WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,651–10,700 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 214 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Google Earth Embed Plugin google-earth-tours Cross-Site Scripting ≤ 1.0 CVE-2025-25078 Patchstack
6.5 Medium Simple Select All Text Box Plugin simple-select-all-text-box Cross-Site Scripting ≤ 3.2 CVE-2025-25079 Patchstack
6.5 Medium Links in Captions Plugin links-in-captions Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2 CVE-2025-25098 Patchstack
6.5 Medium FlexIDX Home Search Plugin flexidx-home-search Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.2 CVE-2025-25082 Patchstack
5.9 Medium Easy WP Tiles Plugin easy-wp-tiles Cross-Site Scripting ≤ 1 CVE-2025-25073 Patchstack
6.5 Medium NextGen Cooliris Gallery Plugin nextgen-cooliris-gallery Cross-Site Scripting ≤ 0.7 CVE-2025-25091 Patchstack
6.5 Medium Graceful Email Obfuscation Plugin graceful-email-obfuscation Cross-Site Scripting ≤ 0.2.2 CVE-2025-25076 Patchstack
4.3 Medium Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time Plugin builder-shortcode-extras Information Disclosure WordPress Shortcodes Collection to Save You Time <= 1.0.0 - Authenticated (Contributor+) Post Disclosure ≤ 1.0.0 CVE-2024-13841 Wordfence
6.1 Medium Guten Free Options Plugin guten-free-options Cross-Site Scripting Reflected XSS No login needed ≤ 0.9.5 CVE-2024-13492 WPScan
6.5 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function ≤ 1.27.6 CVE-2025-0859 Wordfence
4.7 Medium LikeBot – Decentralized like-system Plugin Cross-Site Scripting Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF No login needed ≤ 0.85 CVE-2025-0522 WPScan
5.3 Medium WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Information Disclosure Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.0.8 CVE-2024-13829 Wordfence
6.5 Medium Ksher Plugin ksher-payment Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22730 Patchstack
6.5 Medium Alert Box Block – Display notice/alerts in the front end Plugin alert-box-block Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-22675 Patchstack
6.5 Medium Product Blocks for WooCommerce Plugin product-blocks-for-woocommerce Cross-Site Scripting ≤ 1.9.1 Fixed in 2.0 CVE-2025-22674 Patchstack
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.1.3.5 Fixed in 5.1.3.6 CVE-2025-22664 Patchstack
6.5 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-22662 Patchstack
6.5 Medium Music Press Pro Plugin music-press-pro Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.4.6 CVE-2025-22653 Patchstack
4.3 Medium OnePress Plugin onepress Broken Access Control ≤ 2.3.11 CVE-2025-22643 Patchstack
6.5 Medium Dynamic Conditions Plugin dynamicconditions Cross-Site Scripting ≤ 1.7.4 Fixed in 1.7.5 CVE-2025-22642 Patchstack
5.9 Medium FM Notification Bar Plugin fm-notification-bar Cross-Site Scripting ≤ 1.0.4 CVE-2025-22641 Patchstack
6.5 Medium Responsive Blocks Plugin responsive-block-editor-addons Cross-Site Scripting ≤ 1.9.9 Fixed in 2.0.0 CVE-2025-22697 Patchstack
5.4 Medium Document Block – Upload & Embed Docs Plugin document Broken Access Control Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin <= 1.1.0 - Broken Access Control ≤ 1.1.0 CVE-2025-22696 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.7 CVE-2024-13699 Wordfence
6.5 Medium SocialV - Social Network and Community BuddyPress Theme Broken Access Control Social Network and Community BuddyPress Theme <= 2.0.15 - Missing Authorization to Arbitrary File Download ≤ 2.0.15 CVE-2024-13529 Wordfence
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13733 Wordfence
6.1 Medium ShopSite Plugin shopsite-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.10 CVE-2024-13510 Wordfence
6.5 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion No login needed ≤ 4.6 CVE-2024-13356 Wordfence
6.4 Medium WPForms Lite Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter ≤ 1.9.3.1 CVE-2024-13403 Wordfence
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
4.3 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 1.6.2 CVE-2024-12046 Wordfence
4.3 Medium JS Help Desk – The Ultimate Help Desk & Support Plugin js-support-ticket Broken Access Control The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.8.8 CVE-2024-13607 Wordfence
6.4 Medium HT Mega Plugin ht-mega-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css ≤ 2.7.6 CVE-2024-12597 Wordfence
5.3 Medium Sensei LMS Plugin sensei-lms Information Disclosure Unauthenticated sensei_email/sensei_message Disclosure No login needed < 4.24.4 Fixed in 4.24.4 CVE-2025-0466 WPScan
6.1 Medium Banner Garden Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.1.3 CVE-2025-0368 WPScan
6.1 Medium TransFinanz Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13332 WPScan
6.1 Medium WP Dream Carousel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1b CVE-2024-13331 WPScan
6.1 Medium Giga Messenger Bots Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.3.1 CVE-2024-13328 WPScan
6.1 Medium Musicbox Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.3 CVE-2024-13327 WPScan
6.1 Medium iBuildApp Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.2.0 CVE-2024-13326 WPScan
6.1 Medium Glossy Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.3.5 CVE-2024-13325 WPScan
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 3.0 CVE-2024-13115 WPScan
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.0 CVE-2024-13114 WPScan
4.3 Medium Activity Log WinterLock Plugin winterlock Cross-Site Request Forgery Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted. No login needed prior to 1.2.5 CVE-2025-24982 jpcert
4.3 Medium Eventer Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Bookings Export ≤ 3.9.9 CVE-2024-11134 Wordfence
6.4 Medium Eventer Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.9.4 CVE-2024-11132 Wordfence
5.3 Medium Eventer Plugin Broken Access Control Missing Authorization to Unauthenticated Event Ticket Download No login needed ≤ 3.9.9.5 CVE-2024-11133 Wordfence
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
4.3 Medium Nirweb support Plugin nirweb-support Broken Access Control ≤ 3.0.3 CVE-2025-22695 Patchstack
4.3 Medium Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-22694 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only