WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 10,201–10,250 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Easy Broken Link Checker | Cross-Site Scripting Reflected XSS No login needed |
≤ 9.0.2 |
CVE-2024-13868 |
WPScan | |
| 5.1 Medium | Ad Inserter | Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed |
2.8.0 |
CVE-2025-22623 |
Fluid Attacks | |
| 5.3 Medium | Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More | Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.5.0 Fixed in 2.6.0 |
CVE-2024-11153 |
Wordfence | |
| 5.3 Medium | Sparkling | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation No login needed |
≤ 2.4.9 |
CVE-2024-13423 |
Wordfence | |
| 4.3 Medium | Spreadsheet Integration | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed |
≤ 3.8.2 |
CVE-2025-1463 |
Wordfence | |
| 4.3 Medium | WooMail - WooCommerce Email Customizer | Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection |
≤ 3.0.34 |
CVE-2024-13747 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode |
≤ 3.10.7 Fixed in 3.10.8 |
CVE-2024-11731 |
Wordfence | |
| 6.5 Medium | Listingo - Business Listing and Directory | Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.2.7 |
CVE-2024-13815 |
Wordfence | |
| 4.3 Medium | Zass - WooCommerce Theme for Handmade Artists and Artisans | Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 3.9.9.10 |
CVE-2024-13810 |
Wordfence | |
| 6.5 Medium | Hero Slider - WordPress Slider | SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.3.5 |
CVE-2024-13809 |
Wordfence | |
| 6.4 Medium | Point Maker | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1.6 |
CVE-2024-12815 |
Wordfence | |
| 6.5 Medium | WP Online Contract | Broken Access Control Missing Authorization to Unauthenticated Settings Import No login needed |
≤ 5.1.4 |
CVE-2025-0954 |
Wordfence | |
| 6.1 Medium | Company Directory | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Function No login needed |
≤ 4.3 |
CVE-2024-13839 |
Wordfence | |
| 4.3 Medium | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce | Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 4.5.7 |
CVE-2024-13811 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.16.5 |
CVE-2024-13778 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library |
≤ 1.3.4, ≤ 2.4.7 |
CVE-2024-5667 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode |
≤ 3.10.6 |
CVE-2024-13757 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion |
≤ 1.16.5 |
CVE-2024-13780 |
Wordfence | |
| 6.1 Medium | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-13779 |
Wordfence | |
| 6.4 Medium | Simple Notification | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.3 |
CVE-2024-13866 |
Wordfence | |
| 6.4 Medium | Recently Purchased Products For Woo | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter |
≤ 1.1.3 |
CVE-2025-1008 |
Wordfence | |
| 6.1 Medium | Razorpay Subscription Button Elementor | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2024-13827 |
Wordfence | |
| 6.4 Medium | SearchIQ – The Search Solution | Cross-Site Scripting The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.7 |
CVE-2024-13350 |
Wordfence | |
| 5.3 Medium | JNews - WordPress Newspaper Magazine Blog AMP | Broken Access Control WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration No login needed |
≤ 11.6.6 |
CVE-2024-8682 |
Wordfence | |
| 6.3 Medium | bbPress | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed |
≤ 2.6.11 Fixed in 2.6.12 |
CVE-2025-1435 |
Wordfence | |
| 4.3 Medium | I Am Gloria | Cross-Site Request Forgery No login needed |
≤ 1.1.4 |
CVE-2025-0990 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter |
≤ 7.3.3 |
CVE-2025-0370 |
Wordfence | |
| 5.4 Medium | Ultimate WordPress Auction | Broken Access Control Missing Authorization to Arbitrary Post Deletion |
≤ 4.2.9 Fixed in 4.3.4 |
CVE-2025-0958 |
Wordfence | |
| 6.4 Medium | Master Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.7.1 |
CVE-2025-0433 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization |
≤ 2.6.2 |
CVE-2024-13724 |
Wordfence | |
| 6.4 Medium | Structured Content (JSON-LD) #wpsc | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode |
≤ 1.6.3 |
CVE-2025-0512 |
Wordfence | |
| 6.4 Medium | Master Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.0.7.2 |
CVE-2024-9618 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed |
≤ 2.6.2 |
CVE-2024-13682 |
Wordfence | |
| 5.3 Medium | Admin and Site Enhancements (ASE) | Authentication Bypass Limit Login Attempt Bypass via IP Spoofing No login needed |
< 7.6.10 Fixed in 7.6.10 |
CVE-2024-13685 |
WPScan | |
| 6.5 Medium | teachPress | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 9.0.7 |
CVE-2025-1321 |
Wordfence | |
| 4.3 Medium | VW Storefront | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 0.9.9 |
CVE-2024-13686 |
Wordfence | |
| 4.9 Medium | GPX Viewer | Path Traversal |
≤ 2.2.11 Fixed in 2.2.12 |
CVE-2025-27274 |
Patchstack | |
| 5.8 Medium | Affiliate Links Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-27273 |
Patchstack | |
| 6.5 Medium | Social Links | Cross-Site Scripting Stored Cross-Site Scripting |
≤ 1.0.11 |
CVE-2025-25137 |
Patchstack | |
| 6.5 Medium | RJ Quickcharts | Cross-Site Scripting |
≤ 0.6.1 |
CVE-2025-25131 |
Patchstack | |
| 5.4 Medium | Theme Options Z | Cross-Site Request Forgery No login needed |
≤ 1.4 |
CVE-2025-25121 |
Patchstack | |
| 6.5 Medium | Like dislike plus counter | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-25115 |
Patchstack | |
| 6.5 Medium | UniTimetable | Cross-Site Scripting |
≤ 1.1 |
CVE-2025-25084 |
Patchstack | |
| 6.5 Medium | Woo Update Variations In Cart | Cross-Site Scripting |
≤ 0.0.9 |
CVE-2025-23829 |
Patchstack | |
| 6.5 Medium | WAH Forms | Information Disclosure Sensitive Data Exposure |
≤ 1.0 |
CVE-2025-23763 |
Patchstack | |
| 6.5 Medium | Interactive Page Hierarchy | Broken Access Control |
≤ 1.0.1 |
CVE-2025-23615 |
Patchstack | |
| 6.5 Medium | WP Journal | Broken Access Control |
≤ 1.1 |
CVE-2025-23613 |
Patchstack | |
| 6.5 Medium | DZS Ajaxer Lite | Cross-Site Scripting |
≤ 1.04 |
CVE-2025-23579 |
Patchstack | |
| 6.5 Medium | ts-tree | Broken Access Control Arbitrary Content Deletion |
≤ 0.1.1 |
CVE-2025-23515 |
Patchstack | |
| 6.5 Medium | RSVP ME | Cross-Site Scripting |
≤ 1.9.9 |
CVE-2025-23480 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.