WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,601–10,650 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 213 of 342
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Easy Quotes Plugin easy-quotes SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-26943 Patchstack
6.5 Medium Counters Block Plugin counters-block Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-26939 Patchstack
6.5 Medium Countdown Timer Plugin countdown-time Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-26938 Patchstack
6.5 Medium Icon List Block Plugin icon-list-block Cross-Site Scripting ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-26937 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-26935 Patchstack
7.5 High ChatBot Plugin chatbot Local File Inclusion ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-26932 Patchstack
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
4.3 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-26928 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
8.5 High Wishlist Plugin wishlist SQL Injection ≤ 1.0.41 Fixed in 1.0.42 CVE-2025-26915 Patchstack
6.5 Medium AR Plugin ar-for-wordpress Cross-Site Scripting ≤ 7.7 Fixed in 7.8 CVE-2025-26913 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-26912 Patchstack
4.3 Medium System Dashboard Plugin system-dashboard Information Disclosure Sensitive Data Exposure ≤ 2.8.18 Fixed in 2.8.19 CVE-2025-26911 Patchstack
7.5 High Mortgage Calculator Estatik Plugin estatik-mortgage-calculator Local File Inclusion ≤ 2.0.12 CVE-2025-26907 Patchstack
7.5 High Estatik Plugin estatik Local File Inclusion ≤ 4.3.0 CVE-2025-26905 Patchstack
6.5 Medium WP Responsive Auto Fit Text Plugin wp-responsive-slab-text Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2025-26904 Patchstack
9.8 Critical Flexmls® IDX Plugin flexmls-idx PHP Object Injection No login needed ≤ 3.14.27 Fixed in 3.14.28 CVE-2025-26900 Patchstack
6.5 Medium List Related Attachments Plugin list-related-attachments-widget Cross-Site Scripting ≤ 2.1.6 CVE-2025-26897 Patchstack
6.5 Medium PiwigoPress Plugin piwigopress Cross-Site Scripting ≤ 2.33 CVE-2025-26896 Patchstack
6.5 Medium Easy Charts Plugin easy-charts Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-26893 Patchstack
6.5 Medium Ibtana Plugin ibtana-visual-editor Cross-Site Scripting ≤ 1.2.5.9 CVE-2025-26891 Patchstack
6.5 Medium EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Scripting ≤ 5.21.35 Fixed in 5.25.08 CVE-2025-26887 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 10.8 Fixed in 10.9 CVE-2025-26884 Patchstack
6.5 Medium Popup Builder Plugin easy-notify-lite Cross-Site Scripting ≤ 1.1.33 Fixed in 1.1.35 CVE-2025-26882 Patchstack
6.5 Medium Sticky Content Plugin sticky-menu-block Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26881 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.5 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-26877 Patchstack
6.8 Medium Search with Typesense Plugin search-with-typesense Path Traversal ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-26876 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.8.3 Fixed in 4.8.4 CVE-2025-26871 Patchstack
7.1 High Fast Flow Plugin fast-flow-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.16 Fixed in 1.2.18 CVE-2025-26868 Patchstack
7.5 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Path Traversal Arbitrary File Download No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26753 Patchstack
8.6 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Arbitrary File Deletion No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26752 Patchstack
7.1 High Alphabetic Pagination Plugin alphabetic-pagination Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-26751 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.25.10 Fixed in 3.25.11 CVE-2024-54444 Patchstack
5.4 Medium Simple Photo Feed Plugin simple-photo-feed Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-27000 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.25.17 Fixed in 3.25.18 CVE-2025-26987 Patchstack
8.1 High Majestic Support Plugin majestic-support Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-26985 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Cross-Site Request Forgery in wfu_file_details No login needed ≤ 4.25.2 CVE-2024-13494 Wordfence
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
5.4 Medium Sticky Header On Scroll Plugin sticky-header-on-scroll Broken Access Control ≤ 1.0 CVE-2025-27356 Patchstack
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
7.1 High 无觅相关文章插件 Plugin wumii-related-posts Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.5.7 CVE-2025-27352 Patchstack
6.5 Medium Local Search SEO Contact Page Plugin local-search-seo-contact-page Cross-Site Scripting ≤ 4.0.1 CVE-2025-27351 Patchstack
6.5 Medium Get Posts Plugin nurelm-get-posts Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.6 CVE-2025-27349 Patchstack
6.5 Medium WP Social SEO Booster – Knowledge Graph Social Signals SEO Plugin wp-social-seo-booster Cross-Site Scripting ≤ 1.2.0 CVE-2025-27348 Patchstack
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
6.5 Medium Reactive Mortgage Calculator Plugin reactive-mortgage-calculator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-27341 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only