WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,151–10,200 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 204 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Appsero Helper Plugin appsero-helper Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2024-13436 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.1 Medium Contact Us By Lord Linus Plugin Cross-Site Scripting Admin+ Stored XSS via CSRF ≤ 2.6 CVE-2025-1382 WPScan
4.3 Medium easy-broken-link-checker Plugin Cross-Site Request Forgery Bulk Actions via CSRF ≤ 9.0.2 CVE-2025-1362 WPScan
5.3 Medium Starter Templates by FancyWP Plugin starter-templates Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.0.0 CVE-2024-13924 Wordfence
4.3 Medium RomethemeKit For Elementor Plugin rometheme-for-elementor Broken Access Control Missing Authorization in save_options and reset_widgets ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-10326 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-1664 Wordfence
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.0 CVE-2024-13675 Wordfence
6.4 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin Cross-Site Scripting FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.6.7 CVE-2024-13649 Wordfence
6.4 Medium Gallery Styles Plugin gallery-styles Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-1783 Wordfence
6.3 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Broken Access Control Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction ≤ 16.26.10 CVE-2025-1325 Wordfence
4.3 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Information Disclosure Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure ≤ 16.26.10 CVE-2025-1322 Wordfence
6.4 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Cross-Site Scripting Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 16.26.10 CVE-2025-1324 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
5.4 Medium Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 2.3.6 CVE-2024-13816 Wordfence
4.3 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Information Disclosure WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 2.5.5 CVE-2024-10321 Wordfence
5.4 Medium Email Keep Plugin Cross-Site Request Forgery Email Deletion via CSRF ≤ 1.1 CVE-2024-13826 WPScan
6.1 Medium Email Keep Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13825 WPScan
4.3 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates ≤ 2.4.29 Fixed in 2.4.30 CVE-2024-12114 Wordfence
4.9 Medium Post SMTP Plugin post-smtp SQL Injection Authenticated (Administrator+) SQL Injection via columns Parameter ≤ 3.1.2 CVE-2024-13844 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size ≤ 2.4.29 CVE-2024-12119 Wordfence
5.9 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 5.4.1 CVE-2024-13640 Wordfence
4.3 Medium Code Snippets CPT Plugin code-snippets-cpt Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 2.1.0 CVE-2024-13895 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2024-13774 Wordfence
4.3 Medium Post Lockdown Plugin post-lockdown Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Disclosure ≤ 4.0.2 Fixed in 4.0.3 CVE-2025-1504 Wordfence
6.4 Medium Years Since – Timeless Plugin years-since Cross-Site Scripting Timeless <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-12460 Wordfence
6.5 Medium Shortcode Cleaner Lite Plugin shortcode-cleaner-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Export ≤ 1.0.9 CVE-2025-1481 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget ≤ 2.8.2 Fixed in 2.8.3 CVE-2025-1261 Wordfence
6.5 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo SQL Injection Authenticated (Subscriber+) SQL Injection via search Parameter ≤ 12.4.05 CVE-2025-1768 Wordfence
6.1 Medium Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins Plugin related-post Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed 2.0.59 CVE-2024-12634 Wordfence
4.8 Medium Reservit Hotel Plugin reservit-hotel Cross-Site Scripting Admin+ Stored XSS < 3.0 Fixed in 3.0 CVE-2024-9458 WPScan
5.5 Medium WPGet API Plugin wpgetapi Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.2.10 CVE-2024-13857 Wordfence
4.3 Medium VK Blocks Plugin vk-blocks Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 1.94.2.2 Fixed in 1.95.0.3 CVE-2024-13635 Wordfence
4.3 Medium SupportCandy – Helpdesk & Customer Support Ticket System Plugin supportcandy Broken Access Control Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference ≤ 3.3.0 Fixed in 3.3.6 CVE-2024-13552 Wordfence
6.4 Medium Advanced File Manager Plugin file-manager-advanced Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload ≤ 5.2.14 CVE-2024-13805 Wordfence
6.1 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.3 Fixed in 1.6.8.5 CVE-2024-13431 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 93.0.0 CVE-2024-12610 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Student+) SQL Injection via 'view-attendance' ≤ 92.0.0 CVE-2024-12609 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence
6.5 Medium Hero Maps Premium - Customizable Google Maps Plugin SQL Injection Customizable Google Maps Plugin <= 2.3.9 - Authenticated (Subscriber+) SQL Injection ≤ 2.3.9 CVE-2024-13781 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 93.0.0 CVE-2024-12611 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' ≤ 92.0.0 CVE-2024-12607 Wordfence
6.4 Medium Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.28 Fixed in 3.14.29 CVE-2025-0863 Wordfence
6.4 Medium Wishlist Plugin wishlist Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.43 Fixed in 1.0.44 CVE-2024-12809 Wordfence
4.3 Medium Homey Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed ≤ 2.4.3 CVE-2025-0748 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Broken Access Control Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export ≤ 4.0.7.3 CVE-2024-13526 Wordfence
4.3 Medium Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics Plugin cookiebot Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission ≤ 4.4.1 Fixed in 4.4.2 CVE-2025-1666 Wordfence
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed ≤ 4.2.2 CVE-2025-1383 Wordfence
5.5 Medium Notibar Plugin notibar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.1.5 CVE-2025-1672 Wordfence
6.5 Medium Moving Media Library Plugin moving-media-library Path Traversal Authenticated (Administrator+) Directory Traversal to Arbitrary File Deletion ≤ 1.22 Fixed in 1.23 CVE-2024-13897 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only