WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,351–10,400 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 208 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28875 Patchstack
6.5 Medium BP Email Assign Templates Plugin bp-email-assign-templates Broken Access Control Arbitrary Content Deletion ≤ 1.7 Fixed in 1.8 CVE-2025-28874 Patchstack
5.3 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Broken Access Control No login needed ≤ 2.2.4 CVE-2025-28872 Patchstack
5.9 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Cross-Site Scripting ≤ 2.2.4 CVE-2025-28871 Patchstack
6.5 Medium amoCRM WebForm Plugin amocrm-webform Cross-Site Scripting ≤ 1.1 CVE-2025-28870 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
7.1 High WP jQuery Persian Datepicker Plugin wpjqp-datepicker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0 CVE-2025-28861 Patchstack
7.1 High Google News Editors Picks Feed Generator Plugin google-news-editors-picks-news-feeds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-28860 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack
7.1 High Rankchecker.io Integration Plugin rankchecker-io-integration Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28857 Patchstack
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
10.0 Critical Fresh Framework Plugin fresh-framework Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.70.0 CVE-2025-26936 Patchstack
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
9.0 Critical Massive Dynamic Plugin massive-dynamic Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 8.2 CVE-2025-26916 Patchstack
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
7.1 High WordPress Activity O Meter Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13668 WPScan
9.8 Critical Golo - Directory & Listing, Travel Theme Broken Access Control Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change No login needed ≤ 1.6.10 CVE-2024-12876 Wordfence
8.8 High Eventer - WordPress Event & Booking Manager Plugin SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id ≤ 3.9.9.2 CVE-2025-0959 Wordfence
8.8 High School Management System Plugin wpschoolpress Privilege Escalation Authenticated (Student+) Account Takeover and Privilege Escalation ≤ 93.0.0 CVE-2024-9658 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 93.0.0 CVE-2024-12610 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Student+) SQL Injection via 'view-attendance' ≤ 92.0.0 CVE-2024-12609 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 93.0.0 CVE-2024-12611 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' ≤ 92.0.0 CVE-2024-12607 Wordfence
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
8.1 High Flex Mag - Responsive WordPress News Theme Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 3.5.2 CVE-2024-13655 Wordfence
4.3 Medium Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics Plugin cookiebot Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission ≤ 4.4.1 CVE-2025-1666 Wordfence
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed ≤ 4.2.2 CVE-2025-1383 Wordfence
8.8 High WordPress Awesome Import & Export Plugin - Import & Export WordPress Data Plugin Broken Access Control Import & Export WordPress Data <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Execution/Privilege Escalation ≤ 4.1.1 CVE-2024-13232 Wordfence
6.5 Medium Listingo - Business Listing and Directory Theme Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.7 CVE-2024-13815 Wordfence
9.8 Critical VEDA - MultiPurpose Theme PHP Object Injection MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection No login needed ≤ 4.2 CVE-2024-13787 Wordfence
6.5 Medium Hero Slider - WordPress Slider Plugin SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.3.5 CVE-2024-13809 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.16.5 CVE-2024-13778 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion ≤ 1.16.5 CVE-2024-13780 Wordfence
6.1 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-13779 Wordfence
8.1 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin PHP Object Injection WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection No login needed ≤ 6.91 CVE-2024-13777 Wordfence
5.3 Medium JNews - WordPress Newspaper Magazine Blog AMP Theme Broken Access Control WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration No login needed ≤ 11.6.6 CVE-2024-8682 Wordfence
5.4 Medium Ultimate WordPress Auction Plugin ultimate-auction Broken Access Control Missing Authorization to Arbitrary Post Deletion ≤ 4.2.9 CVE-2025-0958 Wordfence
7.1 High Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26994 Patchstack
7.1 High Zigaform Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26989 Patchstack
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
10.0 Critical Ark Theme Core Plugin ark-core Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.71.0 Fixed in 1.71.0 CVE-2025-26970 Patchstack
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory PHP Object Injection ≤ 2.3.14 Fixed in 2.3.15 CVE-2025-26967 Patchstack
7.1 High Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Cross-Site Scripting Unishippers Edition plugin <= 2.4.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26918 Patchstack
7.1 High WP Templata Plugin wptemplata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26917 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only