WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,351–10,400 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 208 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Sticky Content Plugin sticky-menu-block Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26881 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.5 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-26877 Patchstack
6.8 Medium Search with Typesense Plugin search-with-typesense Path Traversal ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-26876 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.8.3 Fixed in 4.8.4 CVE-2025-26871 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.25.10 Fixed in 3.25.11 CVE-2024-54444 Patchstack
5.4 Medium Simple Photo Feed Plugin simple-photo-feed Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-27000 Patchstack
5.3 Medium Advanced Google reCaptcha Plugin advanced-google-recaptcha Authentication Bypass Built-in Math CAPTCHA Bypass No login needed ≤ 1.27 Fixed in 1.28 CVE-2025-1262 Wordfence
6.4 Medium Enfold Theme Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id ≤ 6.0.9 CVE-2024-13695 Wordfence
5.3 Medium Enfold Theme Broken Access Control Missing Authorization to Sensitive Information Disclosure in avia-export-class.php No login needed ≤ 6.0.9 CVE-2024-13693 Wordfence
4.3 Medium WordPress File Upload Plugin wp-file-upload Cross-Site Request Forgery Cross-Site Request Forgery in wfu_file_details No login needed ≤ 4.25.2 Fixed in 4.25.3 CVE-2024-13494 Wordfence
5.3 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Information Disclosure Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure No login needed ≤ 4.0.4 Fixed in 4.0.5 CVE-2025-1063 Wordfence
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
5.4 Medium Sticky Header On Scroll Plugin sticky-header-on-scroll Broken Access Control ≤ 1.0 CVE-2025-27356 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
6.5 Medium Local Search SEO Contact Page Plugin local-search-seo-contact-page Cross-Site Scripting ≤ 4.0.1 CVE-2025-27351 Patchstack
6.5 Medium Get Posts Plugin nurelm-get-posts Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.6 CVE-2025-27349 Patchstack
6.5 Medium WP Social SEO Booster – Knowledge Graph Social Signals SEO Plugin wp-social-seo-booster Cross-Site Scripting ≤ 1.2.0 CVE-2025-27348 Patchstack
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
6.5 Medium Reactive Mortgage Calculator Plugin reactive-mortgage-calculator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-27341 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
6.5 Medium PlayerJS Plugin playerjs Cross-Site Scripting ≤ 2.23 Fixed in 2.24 CVE-2025-27330 Patchstack
6.5 Medium EZ InLinkz linkup Plugin inlinkz-scripter Cross-Site Scripting ≤ 0.18 CVE-2025-27329 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
6.5 Medium Live Streaming Video Player – by SRS Player Plugin srs-player Cross-Site Scripting by SRS Player plugin <= 1.0.18 - Cross Site Scripting (XSS) ≤ 1.0.18 CVE-2025-27327 Patchstack
6.5 Medium Animated Text Block Plugin animated-text-block Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26883 Patchstack
6.5 Medium Video.js HLS Player Plugin videojs-hls-player Cross-Site Scripting ≤ 1.0.2 CVE-2025-27325 Patchstack
6.5 Medium WP About Author Plugin wp-about-author Cross-Site Scripting ≤ 1.5 Fixed in 1.6 CVE-2025-27323 Patchstack
6.5 Medium Profile Widget Ninja Plugin profile-widget-ninja Cross-Site Scripting ≤ 4.3 CVE-2025-27320 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack
4.3 Medium RAYS Grid Plugin rays-grid Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-27317 Patchstack
4.3 Medium JPG, PNG Compression and Optimization Plugin wp-image-compression Cross-Site Request Forgery No login needed ≤ 1.7.35 CVE-2025-27316 Patchstack
4.3 Medium All-In-One Cufon Plugin all-in-one-cufon Cross-Site Request Forgery No login needed ≤ 1.3.0 CVE-2025-27315 Patchstack
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
6.5 Medium Quotes llama Plugin quotes-llama Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-27307 Patchstack
6.5 Medium Pathomation Plugin pathomation Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.5.1 CVE-2025-27306 Patchstack
6.5 Medium Table of Contents Block Plugin table-of-contents Cross-Site Scripting ≤ 1.0.2 CVE-2025-27305 Patchstack
5.9 Medium Contact Form 7 Star Rating with font Awesome Plugin contact-form-7-star-rating-with-font-awersome Cross-Site Scripting ≤ 1.3 CVE-2025-27304 Patchstack
5.9 Medium Contact Form 7 Star Rating Plugin contact-form-7-star-rating Cross-Site Scripting ≤ 1.10 CVE-2025-27303 Patchstack
4.8 Medium WP-Asambleas Plugin wp-asambleas Arbitrary Shortcode Execution No login needed ≤ 2.85.0 CVE-2025-27294 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack
6.5 Medium Archive Page Plugin archive-page Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-27280 Patchstack
6.5 Medium Hover Image Button Plugin hover-image-button Cross-Site Scripting ≤ 1.1.2 CVE-2025-27266 Patchstack
6.5 Medium Google Maps Plugin google-maps-for-wordpress Cross-Site Scripting ≤ 1.0.3 CVE-2025-27265 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only