WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,201–10,250 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 205 of 342
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High JiangQie Official Website Mini Program Plugin jiangqie-official-website-mini-program SQL Injection ≤ 1.8.2 CVE-2025-30604 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack
4.3 Medium Flipdish Ordering System Plugin flipdish-ordering-system Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.5.2 CVE-2025-30601 Patchstack
5.9 Medium WP Hotjar Plugin wp-hotjar Cross-Site Scripting ≤ 0.0.3 CVE-2025-30600 Patchstack
5.9 Medium WP Parallax Content Slider Plugin wp-parallax-content-slider Cross-Site Scripting ≤ 0.9.8 CVE-2025-30599 Patchstack
4.3 Medium OSS Upload Plugin oss-upload Cross-Site Request Forgery WordPress OSS Upload plugin <= 4.8.9 Cross Site Request Forgery (CSRF) No login needed ≤ 4.8.9 CVE-2025-30598 Patchstack
6.5 Medium IG Shortcodes Plugin ig-shortcodes Cross-Site Scripting WordPress IG Shortcodes plugin <= 3.1 Cross Site Scripting (XSS) ≤ 3.1 CVE-2025-30597 Patchstack
6.5 Medium include-file Plugin include-file Cross-Site Scripting WordPress include-file plugin <= 1 Cross Site Scripting (XSS) ≤ 1 CVE-2025-30595 Patchstack
6.5 Medium Include URL Plugin include-url Cross-Site Scripting WordPress Include URL plugin <= 0.3.5 Cross Site Scripting (XSS) ≤ 0.3.5 CVE-2025-30593 Patchstack
5.3 Medium Advanced Dewplayer Plugin advanced-dewplayer Broken Access Control plugin <= 1.6 Broken Access Control No login needed ≤ 1.6 CVE-2025-30592 Patchstack
5.3 Medium Music Press Pro Plugin music-press-pro Broken Access Control WordPress Music Press Pro plugin <= 1.4.6 Broken Access Control No login needed ≤ 1.4.6 CVE-2025-30591 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30590 Patchstack
7.1 High Map Contact Plugin map-contact Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.4 CVE-2025-30588 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High cTabs Plugin ctabs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-30586 Patchstack
4.3 Medium Generate Post Thumbnails Plugin generate-post-thumbnails Cross-Site Request Forgery No login needed ≤ 0.8 CVE-2025-30585 Patchstack
7.1 High AlphaOmega Captcha & Anti-Spam Filter Plugin alphaomega-captcha-anti-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3 CVE-2025-30584 Patchstack
7.1 High Pro Rank Tracker Plugin proranktracker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30583 Patchstack
5.3 Medium Top Bar Plugin ultimate-bar Broken Access Control No login needed ≤ 3.3 CVE-2025-30581 Patchstack
7.1 High AdSense Privacy Policy Plugin adsense-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30578 Patchstack
7.1 High Browser Address Bar Color Plugin browser-address-bar-color Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3 Fixed in 3.4 CVE-2025-30577 Patchstack
4.3 Medium Hacklog Remote Image Autosave Plugin hacklog-remote-image-autosave Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-30576 Patchstack
5.9 Medium Login Redirect Plugin login-redirect Cross-Site Scripting WordPress Login Redirect plugin <= - 1.0.5 Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2025-30575 Patchstack
5.9 Medium Mobile Navigation Plugin mobile-navigation Cross-Site Scripting WordPress Mobile Navigation plugin <= - 1.5 Cross Site Scripting (XSS) ≤ 1.5 CVE-2025-30574 Patchstack
5.9 Medium My Default Post Content Plugin my-default-post-content Cross-Site Scripting WordPress My Default Post Content plugin <= - 0.7.3 Cross Site Scripting (XSS) ≤ 0.7.3 CVE-2025-30573 Patchstack
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
7.6 High STEdb Forms Plugin stedb-forms SQL Injection ≤ 1.0.4 CVE-2025-30571 Patchstack
7.6 High دکمه، شبکه اجتماعی خرید Plugin dokme SQL Injection ≤ 2.0.6 CVE-2025-30570 Patchstack
8.5 High WP Featured Entries Plugin wp-featured-entries SQL Injection WordPress WP Featured Entries plugin <= - 1.0 SQL Injection ≤ 1.0 CVE-2025-30569 Patchstack
4.3 Medium Super Static Cache Plugin super-static-cache Cross-Site Request Forgery No login needed ≤ 3.3.5 CVE-2025-30568 Patchstack
6.5 Medium Clink Plugin clink Cross-Site Scripting ≤ 1.2.2 CVE-2025-30566 Patchstack
7.1 High banner-manager Plugin banner-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 16.04.19 CVE-2025-30565 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
7.1 High CAS Maestro Plugin cas-maestro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 CVE-2025-30561 Patchstack
7.1 High jQuery Dropdown Menu Plugin jquery-drop-down-menu-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 CVE-2025-30560 Patchstack
7.1 High ANAC XML Render Plugin anac-xml-render Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.7 CVE-2025-30558 Patchstack
4.3 Medium Easy 301 Redirects Plugin odihost-easy-redirect-301 Cross-Site Request Forgery No login needed ≤ 1.33 CVE-2025-30557 Patchstack
4.3 Medium Fix Rss Feeds Plugin fix-rss-feed Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-30556 Patchstack
7.1 High WordPres 同步微博 Plugin wp2wb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30555 Patchstack
6.5 Medium GMO Font Agent Plugin gmo-font-agent Cross-Site Scripting ≤ 1.6 CVE-2025-30553 Patchstack
7.1 High WordPress Admin Bar Improved Plugin wordpress-admin-bar-improved Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.5 CVE-2025-30552 Patchstack
6.5 Medium Pretty file links Plugin pretty-file-links Cross-Site Scripting ≤ 0.9 CVE-2025-30551 Patchstack
7.1 High CallPhone'r Plugin callphoner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30550 Patchstack
4.3 Medium Yummly Rich Recipes Plugin yummly-rich-recipes Cross-Site Request Forgery No login needed ≤ 4.2 CVE-2025-30549 Patchstack
4.3 Medium Cackle Plugin cackle Cross-Site Request Forgery No login needed ≤ 4.33 CVE-2025-30546 Patchstack
5.9 Medium issuuPress Plugin issuupress Cross-Site Scripting ≤ 1.3.2 CVE-2025-30545 Patchstack
4.3 Medium Menu Duplicator Plugin copy-menu Broken Access Control ≤ 1.0 CVE-2025-30543 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only