WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 10,151–10,200 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Appsero Helper | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.3.2 |
CVE-2024-13436 |
Wordfence | |
| 4.3 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed |
≤ 1.9.8 |
CVE-2025-1926 |
Wordfence | |
| 6.1 Medium | Contact Us By Lord Linus | Cross-Site Scripting Admin+ Stored XSS via CSRF |
≤ 2.6 |
CVE-2025-1382 |
WPScan | |
| 4.3 Medium | easy-broken-link-checker | Cross-Site Request Forgery Bulk Actions via CSRF |
≤ 9.0.2 |
CVE-2025-1362 |
WPScan | |
| 5.3 Medium | Starter Templates by FancyWP | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 2.0.0 |
CVE-2024-13924 |
Wordfence | |
| 4.3 Medium | RomethemeKit For Elementor | Broken Access Control Missing Authorization in save_options and reset_widgets |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-10326 |
Wordfence | |
| 6.4 Medium | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2025-1664 |
Wordfence | |
| 6.4 Medium | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.0 |
CVE-2024-13675 |
Wordfence | |
| 6.4 Medium | 140+ Widgets | Xpro Addons For Elementor – FREE | Cross-Site Scripting FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.6.7 |
CVE-2024-13649 |
Wordfence | |
| 6.4 Medium | Gallery Styles | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.4 Fixed in 1.3.5 |
CVE-2025-1783 |
Wordfence | |
| 6.3 Medium | WP-Recall – Registration, Profile, Commerce & More | Broken Access Control Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction |
≤ 16.26.10 |
CVE-2025-1325 |
Wordfence | |
| 4.3 Medium | WP-Recall – Registration, Profile, Commerce & More | Information Disclosure Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure |
≤ 16.26.10 |
CVE-2025-1322 |
Wordfence | |
| 6.4 Medium | WP-Recall – Registration, Profile, Commerce & More | Cross-Site Scripting Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 16.26.10 |
CVE-2025-1324 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 6.2.2 |
CVE-2025-1287 |
Wordfence | |
| 5.4 Medium | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit | Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions |
≤ 2.3.6 |
CVE-2024-13816 |
Wordfence | |
| 4.3 Medium | All-in-One Addons for Elementor – WidgetKit | Information Disclosure WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates |
≤ 2.5.5 |
CVE-2024-10321 |
Wordfence | |
| 5.4 Medium | Email Keep | Cross-Site Request Forgery Email Deletion via CSRF |
≤ 1.1 |
CVE-2024-13826 |
WPScan | |
| 6.1 Medium | Email Keep | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.1 |
CVE-2024-13825 |
WPScan | |
| 4.3 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates |
≤ 2.4.29 Fixed in 2.4.30 |
CVE-2024-12114 |
Wordfence | |
| 4.9 Medium | Post SMTP | SQL Injection Authenticated (Administrator+) SQL Injection via columns Parameter |
≤ 3.1.2 |
CVE-2024-13844 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size |
≤ 2.4.29 |
CVE-2024-12119 |
Wordfence | |
| 5.9 Medium | Print Invoice & Delivery Notes for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 5.4.1 |
CVE-2024-13640 |
Wordfence | |
| 4.3 Medium | Code Snippets CPT | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 2.1.0 |
CVE-2024-13895 |
Wordfence | |
| 6.1 Medium | Wishlist for WooCommerce: Multi Wishlists Per Customer | Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed |
≤ 3.1.7 Fixed in 3.1.8 |
CVE-2024-13774 |
Wordfence | |
| 4.3 Medium | Post Lockdown | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Disclosure |
≤ 4.0.2 Fixed in 4.0.3 |
CVE-2025-1504 |
Wordfence | |
| 6.4 Medium | Years Since – Timeless | Cross-Site Scripting Timeless <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-12460 |
Wordfence | |
| 6.5 Medium | Shortcode Cleaner Lite | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Export |
≤ 1.0.9 |
CVE-2025-1481 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget |
≤ 2.8.2 Fixed in 2.8.3 |
CVE-2025-1261 |
Wordfence | |
| 6.5 Medium | SEO Plugin by Squirrly SEO | SQL Injection Authenticated (Subscriber+) SQL Injection via search Parameter |
≤ 12.4.05 |
CVE-2025-1768 |
Wordfence | |
| 6.1 Medium | Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
2.0.59 |
CVE-2024-12634 |
Wordfence | |
| 4.8 Medium | Reservit Hotel | Cross-Site Scripting Admin+ Stored XSS |
< 3.0 Fixed in 3.0 |
CVE-2024-9458 |
WPScan | |
| 5.5 Medium | WPGet API | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 2.2.10 |
CVE-2024-13857 |
Wordfence | |
| 4.3 Medium | VK Blocks | Broken Access Control Missing Authorization to Sensitive Information Exposure |
≤ 1.94.2.2 Fixed in 1.95.0.3 |
CVE-2024-13635 |
Wordfence | |
| 4.3 Medium | SupportCandy – Helpdesk & Customer Support Ticket System | Broken Access Control Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference |
≤ 3.3.0 Fixed in 3.3.6 |
CVE-2024-13552 |
Wordfence | |
| 6.4 Medium | Advanced File Manager | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload |
≤ 5.2.14 |
CVE-2024-13805 |
Wordfence | |
| 6.1 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.8.3 Fixed in 1.6.8.5 |
CVE-2024-13431 |
Wordfence | |
| 5.3 Medium | School Management System | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 93.0.0 |
CVE-2024-12610 |
Wordfence | |
| 6.5 Medium | School Management System | SQL Injection Authenticated (Student+) SQL Injection via 'view-attendance' |
≤ 92.0.0 |
CVE-2024-12609 |
Wordfence | |
| 5.3 Medium | Platform.ly for WooCommerce | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 1.1.6 |
CVE-2024-13904 |
Wordfence | |
| 6.5 Medium | Hero Maps Premium - Customizable Google Maps | SQL Injection Customizable Google Maps Plugin <= 2.3.9 - Authenticated (Subscriber+) SQL Injection |
≤ 2.3.9 |
CVE-2024-13781 |
Wordfence | |
| 5.3 Medium | School Management System | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 93.0.0 |
CVE-2024-12611 |
Wordfence | |
| 6.5 Medium | School Management System | SQL Injection Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' |
≤ 92.0.0 |
CVE-2024-12607 |
Wordfence | |
| 6.4 Medium | Flexmls® IDX | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.14.28 Fixed in 3.14.29 |
CVE-2025-0863 |
Wordfence | |
| 6.4 Medium | Wishlist | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.43 Fixed in 1.0.44 |
CVE-2024-12809 |
Wordfence | |
| 4.3 Medium | Homey | Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed |
≤ 2.4.3 |
CVE-2025-0748 |
Wordfence | |
| 4.3 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export |
≤ 4.0.7.3 |
CVE-2024-13526 |
Wordfence | |
| 4.3 Medium | Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics | Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission |
≤ 4.4.1 Fixed in 4.4.2 |
CVE-2025-1666 |
Wordfence | |
| 4.3 Medium | Podlove Podcast Publisher | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed |
≤ 4.2.2 |
CVE-2025-1383 |
Wordfence | |
| 5.5 Medium | Notibar | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 2.1.5 |
CVE-2025-1672 |
Wordfence | |
| 6.5 Medium | Moving Media Library | Path Traversal Authenticated (Administrator+) Directory Traversal to Arbitrary File Deletion |
≤ 1.22 Fixed in 1.23 |
CVE-2024-13897 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.