Medium Lava Ajax Search Plugin lava-ajax-search Cross-Site Scripting ≤ 1.1.9 CVE-2025-28937 Patchstack
5.9 Medium Lunar Plugin lunar-sell-photos-online Cross-Site Scripting ≤ 1.3.0 CVE-2025-28936 Patchstack
6.5 Medium List Mixcloud Plugin list-mixcloud Cross-Site Scripting ≤ 1.4 CVE-2025-28930 Patchstack
6.5 Medium Tabbed Login Widget Plugin tabbed-login Cross-Site Scripting ≤ 1.1.2 CVE-2025-28929 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
5.9 Medium Post Read Time Plugin post-read-time Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.6 CVE-2025-28926 Patchstack
5.3 Medium Responsive Google Map Plugin responsive-google-map Broken Access Control No login needed ≤ 3.1.5 CVE-2025-28920 Patchstack
6.5 Medium Easy Image Display Plugin easy-image-display Cross-Site Scripting ≤ 1.2.5 CVE-2025-28919 Patchstack
6.5 Medium Featured Image Thumbnail Grid Plugin thumbnail-grid Cross-Site Scripting ≤ 6.8 Fixed in 6.9 CVE-2025-28918 Patchstack
5.9 Medium wordpress login form to anywhere Plugin wp-show-login-form Cross-Site Scripting ≤ 0.2 CVE-2025-28914 Patchstack
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
5.9 Medium pipDisqus Plugin pipdisqus Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28908 Patchstack
5.9 Medium WP Last Modified Plugin wp-last-modified Cross-Site Scripting ≤ 0.1 CVE-2025-28907 Patchstack
5.9 Medium Skitter Slideshow Plugin wp-skitter-slideshow Cross-Site Scripting ≤ 2.5.2 CVE-2025-28906 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
4.7 Medium AS English Admin Plugin as-english-admin Open Redirect No login needed ≤ 1.0.0 CVE-2025-28896 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
6.5 Medium Bee Layer Slider Plugin bee-layer-slider Cross-Site Scripting ≤ 1.1 CVE-2025-28879 Patchstack
5.9 Medium Awesome Surveys Plugin awesome-surveys Cross-Site Scripting ≤ 2.0.10 CVE-2025-28878 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
5.9 Medium BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28875 Patchstack
6.5 Medium BP Email Assign Templates Plugin bp-email-assign-templates Broken Access Control Arbitrary Content Deletion ≤ 1.7 Fixed in 1.8 CVE-2025-28874 Patchstack
5.3 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Broken Access Control No login needed ≤ 2.2.4 CVE-2025-28872 Patchstack
5.9 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Cross-Site Scripting ≤ 2.2.4 CVE-2025-28871 Patchstack
6.5 Medium amoCRM WebForm Plugin amocrm-webform Cross-Site Scripting ≤ 1.1 CVE-2025-28870 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
4.3 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Information Disclosure Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content ≤ 1.8.13 CVE-2024-13228 Wordfence
4.8 Medium Coronavirus (COVID-19) Notice Message Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.1.2 CVE-2025-0629 WPScan
6.1 Medium SEO Tools Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 4.0.7 CVE-2024-13853 WPScan
4.3 Medium XV Random Quotes Plugin xv-random-quotes Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 1.40 CVE-2024-13580 WPScan
6.1 Medium ProductDyno Plugin productdyno Cross-Site Scripting Reflected Cross-Site Scripting via 'res' Parameter No login needed ≤ 1.0.24 CVE-2024-13413 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only