WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,801–10,850 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 217 of 342
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Internal Links Generator Plugin internal-links-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.51 CVE-2025-23571 Patchstack
7.1 High WP Login Attempt Log Plugin wp-login-attempt-log Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23568 Patchstack
6.5 Medium WPLingo Plugin wplingo Broken Access Control Arbitrary Content Deletion ≤ 1.1.2 CVE-2025-23534 Patchstack
7.1 High Kv Compose Email From Dashboard Plugin kv-send-email-from-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23525 Patchstack
7.1 High HSS Embed Streaming Video Plugin hss-embed-streaming-video Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.23 CVE-2025-23523 Patchstack
7.1 High WordPress 淘宝客插件 Plugin taobaoke Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23492 Patchstack
7.1 High Live Dashboard Plugin live-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2025-23474 Patchstack
7.1 High Envato Affiliater Plugin envato-affiliater Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2025-23431 Patchstack
7.1 High QMean – WordPress Did You Mean Plugin qmean Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-23428 Patchstack
9.9 Critical Widget Options Plugin widget-options Remote Code Execution Arbitrary Code Execution ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-22630 Patchstack
6.5 Medium Embed Google Map Plugin embed-google-map Cross-Site Scripting ≤ 3.2 CVE-2025-26539 Patchstack
6.5 Medium Prezi Embedder Plugin prezi-embedder Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1 CVE-2025-26538 Patchstack
7.1 High TinyMCE Advanced qTranslate fix editor problems Plugin tinymce-advanced-qtranslate-fix-editor-problems Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-26582 Patchstack
7.1 High Page/Post Specific Social Share Buttons Plugin pagepost-specific-social-share-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26580 Patchstack
7.1 High Simple Documentation Plugin client-documentation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.8 CVE-2025-26578 Patchstack
7.1 High DX-auto-publish Plugin dx-auto-publish Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-26577 Patchstack
6.5 Medium Google Drive WP Media Plugin google-drive-wp-media Cross-Site Scripting ≤ 2.4.4 CVE-2025-26574 Patchstack
7.1 High WP PHPList Plugin phplist-form-integration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-26572 Patchstack
7.1 High Wibiya Toolbar Plugin wibiya Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-26571 Patchstack
7.1 High Glance That Plugin glance-that Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.9 CVE-2025-26570 Patchstack
7.1 High Post Thumbs Plugin post-thumbs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-26569 Patchstack
7.1 High Easy Amazon Product Information Plugin easy-amazon-product-information Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.1 CVE-2025-26568 Patchstack
6.5 Medium Font Awesome WP Plugin font-awesome-wp Cross-Site Scripting ≤ 1.0 CVE-2025-26567 Patchstack
7.1 High RSS Filter Plugin rss-filter Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-26562 Patchstack
5.9 Medium Elfsight Yottie Lite Plugin yottie-lite Cross-Site Scripting ≤ 1.3.3 CVE-2025-26561 Patchstack
6.5 Medium Aparat Responsive Plugin aparat-responsive Cross-Site Scripting ≤ 1.3 CVE-2025-26558 Patchstack
7.1 High Naver Syndication V2 Plugin badr-naver-syndication Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.8.3 CVE-2025-26552 Patchstack
7.1 High Bootstrap collapse Plugin bootstrap-collapse Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-26551 Patchstack
7.1 High Global Meta Keyword & Description Plugin global-meta-keyword-and-description Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 2.3 CVE-2025-26550 Patchstack
7.1 High WP Html Page Sitemap Plugin wp-html-page-sitemap Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26549 Patchstack
7.1 High My Login Logout Plugin my-loginlogout Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26547 Patchstack
7.1 High Related Posts Line-up-Exactly by Milliard Plugin related-posts-line-up-exactry-by-milliard Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.22 CVE-2025-26545 Patchstack
7.1 High Simple Responsive Menu Plugin simple-responsive-menu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26543 Patchstack
6.1 Medium Listivo - Classified Ads Theme Cross-Site Scripting Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting No login needed ≤ 2.3.67 CVE-2024-13867 Wordfence
8.1 High Puzzles | WP Magazine / Review with Store WordPress Theme + RTL Theme PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.2.4 CVE-2024-13770 Wordfence
5.4 Medium Global Gallery - WordPress Responsive Gallery Plugin Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 9.1.5 CVE-2024-13814 Wordfence
8.1 High ZoxPress - The All-In-One WordPress News Theme Broken Access Control The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Deletion ≤ 2.12.0 CVE-2024-13654 Wordfence
8.1 High Click Mag - Viral WordPress News Magazine/Blog Theme Broken Access Control Viral WordPress News Magazine/Blog Theme <= 3.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Deletion ≤ 3.6.0 CVE-2024-13656 Wordfence
8.8 High ZoxPress - The All-In-One WordPress News Theme Broken Access Control The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 2.12.0 CVE-2024-13653 Wordfence
9.8 Critical Real Estate 7 Theme Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed ≤ 3.5.1 CVE-2024-13421 Wordfence
8.1 High Popup Plugin For WordPress - ConvertPlus Plugin Broken Access Control ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 3.5.30 CVE-2024-13800 Wordfence
6.4 Medium Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin gs-woo-brands Cross-Site Scripting Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.2 CVE-2024-11746 Wordfence
6.4 Medium Puzzles | WP Magazine / Review with Store WordPress Theme + RTL Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.2.4 CVE-2024-13769 Wordfence
4.3 Medium aDirectory – WordPress Directory Listing Plugin adirectory Broken Access Control WordPress Directory Listing Plugin <= 2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 2.3 CVE-2024-13541 Wordfence
5.3 Medium The Ultimate WordPress Toolkit – WP Extended Plugin Broken Access Control WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation No login needed ≤ 3.0.13 CVE-2024-13554 Wordfence
6.4 Medium DWT - Directory & Listing Theme Cross-Site Scripting Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.3.4 CVE-2025-0169 Wordfence
8.2 High BookPress – For Book Authors Plugin book-press Broken Access Control For Book Authors Plugin <= 1.2.7 - Broken Access Control No login needed ≤ 1.2.7 CVE-2025-25167 Patchstack
7.1 High BookPress – For Book Authors Plugin book-press Cross-Site Request Forgery For Book Authors Plugin <= 1.2.7 - CSRF to Stored XSS No login needed ≤ 1.2.7 CVE-2025-25168 Patchstack
7.1 High InLocation Plugin inlocation Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-25166 Patchstack
7.5 High Plugin A/B Image Optimizer Plugin images-optimizer Path Traversal Arbitrary File Download No login needed ≤ 3.3 CVE-2025-25163 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only