WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,001–1,050 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 52
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Integration for WooCommerce and QuickBooks Plugin wp-woocommerce-quickbooks Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-39600 Patchstack
9.6 Critical Custom CSS, JS & PHP Plugin custom-css Cross-Site Request Forgery CSRF to RCE No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-39601 Patchstack
9.6 Critical WPJobBoard Plugin wpjobboard Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30967 Patchstack
4.3 Medium InPost Gallery Plugin inpost-gallery Cross-Site Request Forgery No login needed ≤ 2.1.4.3 Fixed in 2.1.4.4 CVE-2025-26903 Patchstack
8.1 High Arkhe Plugin arkhe Cross-Site Request Forgery CSRF to Local File Inclusion No login needed ≤ 3.12.0 CVE-2025-26748 Patchstack
4.3 Medium WPJobBoard Plugin wpjobboard Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) vulnerabilities No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30965 Patchstack
5.4 Medium Photography Plugin photography Server-Side Request Forgery No login needed ≤ 7.7.6 Fixed in 7.7.6 CVE-2025-30964 Patchstack
4.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Server-Side Request Forgery ≤ 1.7.1006 Fixed in 1.7.1007 CVE-2025-26990 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-27009 Patchstack
5.3 Medium Webcraftic Clearfy – WordPress optimization Plugin clearfy Cross-Site Request Forgery WordPress optimization plugin <= 2.3.1 - Cross-Site Request Forgery to Clear Cache No login needed ≤ 2.3.1 CVE-2024-13338 Wordfence
4.3 Medium Webcraftic Clearfy – WordPress optimization Plugin clearfy Cross-Site Request Forgery WordPress optimization plugin <= 2.3.2 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy' No login needed ≤ 2.3.2 CVE-2024-13337 Wordfence
4.3 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Cross-Site Request Forgery No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-32282 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Cross-Site Request Forgery No login needed ≤ 2.6.1 CVE-2025-26902 Patchstack
7.1 High Site Table of Contents Plugin site-table-of-contents Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-31385 Patchstack
7.1 High FrescoChat Live Chat Plugin flexytalk-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.2.6 CVE-2025-31383 Patchstack
4.3 Medium Easyfonts Plugin easyfonts Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31005 Patchstack
5.4 Medium IndieBlocks Plugin indieblocks Server-Side Request Forgery No login needed ≤ 0.13.1 Fixed in 0.13.2 CVE-2025-31009 Patchstack
7.1 High Comment Validation Reloaded Plugin comment-validation-reloaded Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5 CVE-2025-31026 Patchstack
8.8 High Seo Meta Tags Plugin seo-meta-tags Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.4 CVE-2025-31023 Patchstack
7.1 High Pagopar – WooCommerce Gateway Plugin pagopar-woocommerce-gateway Cross-Site Request Forgery WooCommerce Gateway plugin <= 2.7.1 - CSRF to Stored XSS No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2025-31032 Patchstack
9.8 Critical Buddypress Humanity Plugin buddypress-humanity Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.2 CVE-2025-31033 Patchstack
5.9 Medium WP Editor.md – The Perfect WordPress Markdown Editor Plugin wp-editormd Cross-Site Scripting The Perfect Markdown Editor plugin <= 10.2.1 - Cross Site Scripting (XSS) ≤ 10.2.1 CVE-2025-31035 Patchstack
4.3 Medium Customize Login Page Plugin customize-login-page Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1 CVE-2025-31034 Patchstack
8.8 High WPSolr Plugin wpsolr-free Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 24.0 Fixed in 24.0.1 CVE-2025-31036 Patchstack
8.8 High Essential Breadcrumbs Plugin essential-breadcrumbs Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.1.1 CVE-2025-31038 Patchstack
7.1 High Scheduled Plugin scheduled Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31375 Patchstack
7.1 High Language Field Plugin language-field Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.9 CVE-2025-31382 Patchstack
7.1 High Social Crowd Plugin social-crowd Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.9.6.1 CVE-2025-31390 Patchstack
7.1 High The World Plugin the-world Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.4 CVE-2025-31388 Patchstack
7.1 High Script Compressor Plugin script-compressor Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.1 CVE-2025-31391 Patchstack
7.1 High Smart Product Gallery Slider Plugin smart-product-gallery-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.4 CVE-2025-31392 Patchstack
7.1 High More Mime Type Filters Plugin more-mime-type-filters Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-31394 Patchstack
7.1 High Social Bookmarking RELOADED Plugin social-bookmarking-reloaded Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.18 CVE-2025-31393 Patchstack
7.1 High CG Scroll To Top Plugin cg-scroll-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.5 CVE-2025-31399 Patchstack
7.1 High Easy Custom CSS Plugin easy-custom-css Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31395 Patchstack
7.1 High WS Audio Player Plugin ws-audio-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.8 CVE-2025-31400 Patchstack
7.1 High NewsBoard Post and RSS Scroller Plugin newsboard Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.12 CVE-2025-31402 Patchstack
7.1 High MMX – Make Me Christmas Plugin mmx-make-me-christmas Cross-Site Request Forgery Make Me Christmas plugin <= 1.0.0 - CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-31401 Patchstack
7.1 High Advanced Tag Lists Plugin advanced-tag-list Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-32476 Patchstack
7.1 High AF Tell a Friend Plugin af-tell-a-friend Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-31404 Patchstack
7.1 High WP-Easy Menu Plugin wp-easy-menu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.41 CVE-2025-32477 Patchstack
7.1 High Flags Widget Plugin flags-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.7 CVE-2025-32479 Patchstack
7.1 High WP SexyLightBox Plugin wp-sexylightbox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5.3 CVE-2025-32478 Patchstack
7.1 High Windows Live Writer Plugin windows-live-writer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-32480 Patchstack
7.1 High Custom Smilies Plugin custom-smilies Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-32482 Patchstack
7.1 High Nino Social Connect Plugin nino-social-connect Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-32481 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2025-32485 Patchstack
7.1 High WP-Planification Plugin wp-planification Cross-Site Request Forgery WP-Planning plugin <= 2.3.1 - CSRF to Stored XSS No login needed ≤ 2.3.1 CVE-2025-32484 Patchstack
4.9 Medium Waymark Plugin waymark Server-Side Request Forgery ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-32487 Patchstack
4.3 Medium reCAPTCHA Jetpack Plugin recaptcha-jetpack Cross-Site Request Forgery No login needed ≤ 0.2.2 CVE-2025-32494 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only