WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 10,801–10,850 of 17,051 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Internal Links Generator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.51 |
CVE-2025-23571 |
Patchstack | |
| 7.1 High | WP Login Attempt Log | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3 |
CVE-2025-23568 |
Patchstack | |
| 6.5 Medium | WPLingo | Broken Access Control Arbitrary Content Deletion |
≤ 1.1.2 |
CVE-2025-23534 |
Patchstack | |
| 7.1 High | Kv Compose Email From Dashboard | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-23525 |
Patchstack | |
| 7.1 High | HSS Embed Streaming Video | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.23 |
CVE-2025-23523 |
Patchstack | |
| 7.1 High | WordPress 淘宝客插件 | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.2 |
CVE-2025-23492 |
Patchstack | |
| 7.1 High | Live Dashboard | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.3.3 |
CVE-2025-23474 |
Patchstack | |
| 7.1 High | Envato Affiliater | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.4 |
CVE-2025-23431 |
Patchstack | |
| 7.1 High | QMean – WordPress Did You Mean | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0 |
CVE-2025-23428 |
Patchstack | |
| 9.9 Critical | Widget Options | Remote Code Execution Arbitrary Code Execution |
≤ 4.1.0 Fixed in 4.1.1 |
CVE-2025-22630 |
Patchstack | |
| 6.5 Medium | Embed Google Map | Cross-Site Scripting |
≤ 3.2 |
CVE-2025-26539 |
Patchstack | |
| 6.5 Medium | Prezi Embedder | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 2.1 |
CVE-2025-26538 |
Patchstack | |
| 7.1 High | TinyMCE Advanced qTranslate fix editor problems | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0.0 |
CVE-2025-26582 |
Patchstack | |
| 7.1 High | Page/Post Specific Social Share Buttons | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1 |
CVE-2025-26580 |
Patchstack | |
| 7.1 High | Simple Documentation | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.8 |
CVE-2025-26578 |
Patchstack | |
| 7.1 High | DX-auto-publish | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2 |
CVE-2025-26577 |
Patchstack | |
| 6.5 Medium | Google Drive WP Media | Cross-Site Scripting |
≤ 2.4.4 |
CVE-2025-26574 |
Patchstack | |
| 7.1 High | WP PHPList | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.7 |
CVE-2025-26572 |
Patchstack | |
| 7.1 High | Wibiya Toolbar | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.0 |
CVE-2025-26571 |
Patchstack | |
| 7.1 High | Glance That | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 4.9 |
CVE-2025-26570 |
Patchstack | |
| 7.1 High | Post Thumbs | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.5 |
CVE-2025-26569 |
Patchstack | |
| 7.1 High | Easy Amazon Product Information | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 4.0.1 |
CVE-2025-26568 |
Patchstack | |
| 6.5 Medium | Font Awesome WP | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-26567 |
Patchstack | |
| 7.1 High | RSS Filter | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-26562 |
Patchstack | |
| 5.9 Medium | Elfsight Yottie Lite | Cross-Site Scripting |
≤ 1.3.3 |
CVE-2025-26561 |
Patchstack | |
| 6.5 Medium | Aparat Responsive | Cross-Site Scripting |
≤ 1.3 |
CVE-2025-26558 |
Patchstack | |
| 7.1 High | Naver Syndication V2 | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 0.8.3 |
CVE-2025-26552 |
Patchstack | |
| 7.1 High | Bootstrap collapse | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.0.4 |
CVE-2025-26551 |
Patchstack | |
| 7.1 High | Global Meta Keyword & Description | Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed |
≤ 2.3 |
CVE-2025-26550 |
Patchstack | |
| 7.1 High | WP Html Page Sitemap | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2025-26549 |
Patchstack | |
| 7.1 High | My Login Logout | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 2.4 |
CVE-2025-26547 |
Patchstack | |
| 7.1 High | Related Posts Line-up-Exactly by Milliard | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 0.0.22 |
CVE-2025-26545 |
Patchstack | |
| 7.1 High | Simple Responsive Menu | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1 |
CVE-2025-26543 |
Patchstack | |
| 6.1 Medium | Listivo - Classified Ads | Cross-Site Scripting Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting No login needed |
≤ 2.3.67 |
CVE-2024-13867 |
Wordfence | |
| 8.1 High | Puzzles | WP Magazine / Review with Store WordPress Theme + RTL | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 4.2.4 |
CVE-2024-13770 |
Wordfence | |
| 5.4 Medium | Global Gallery - WordPress Responsive Gallery | Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 9.1.5 |
CVE-2024-13814 |
Wordfence | |
| 8.1 High | ZoxPress - The All-In-One WordPress News | Broken Access Control The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Deletion |
≤ 2.12.0 |
CVE-2024-13654 |
Wordfence | |
| 8.1 High | Click Mag - Viral WordPress News Magazine/Blog | Broken Access Control Viral WordPress News Magazine/Blog Theme <= 3.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Deletion |
≤ 3.6.0 |
CVE-2024-13656 |
Wordfence | |
| 8.8 High | ZoxPress - The All-In-One WordPress News | Broken Access Control The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update |
≤ 2.12.0 |
CVE-2024-13653 |
Wordfence | |
| 9.8 Critical | Real Estate 7 | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
≤ 3.5.1 |
CVE-2024-13421 |
Wordfence | |
| 8.1 High | Popup Plugin For WordPress - ConvertPlus | Broken Access Control ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update |
≤ 3.5.30 |
CVE-2024-13800 |
Wordfence | |
| 6.4 Medium | Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands | Cross-Site Scripting Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.2 |
CVE-2024-11746 |
Wordfence | |
| 6.4 Medium | Puzzles | WP Magazine / Review with Store WordPress Theme + RTL | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 4.2.4 |
CVE-2024-13769 |
Wordfence | |
| 4.3 Medium | aDirectory – WordPress Directory Listing | Broken Access Control WordPress Directory Listing Plugin <= 2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 2.3 |
CVE-2024-13541 |
Wordfence | |
| 5.3 Medium | The Ultimate WordPress Toolkit – WP Extended | Broken Access Control WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation No login needed |
≤ 3.0.13 |
CVE-2024-13554 |
Wordfence | |
| 6.4 Medium | DWT - Directory & Listing | Cross-Site Scripting Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.3.4 |
CVE-2025-0169 |
Wordfence | |
| 8.2 High | BookPress – For Book Authors | Broken Access Control For Book Authors Plugin <= 1.2.7 - Broken Access Control No login needed |
≤ 1.2.7 |
CVE-2025-25167 |
Patchstack | |
| 7.1 High | BookPress – For Book Authors | Cross-Site Request Forgery For Book Authors Plugin <= 1.2.7 - CSRF to Stored XSS No login needed |
≤ 1.2.7 |
CVE-2025-25168 |
Patchstack | |
| 7.1 High | InLocation | Cross-Site Scripting No login needed |
≤ 1.8 |
CVE-2025-25166 |
Patchstack | |
| 7.5 High | Plugin A/B Image Optimizer | Path Traversal Arbitrary File Download No login needed |
≤ 3.3 |
CVE-2025-25163 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.