WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,151–10,200 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 204 of 342
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Zalo Live Chat Plugin zalo-live-chat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-26542 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack
6.5 Medium GDPR Tools Plugin gdpr-tools Cross-Site Scripting ≤ 1.0.2 CVE-2025-26537 Patchstack
7.1 High Another Events Calendar Plugin another-events-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.0 CVE-2025-26536 Patchstack
7.1 High Theme Demo Bar Plugin wordpress-theme-demo-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-25134 Patchstack
8.1 High Formality Plugin formality Local File Inclusion No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-24690 Patchstack
7.1 High Google Plus Plugin google-plus-google Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23964 Patchstack
8.1 High custom-field-list-widget Plugin custom-field-list-widget Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-23952 Patchstack
8.1 High LinkedIn Lite Plugin linkedin-lite Local File Inclusion No login needed ≤ 1.0 CVE-2025-23937 Patchstack
7.1 High Infugrator Plugin infugrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23735 Patchstack
7.1 High AuMenu Plugin aumenu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-23728 Patchstack
7.1 High AppReview Plugin appreview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-23714 Patchstack
7.1 High Your Lightbox Plugin your-lightbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23704 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
7.1 High Management-screen-droptiles Plugin cxc-sawa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23666 Patchstack
7.1 High Frontend Post Submission Plugin frontend-post-submission Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23638 Patchstack
7.1 High WP Database Audit Plugin database-audit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23633 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23612 Patchstack
7.1 High RDP inGroups+ Plugin rdp-ingroups Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-23546 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack
7.1 High RDP Linkedin Login Plugin rdp-linkedin-login Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2025-23542 Patchstack
7.1 High Site Editor Google Map Plugin site-editor-google-map Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23466 Patchstack
7.1 High RWS Enquiry And Lead Follow-up Plugin rws-enquiry Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23460 Patchstack
7.1 High NS Simple Intro Loader Plugin ns-simple-intro-loader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2025-23459 Patchstack
7.1 High GetSocial Plugin getsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-22283 Patchstack
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.7 CVE-2025-1312 Wordfence
6.4 Medium Zapier Plugin zapier Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user Function ≤ 1.5.1 CVE-2024-13411 Wordfence
7.2 High WordPress Importer Plugin wordpress-importer PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 0.8.3 CVE-2024-13889 Wordfence
6.5 Medium Jobs Plugin job-postings Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 2.7.11 CVE-2025-1310 Wordfence
7.2 High Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Remote Code Execution WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection ≤ 1.16.10 CVE-2025-2257 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.19.0 CVE-2025-1784 Wordfence
7.5 High WP01 Plugin wp01 Path Traversal Arbitrary File Download No login needed ≤ 2.6.2 CVE-2025-30567 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-28904 Patchstack
6.5 Medium Gallery for Social Photo Plugin feed-instagram-lite Cross-Site Scripting ≤ 1.0.0.35 Fixed in 1.0.0.37 CVE-2025-26742 Patchstack
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11273 WPScan
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11272 WPScan
5.9 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.11 Fixed in 2.7.11 CVE-2024-10105 WPScan
5.9 Medium wA11y – The Web Accessibility Toolbox Plugin wa11y Cross-Site Scripting The Web Accessibility Toolbox plugin <= 1.0.3 - Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2025-30623 Patchstack
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
6.5 Medium WP Social Widget Plugin wp-social-widget Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-30610 Patchstack
5.3 Medium AppExperts Plugin appexperts Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.5 CVE-2025-30609 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
5.9 Medium Easy Page Transition Plugin easy-page-transition Cross-Site Scripting ≤ 1.0.1 CVE-2025-30606 Patchstack
4.3 Medium sourceplay-navermap Plugin sourceplay-navermap Broken Access Control ≤ 0.0.2 CVE-2025-30605 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only