WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,301–10,350 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 207 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Resido - Real Estate Theme Broken Access Control Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update No login needed ≤ 3.6 CVE-2025-1285 Wordfence
4.9 Medium WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins Plugin reportattacks SQL Injection Authenticated (Admin+) SQL Injection ≤ 2.32 CVE-2025-2250 Wordfence
5.3 Medium Business Directory Plugin - Easy Listing Directories Plugin business-directory-plugin Broken Access Control Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition No login needed ≤ 6.4.14 CVE-2024-13887 Wordfence
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
5.9 Medium DP ALTerminator - Missing ALT manager Plugin dp-alterminator-missing-alt-manager Cross-Site Scripting Missing ALT manager Plugin <= 1.0.2 - Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2025-28943 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-28938 Patchstack
5.9 Medium Lava Ajax Search Plugin lava-ajax-search Cross-Site Scripting ≤ 1.1.9 CVE-2025-28937 Patchstack
5.9 Medium Lunar Plugin lunar-sell-photos-online Cross-Site Scripting ≤ 1.3.0 CVE-2025-28936 Patchstack
7.1 High MaxA/B Plugin maxab Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-28933 Patchstack
7.1 High Insert Code Plugin insert-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 CVE-2025-28932 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
6.5 Medium List Mixcloud Plugin list-mixcloud Cross-Site Scripting ≤ 1.4 CVE-2025-28930 Patchstack
6.5 Medium Tabbed Login Widget Plugin tabbed-login Cross-Site Scripting ≤ 1.1.2 CVE-2025-28929 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
5.9 Medium Post Read Time Plugin post-read-time Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.6 CVE-2025-28926 Patchstack
7.1 High WATI Chat and Notification Plugin wati-chat-and-notification Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.5 CVE-2025-28925 Patchstack
7.1 High No Disposable Email Plugin no-disposable-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-28923 Patchstack
7.1 High Go To Top Plugin go-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.8 CVE-2025-28922 Patchstack
5.3 Medium Responsive Google Map Plugin responsive-google-map Broken Access Control No login needed ≤ 3.1.5 CVE-2025-28920 Patchstack
6.5 Medium Easy Image Display Plugin easy-image-display Cross-Site Scripting ≤ 1.2.5 CVE-2025-28919 Patchstack
6.5 Medium Featured Image Thumbnail Grid Plugin thumbnail-grid Cross-Site Scripting ≤ 6.8 Fixed in 6.9 CVE-2025-28918 Patchstack
9.1 Critical ThemeEgg ToolKit Plugin themeegg-toolkit Arbitrary File Upload ≤ 1.2.9 CVE-2025-28915 Patchstack
5.9 Medium wordpress login form to anywhere Plugin wp-show-login-form Cross-Site Scripting ≤ 0.2 CVE-2025-28914 Patchstack
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
5.9 Medium pipDisqus Plugin pipdisqus Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28908 Patchstack
5.9 Medium WP Last Modified Plugin wp-last-modified Cross-Site Scripting ≤ 0.1 CVE-2025-28907 Patchstack
5.9 Medium Skitter Slideshow Plugin wp-skitter-slideshow Cross-Site Scripting ≤ 2.5.2 CVE-2025-28906 Patchstack
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack
7.1 High TabGarb Pro Plugin tabgarb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6 CVE-2025-28900 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
4.7 Medium AS English Admin Plugin as-english-admin Open Redirect No login needed ≤ 1.0.0 CVE-2025-28896 Patchstack
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High List of Posts from each Category Plugin list-posts-by-category Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28894 Patchstack
7.1 High FTP Sync Plugin ftp-sync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.6 CVE-2025-28892 Patchstack
7.1 High price-calc Plugin price-calc Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6.3 CVE-2025-28891 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
7.1 High WP Compare Tables Plugin wp-compare-tables Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-28883 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
6.5 Medium Bee Layer Slider Plugin bee-layer-slider Cross-Site Scripting ≤ 1.1 CVE-2025-28879 Patchstack
5.9 Medium Awesome Surveys Plugin awesome-surveys Cross-Site Scripting ≤ 2.0.10 CVE-2025-28878 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only