WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,701–10,750 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 215 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium CF7 Google Sheets Connector Plugin cf7-google-sheets-connector Broken Access Control No login needed ≤ 5.0.17 Fixed in 5.0.18 CVE-2025-22686 Patchstack
6.5 Medium NotificationX Plugin notificationx Cross-Site Scripting ≤ 2.9.5 Fixed in 3.0.0 CVE-2025-22683 Patchstack
4.3 Medium Content Cloner Plugin super-seo-content-cloner Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-22681 Patchstack
4.8 Medium Uix Shortcodes Plugin uix-shortcodes Arbitrary Shortcode Execution No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-22677 Patchstack
6.5 Medium Powerful Auto Chat Plugin powers-triggers-of-woo-to-chat Cross-Site Scripting ≤ 1.9.8 CVE-2025-22292 Patchstack
4.3 Medium Meta Tag Manager Plugin meta-tag-manager Broken Access Control ≤ 3.1 Fixed in 3.2 CVE-2025-22260 Patchstack
4.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.17.4 Fixed in 2.17.5 CVE-2024-50500 Patchstack
6.5 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.2 CVE-2025-24697 Patchstack
6.5 Medium WPGuppy Plugin wpguppy-lite Authentication Bypass Broken Authentication No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-24643 Patchstack
6.5 Medium Setup Default Featured Image Plugin setup-default-feature-image Broken Access Control No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-24642 Patchstack
6.5 Medium Korea for WooCommerce Plugin korea-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-24639 Patchstack
6.5 Medium Awesome Timeline Plugin awesome-timeline Cross-Site Scripting ≤ 1.0.1 CVE-2025-23747 Patchstack
6.5 Medium Demo User DZS Plugin demo-user-dzs-showcase-your-admin-safely Cross-Site Scripting ≤ 1.1.0 CVE-2025-23581 Patchstack
6.5 Medium MLL Audio Player MP3 Ajax Plugin music-let-loose-mp3-audio-player Cross-Site Scripting ≤ 0.7 CVE-2025-23561 Patchstack
6.5 Medium WC Wallet Plugin wc-wallet Broken Access Control Arbitrary Content Deletion ≤ 2.2.0 CVE-2025-23527 Patchstack
6.8 Medium Essential WP Real Estate Plugin Cross-Site Scripting Reflected XSS ≤ 1.1.3 CVE-2024-13347 WPScan
5.4 Medium WooCommerce Support Ticket System Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure ≤ 17.8 CVE-2024-13775 Wordfence
6.4 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.6.9 CVE-2024-13612 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Unauthenticated Company Logo Deletion No login needed ≤ 2.2.6 CVE-2024-13428 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download No login needed ≤ 2.2.6 CVE-2024-13372 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Sending No login needed ≤ 2.2.6 CVE-2024-13371 Wordfence
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Job Deletion ≤ 2.2.6 CVE-2024-13429 Wordfence
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object Reference to Authenticated (Employer+) Arbitrary Company Deletion ≤ 2.2.6 CVE-2024-13425 Wordfence
5.4 Medium Custom Related Posts Plugin custom-related-posts Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Post Search and Relation Updates ≤ 1.7.3 CVE-2024-12825 Wordfence
6.3 Medium MagicForm - WordPress Form Builder Plugin magicform Broken Access Control WordPress Form Builder <= 1.6.2 - Missing Authorization ≤ 1.6.2 CVE-2025-0939 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
6.5 Medium MultiLoca - WooCommerce Multi Locations Inventory Management Plugin SQL Injection WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+) SQL Injection ≤ 4.1.11 CVE-2024-13341 Wordfence
5.4 Medium Widget4call Plugin Cross-Site Scripting Reflected XSS ≤ 1.0.7 CVE-2024-13099 WPScan
5.4 Medium WP Email Newsletter Plugin Cross-Site Scripting Reflected XSS ≤ 1.1 CVE-2024-13098 WPScan
5.4 Medium WP Finance Plugin Cross-Site Scripting Reflected XSS ≤ 1.3.6 CVE-2024-13097 WPScan
4.6 Medium WP Finance Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.3.6 CVE-2024-13096 WPScan
5.4 Medium Responsive iframe Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.2.0 CVE-2024-12768 WPScan
6.5 Medium Jupiterx Core Plugin jupiterx-core Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 4.8.7 CVE-2025-0365 Wordfence
5.3 Medium Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings Plugin directorist Information Disclosure AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure No login needed ≤ 8.0.12 CVE-2024-12041 Wordfence
4.3 Medium RapidLoad – Optimize Web Vitals Automatically Plugin Broken Access Control Optimize Web Vitals Automatically <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Limited Setting Reset ≤ 2.4.4 CVE-2024-13651 Wordfence
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
5.3 Medium WordPress Contact Forms by Cimatti Plugin Broken Access Control Missing Authorization to Unauthenticated Form Submission Download No login needed ≤ 1.9.4 CVE-2024-12184 Wordfence
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.12 CVE-2024-13547 Wordfence
6.4 Medium Site Search 360 Plugin site-search-360 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.6 CVE-2024-11780 Wordfence
6.4 Medium eHive Objects Image Grid Plugin ehive-objects-image-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2024-13662 Wordfence
6.4 Medium Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.13 CVE-2024-12037 Wordfence
6.5 Medium AI Infographic Maker Plugin infographic-and-list-builder-ilist Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.9.0 CVE-2024-12415 Wordfence
5.3 Medium Drag and Drop Multiple File Upload – Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion No login needed ≤ 1.3.8.5 CVE-2024-12267 Wordfence
6.5 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Information Disclosure Sensitive Data Exposure ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-24597 Patchstack
6.5 Medium Designer Plugin designer Cross-Site Scripting ≤ 1.6.4 CVE-2025-23987 Patchstack
5.4 Medium Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23985 Patchstack
6.5 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Scripting ≤ 1.1.2 CVE-2025-22757 Patchstack
5.8 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-22720 Patchstack
6.5 Medium EMI Calculator Plugin emi-calculator Broken Access Control Settings Change No login needed ≤ 1.1 CVE-2025-22265 Patchstack
5.4 Medium Oshine Modules Plugin oshine-modules Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44055 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only