WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,201–10,250 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 205 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Easy Broken Link Checker Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 9.0.2 CVE-2024-13868 WPScan
5.1 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed 2.8.0 CVE-2025-22623 Fluid Attacks
5.3 Medium Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More Plugin content-control Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.5.0 Fixed in 2.6.0 CVE-2024-11153 Wordfence
5.3 Medium Sparkling Theme sparkling Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation No login needed ≤ 2.4.9 CVE-2024-13423 Wordfence
4.3 Medium Spreadsheet Integration Plugin wpgsi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed ≤ 3.8.2 CVE-2025-1463 Wordfence
4.3 Medium WooMail - WooCommerce Email Customizer Plugin Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection ≤ 3.0.34 CVE-2024-13747 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode ≤ 3.10.7 Fixed in 3.10.8 CVE-2024-11731 Wordfence
6.5 Medium Listingo - Business Listing and Directory Theme Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.7 CVE-2024-13815 Wordfence
4.3 Medium Zass - WooCommerce Theme for Handmade Artists and Artisans Theme Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 3.9.9.10 CVE-2024-13810 Wordfence
6.5 Medium Hero Slider - WordPress Slider Plugin SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.3.5 CVE-2024-13809 Wordfence
6.4 Medium Point Maker Plugin point-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.6 CVE-2024-12815 Wordfence
6.5 Medium WP Online Contract Plugin Broken Access Control Missing Authorization to Unauthenticated Settings Import No login needed ≤ 5.1.4 CVE-2025-0954 Wordfence
6.1 Medium Company Directory Plugin staff-directory-pro Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Function No login needed ≤ 4.3 CVE-2024-13839 Wordfence
4.3 Medium Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 4.5.7 CVE-2024-13811 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.16.5 CVE-2024-13778 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin responsive-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library ≤ 1.3.4, ≤ 2.4.7 CVE-2024-5667 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.10.6 CVE-2024-13757 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion ≤ 1.16.5 CVE-2024-13780 Wordfence
6.1 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-13779 Wordfence
6.4 Medium Simple Notification Plugin simple-notification Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13866 Wordfence
6.4 Medium Recently Purchased Products For Woo Plugin recently-purchased-products-for-woo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter ≤ 1.1.3 CVE-2025-1008 Wordfence
6.1 Medium Razorpay Subscription Button Elementor Plugin razorpay-subscription-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-13827 Wordfence
6.4 Medium SearchIQ – The Search Solution Plugin searchiq Cross-Site Scripting The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.7 CVE-2024-13350 Wordfence
5.3 Medium JNews - WordPress Newspaper Magazine Blog AMP Theme Broken Access Control WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration No login needed ≤ 11.6.6 CVE-2024-8682 Wordfence
6.3 Medium bbPress Plugin bbpress Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed ≤ 2.6.11 Fixed in 2.6.12 CVE-2025-1435 Wordfence
4.3 Medium I Am Gloria Plugin gloria-assistant-by-webtronic-labs Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-0990 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter ≤ 7.3.3 CVE-2025-0370 Wordfence
5.4 Medium Ultimate WordPress Auction Plugin ultimate-auction Broken Access Control Missing Authorization to Arbitrary Post Deletion ≤ 4.2.9 Fixed in 4.3.4 CVE-2025-0958 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 2.0.7.1 CVE-2025-0433 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization ≤ 2.6.2 CVE-2024-13724 Wordfence
6.4 Medium Structured Content (JSON-LD) #wpsc Plugin structured-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode ≤ 1.6.3 CVE-2025-0512 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.0.7.2 CVE-2024-9618 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
5.3 Medium Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Limit Login Attempt Bypass via IP Spoofing No login needed < 7.6.10 Fixed in 7.6.10 CVE-2024-13685 WPScan
6.5 Medium teachPress Plugin teachpress SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.0.7 CVE-2025-1321 Wordfence
4.3 Medium VW Storefront Theme vw-storefront Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 0.9.9 CVE-2024-13686 Wordfence
4.9 Medium GPX Viewer Plugin gpx-viewer Path Traversal ≤ 2.2.11 Fixed in 2.2.12 CVE-2025-27274 Patchstack
5.8 Medium Affiliate Links Manager Plugin affiliate-links-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-27273 Patchstack
6.5 Medium Social Links Plugin social-links Cross-Site Scripting Stored Cross-Site Scripting ≤ 1.0.11 CVE-2025-25137 Patchstack
6.5 Medium RJ Quickcharts Plugin rj-quickcharts Cross-Site Scripting ≤ 0.6.1 CVE-2025-25131 Patchstack
5.4 Medium Theme Options Z Plugin theme-options-z Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-25121 Patchstack
6.5 Medium Like dislike plus counter Plugin like-dislike-plus-counter Cross-Site Scripting ≤ 1.0 CVE-2025-25115 Patchstack
6.5 Medium UniTimetable Plugin unitimetable Cross-Site Scripting ≤ 1.1 CVE-2025-25084 Patchstack
6.5 Medium Woo Update Variations In Cart Plugin woo-update-variations-in-cart Cross-Site Scripting ≤ 0.0.9 CVE-2025-23829 Patchstack
6.5 Medium WAH Forms Plugin wah-forms Information Disclosure Sensitive Data Exposure ≤ 1.0 CVE-2025-23763 Patchstack
6.5 Medium Interactive Page Hierarchy Plugin interactive-page-hierarchy Broken Access Control ≤ 1.0.1 CVE-2025-23615 Patchstack
6.5 Medium WP Journal Plugin wpjournal Broken Access Control ≤ 1.1 CVE-2025-23613 Patchstack
6.5 Medium DZS Ajaxer Lite Plugin dzs-ajaxer-lite-dynamic-page-load Cross-Site Scripting ≤ 1.04 CVE-2025-23579 Patchstack
6.5 Medium ts-tree Plugin ts-tree Broken Access Control Arbitrary Content Deletion ≤ 0.1.1 CVE-2025-23515 Patchstack
6.5 Medium RSVP ME Plugin rsvp-me Cross-Site Scripting ≤ 1.9.9 CVE-2025-23480 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only