WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,251–10,300 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 206 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium AvaiBook Plugin avaibook Cross-Site Scripting ≤ 1.2 CVE-2025-30540 Patchstack
5.9 Medium BMo Expo Plugin bmo-expo Cross-Site Scripting ≤ 1.0.15 CVE-2025-30539 Patchstack
4.3 Medium Simple Optimizer Plugin simple-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-30538 Patchstack
5.9 Medium Upload Quota per User Plugin upload-quota-per-user Cross-Site Scripting ≤ 1.3 CVE-2025-30537 Patchstack
5.9 Medium Beautiful Link Preview Plugin beautiful-link-preview Cross-Site Scripting ≤ 1.5.0 CVE-2025-30536 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
4.3 Medium Image Captcha Plugin image-captcha Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-30534 Patchstack
5.9 Medium Message ticker Plugin message-ticker Cross-Site Scripting ≤ 9.3 CVE-2025-30533 Patchstack
5.9 Medium Weather Layer Plugin weather-layer Cross-Site Scripting ≤ 4.2.1 CVE-2025-30532 Patchstack
4.3 Medium WP Ride Booking Plugin wp-ride-booking Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-30531 Patchstack
5.9 Medium AI Preloader Plugin ai-preloader Cross-Site Scripting ≤ 1.0.2 CVE-2025-30530 Patchstack
4.3 Medium Auto Load Next Post Plugin auto-load-next-post Cross-Site Request Forgery No login needed ≤ 1.5.14 CVE-2025-30529 Patchstack
9.3 Critical Awesome Logos Plugin awesome-logos Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.2 CVE-2025-30528 Patchstack
5.9 Medium My Bootstrap Menu Plugin my-bootstrap-menu Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 CVE-2025-30527 Patchstack
4.3 Medium Typekit Plugin typekit Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-30526 Patchstack
7.6 High WP Profitshare Plugin wp-profitshare SQL Injection ≤ 1.4.9 CVE-2025-30525 Patchstack
7.6 High Super Simple Subscriptions Plugin super-simple-subscriptions SQL Injection ≤ 1.1.0 CVE-2025-30523 Patchstack
7.1 High Contact Form 7 Material Design Plugin cf7-material-design Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30522 Patchstack
4.3 Medium GP Back To Top Plugin gp-back-to-top Cross-Site Request Forgery No login needed ≤ 3.0 CVE-2025-30521 Patchstack
8.8 High FoodBakery | Delivery Restaurant Directory Theme Broken Access Control Missing Authorization in Multiple Functions ≤ 4.7 CVE-2024-12920 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
9.8 Critical MinimogWP – The High Converting eCommerce Theme Local File Inclusion The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion No login needed ≤ 3.7.0 CVE-2024-13790 Wordfence
8.5 High All In Menu Plugin all-in-menu SQL Injection ≤ 1.1.5 CVE-2025-27281 Patchstack
8.5 High FS Poster Plugin fs-poster SQL Injection ≤ 6.5.8 Fixed in 6.5.9 CVE-2025-26978 Patchstack
8.5 High PrivateContent Plugin private-content SQL Injection ≤ 8.11.4 CVE-2025-26976 Patchstack
7.1 High PrivateContent Plugin private-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.11.5 CVE-2025-26972 Patchstack
8.3 High PrivateContent Plugin private-content Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 8.11.5 CVE-2025-26969 Patchstack
8.6 High Fresh Framework Plugin fresh-framework Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.70.0 CVE-2025-26961 Patchstack
6.3 Medium Pie Register Premium Plugin pie-register-premium Path Traversal Path Traversal to Non-Arbitrary File Deletion ≤ 3.8.3.2 Fixed in 3.8.3.3 CVE-2025-26940 Patchstack
6.5 Medium Ohio Extra Plugin ohio-extra Content Injection Shortcode Injection No login needed ≤ 3.4.7 CVE-2025-26924 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
6.5 Medium m1.DownloadList Plugin m1downloadlist Cross-Site Scripting ≤ 0.19 Fixed in 0.20 CVE-2025-26895 Patchstack
7.6 High PublishPress Authors Plugin publishpress-authors SQL Injection ≤ 4.7.3 Fixed in 4.7.4 CVE-2025-26886 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
7.1 High WP AntiDDOS Plugin wpantiddos Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-26556 Patchstack
7.1 High Debug-Bar-Extender Plugin debug-bar-extender Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-26555 Patchstack
7.1 High WP Discord Post Plugin wp-discord-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-26554 Patchstack
7.1 High Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26553 Patchstack
7.1 High Random Image Selector Plugin random-image-selector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26548 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Privilege Escalation uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 2.2.0 CVE-2025-1653 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Broken Access Control uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection ≤ 2.2.0 CVE-2025-1657 Wordfence
7.3 High Civi - Job Board & Freelance Marketplace Theme Information Disclosure Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Sensitive Information Exposure No login needed ≤ 2.1.4 CVE-2024-13773 Wordfence
5.6 Medium Civi - Job Board & Freelance Marketplace Theme Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypass No login needed ≤ 2.1.6.1 CVE-2024-13772 Wordfence
9.8 Critical Civi - Job Board & Freelance Marketplace Theme Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Password Update No login needed ≤ 2.1.4 CVE-2024-13771 Wordfence
8.8 High JobCareer | Job Board Responsive Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions ≤ 7.1 CVE-2024-12810 Wordfence
8.1 High Eco Nature - Environment & Ecology Theme Broken Access Control Environment & Ecology WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 2.0.4 CVE-2025-0952 Wordfence
4.3 Medium Zegen - Church Theme Broken Access Control Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates ≤ 1.1.9 CVE-2025-2289 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only