WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,651–10,700 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 214 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
7.1 High Smart Maintenance & Countdown Plugin smart-maintenance-countdown Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-27332 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
6.5 Medium PlayerJS Plugin playerjs Cross-Site Scripting ≤ 2.23 Fixed in 2.24 CVE-2025-27330 Patchstack
6.5 Medium EZ InLinkz linkup Plugin inlinkz-scripter Cross-Site Scripting ≤ 0.18 CVE-2025-27329 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
6.5 Medium Live Streaming Video Player – by SRS Player Plugin srs-player Cross-Site Scripting by SRS Player plugin <= 1.0.18 - Cross Site Scripting (XSS) ≤ 1.0.18 CVE-2025-27327 Patchstack
6.5 Medium Animated Text Block Plugin animated-text-block Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26883 Patchstack
6.5 Medium Video.js HLS Player Plugin videojs-hls-player Cross-Site Scripting ≤ 1.0.2 CVE-2025-27325 Patchstack
6.5 Medium WP About Author Plugin wp-about-author Cross-Site Scripting ≤ 1.5 Fixed in 1.6 CVE-2025-27323 Patchstack
7.1 High Blightly Explorer Plugin blighty-explorer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.0 CVE-2025-27321 Patchstack
6.5 Medium Profile Widget Ninja Plugin profile-widget-ninja Cross-Site Scripting ≤ 4.3 CVE-2025-27320 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack
4.3 Medium RAYS Grid Plugin rays-grid Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-27317 Patchstack
4.3 Medium JPG, PNG Compression and Optimization Plugin wp-image-compression Cross-Site Request Forgery No login needed ≤ 1.7.35 CVE-2025-27316 Patchstack
4.3 Medium All-In-One Cufon Plugin all-in-one-cufon Cross-Site Request Forgery No login needed ≤ 1.3.0 CVE-2025-27315 Patchstack
8.5 High WP Sitemap Plugin wp-sitemap SQL Injection ≤ 1.0 CVE-2025-27312 Patchstack
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
6.5 Medium Quotes llama Plugin quotes-llama Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-27307 Patchstack
6.5 Medium Pathomation Plugin pathomation Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.5.1 CVE-2025-27306 Patchstack
6.5 Medium Table of Contents Block Plugin table-of-contents Cross-Site Scripting ≤ 1.0.2 CVE-2025-27305 Patchstack
5.9 Medium Contact Form 7 Star Rating with font Awesome Plugin contact-form-7-star-rating-with-font-awersome Cross-Site Scripting ≤ 1.3 CVE-2025-27304 Patchstack
5.9 Medium Contact Form 7 Star Rating Plugin contact-form-7-star-rating Cross-Site Scripting ≤ 1.10 CVE-2025-27303 Patchstack
7.2 High NHR Options Table Manager Plugin nhrrob-options-table-manager PHP Object Injection Deserialization of untrusted data ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-27301 Patchstack
7.2 High ADFO Plugin admin-form PHP Object Injection Deserialization of untrusted data ≤ 1.9.1 CVE-2025-27300 Patchstack
8.3 High WP Video Posts Plugin wp-video-posts Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 3.5.1 CVE-2025-27298 Patchstack
7.6 High Bravo Search & Replace Plugin bravo-search-and-replace SQL Injection ≤ 1.0 CVE-2025-27297 Patchstack
7.2 High Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue Plugin revenueflex-easy-ads Broken Access Control Increase Google Adsense and Ad Manager Revenue Plugin <= 1.5 - Settings Change ≤ 1.5 Fixed in 1.5.1 CVE-2025-27296 Patchstack
4.8 Medium WP-Asambleas Plugin wp-asambleas Arbitrary Shortcode Execution No login needed ≤ 2.85.0 CVE-2025-27294 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack
6.5 Medium Archive Page Plugin archive-page Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-27280 Patchstack
7.1 High Add Linked Images To Gallery Plugin add-linked-images-to-gallery-v01 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-27277 Patchstack
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
7.5 High VG PostCarousel Plugin vg-postcarousel Local File Inclusion ≤ 1.1 CVE-2025-27272 Patchstack
6.5 Medium Hover Image Button Plugin hover-image-button Cross-Site Scripting ≤ 1.1.2 CVE-2025-27266 Patchstack
6.5 Medium Google Maps Plugin google-maps-for-wordpress Cross-Site Scripting ≤ 1.0.3 CVE-2025-27265 Patchstack
7.1 High Eventer Plugin eventer Cross-Site Scripting WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.9 Fixed in 3.9.9 CVE-2025-22635 Patchstack
5.8 Medium Give – Divi Donation Modules Plugin give-donation-modules-for-divi Information Disclosure Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-22633 Patchstack
7.1 High WooCommerce Pricing – Product Pricing Plugin woo-pricing-table Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-22632 Patchstack
7.1 High Marketing Automation Plugin marketing-automation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6.8 Fixed in 1.2.6.9 CVE-2025-22631 Patchstack
10.0 Critical Chaty Pro Plugin chaty-pro Arbitrary File Upload No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-26776 Patchstack
7.1 High Responsive Modal Builder for High Conversion – Easy Popups Plugin easy-popups Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-26774 Patchstack
6.5 Medium Distance Based Shipping Calculator Plugin distance-based-shipping-calculator Broken Access Control Settings Change No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2025-26764 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack
7.5 High Calculator Builder Plugin calculator-builder Local File Inclusion No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-26760 Patchstack
7.5 High FULL Customer Plugin full-customer Local File Inclusion Cliente plugin <= 3.1.26 - Local File Inclusion No login needed ≤ 3.1.26 Fixed in 3.1.27 CVE-2025-26757 Patchstack
8.8 High A1POST.BG Shipping for Woo Plugin a1post-bg-shipping-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5 Fixed in 1.5.1 CVE-2025-27012 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only