WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,301–10,350 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 207 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Server-Side Request Forgery WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery ≤ 1.16.8 CVE-2024-13907 Wordfence
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.6.0 CVE-2024-6261 Wordfence
5.3 Medium OneStore Sites Plugin onestore-sites Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 0.1.1 CVE-2024-13905 Wordfence
6.4 Medium Forminator Plugin forminator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting 1.39.2 CVE-2025-0469 Wordfence
4.3 Medium School Management System – SakolaWP Plugin sakolawp-lite Cross-Site Request Forgery SakolaWP <= 1.0.8 - Cross-Site Request Forgery to Exam Setting Manipulation No login needed ≤ 1.0.8 CVE-2024-13647 Wordfence
5.3 Medium Events Manager Plugin events-manager Broken Access Control No login needed ≤ 6.6.4.1 Fixed in 6.6.4.2 CVE-2025-1249 Patchstack
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
4.4 Medium Quiz Organizer Plugin quiz-organizer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.9.1 CVE-2024-6810 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text, Countdown Widget, and Login Form Shortcodes ≤ 3.6.0 CVE-2025-1517 Wordfence
4.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-13560 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.3 CVE-2024-13803 Wordfence
6.1 Medium R3W Instafeed Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13678 WPScan
6.1 Medium CalendApp Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13669 WPScan
6.1 Medium Post Sync Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13634 WPScan
6.1 Medium News List Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13630 WPScan
6.1 Medium Pushbiz Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13629 WPScan
6.1 Medium WP Pricing Table Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13628 WPScan
5.9 Medium Countdown Timer for Elementor Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.3.7 Fixed in 1.3.7 CVE-2024-13113 WPScan
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected XSS No login needed < 5.0.0 Fixed in 5.0.0 CVE-2024-12737 WPScan
5.4 Medium WooCommerce Cart Count Shortcode Plugin Cross-Site Scripting Contributor+ XSS < 1.1.0 Fixed in 1.1.0 CVE-2024-10563 WPScan
5.3 Medium SureMembers Plugin suremembers-core Information Disclosure Sensitive Information Exposure No login needed ≤ 1.10.6 CVE-2024-12434 Wordfence
5.4 Medium Market Exporter Plugin market-exporter Broken Access Control ≤ 2.0.21 Fixed in 2.0.22 CVE-2025-26995 Patchstack
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-26983 Patchstack
6.5 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.5 Fixed in 2.5.1 CVE-2025-26980 Patchstack
5.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-26975 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-26965 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
6.5 Medium Easy Contact Form Lite Plugin contact-form-lite Cross-Site Scripting ≤ 1.1.25 Fixed in 1.1.27 CVE-2025-26962 Patchstack
6.5 Medium Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Broken Access Control Unishippers Edition plugin <= 2.4.9 - Broken Access Control No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26960 Patchstack
6.5 Medium Business Card Block Plugin business-card-block Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-26952 Patchstack
6.5 Medium Team Section Block Plugin team-section Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-26949 Patchstack
4.3 Medium Pie Register Premium Plugin pie-register-premium Broken Access Control ≤ 3.8.3.2 Fixed in 3.8.3.3 CVE-2025-26948 Patchstack
6.5 Medium Services Section block Plugin services-section Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-26947 Patchstack
6.5 Medium Info Cards Plugin info-cards Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-26945 Patchstack
6.5 Medium Counters Block Plugin counters-block Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-26939 Patchstack
6.5 Medium Countdown Timer Plugin countdown-time Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-26938 Patchstack
6.5 Medium Icon List Block Plugin icon-list-block Cross-Site Scripting ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-26937 Patchstack
4.3 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-26928 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
6.5 Medium AR Plugin ar-for-wordpress Cross-Site Scripting ≤ 7.7 Fixed in 7.8 CVE-2025-26913 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-26912 Patchstack
4.3 Medium System Dashboard Plugin system-dashboard Information Disclosure Sensitive Data Exposure ≤ 2.8.18 Fixed in 2.8.19 CVE-2025-26911 Patchstack
6.5 Medium WP Responsive Auto Fit Text Plugin wp-responsive-slab-text Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2025-26904 Patchstack
6.5 Medium List Related Attachments Plugin list-related-attachments-widget Cross-Site Scripting ≤ 2.1.6 CVE-2025-26897 Patchstack
6.5 Medium PiwigoPress Plugin piwigopress Cross-Site Scripting ≤ 2.33 CVE-2025-26896 Patchstack
6.5 Medium Easy Charts Plugin easy-charts Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-26893 Patchstack
6.5 Medium Ibtana Plugin ibtana-visual-editor Cross-Site Scripting ≤ 1.2.5.9 CVE-2025-26891 Patchstack
6.5 Medium EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Scripting ≤ 5.21.35 Fixed in 5.25.08 CVE-2025-26887 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 10.8 Fixed in 10.9 CVE-2025-26884 Patchstack
6.5 Medium Popup Builder Plugin easy-notify-lite Cross-Site Scripting ≤ 1.1.33 Fixed in 1.1.35 CVE-2025-26882 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only