WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,801–10,850 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 217 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Table Editor Plugin wp-table-editor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.1 CVE-2024-13661 Wordfence
6.1 Medium Wonder FontAwesome Plugin wonder-fontawesome Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.8 CVE-2024-13512 Wordfence
6.4 Medium WP Dispensary Plugin wp-dispensary Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.0 CVE-2024-12444 Wordfence
4.3 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Broken Access Control Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing Authorization to Icon Font Deletion ≤ 1.5.9 CVE-2024-11583 Wordfence
6.4 Medium Automatically Hierarchic Categories in Menu Plugin automatically-hierarchic-categories-in-menu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.7 CVE-2024-13466 Wordfence
6.4 Medium Alex Reservations: Smart Restaurant Booking Plugin alex-reservations Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.0.5 CVE-2024-13380 Wordfence
6.1 Medium WP Image Uploader Plugin wp-image-uploader Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2024-13706 Wordfence
6.1 Medium Simple:Press Forum Plugin simplepress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.10.11 CVE-2024-12409 Wordfence
6.4 Medium Clinked Client Portal Plugin clinked-client-portal Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2024-12524 Wordfence
4.9 Medium VR-Frases (collect & share quotes) Plugin vr-frases SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.0.1 CVE-2025-0861 Wordfence
6.1 Medium VR-Frases (collect & share quotes) Plugin vr-frases Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.0.1 CVE-2025-0860 Wordfence
6.5 Medium CP Contact Form with PayPal Plugin cp-contact-form-with-paypal Cross-Site Request Forgery No login needed ≤ 1.3.52 CVE-2024-13758 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter ≤ 1.9.9 CVE-2024-13732 Wordfence
6.4 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.8.24 CVE-2024-13470 Wordfence
6.4 Medium Stratum – Elementor Widgets Plugin Cross-Site Scripting Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerability via Image Hotspot Widget ≤ 1.4.7 CVE-2024-13642 Wordfence
5.3 Medium Event Tickets Plugin Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure No login needed ≤ 5.18.1 CVE-2024-13457 Wordfence
4.3 Medium Bulk Me Now Plugin Cross-Site Request Forgery Message Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12709 WPScan
6.5 Medium GoodLayers Core Plugin Cross-Site Scripting Subscriber+ Stored XSS via SVG Upload < 2.1.3 Fixed in 2.1.3 CVE-2024-12163 WPScan
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting Contributor+ Stored XSS < 2.4.0 Fixed in 2.4.0 CVE-2024-10309 WPScan
6.4 Medium EthereumICO Plugin ethereumico Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ethereum-ico Shortcode ≤ 2.4.6 CVE-2024-12921 Wordfence
6.4 Medium Divi Torque Lite Plugin addons-for-divi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 4.1.0 CVE-2025-0353 Wordfence
6.4 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via brid_override_yt Shortcode ≤ 3.8.3 CVE-2024-13561 Wordfence
6.4 Medium ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages Plugin clickwhale Cross-Site Scripting Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2025-0804 Wordfence
6.4 Medium Philantro – Donations and Donor Management Plugin philantro Cross-Site Scripting Donations and Donor Management <= 5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via donate Shortcode ≤ 5.3 CVE-2024-13527 Wordfence
6.1 Medium MailUp Auto Subscription Plugin mailup-auto-subscribtion Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2024-13521 Wordfence
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter ≤ 3.7.8 CVE-2025-0321 Wordfence
4.8 Medium Social Share Buttons Plugin share-button Cross-Site Scripting Admin+ Stored XSS ≤ 2.7 CVE-2024-12807 WPScan
6.1 Medium Infility Global Plugin infility-global Cross-Site Scripting Reflected XSS No login needed ≤ 2.9.8 CVE-2024-12723 WPScan
4.8 Medium Simple Image Sizes Plugin simple-image-sizes Cross-Site Scripting Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of th… 3.2.3 and earlier CVE-2025-24810 jpcert
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
5.3 Medium Houzez Plugin houzez Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.2 CVE-2025-24747 Patchstack
4.3 Medium Bridge Core Plugin bridge-core Broken Access Control ≤ 3.3 Fixed in 3.3.1 CVE-2025-24744 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-24743 Patchstack
4.3 Medium WP Go Maps Plugin wp-google-maps Cross-Site Request Forgery No login needed ≤ 9.0.40 Fixed in 9.0.41 CVE-2025-24742 Patchstack
4.7 Medium KB Support Plugin kb-support Open Redirect No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-24741 Patchstack
4.7 Medium LearnPress Plugin learnpress Open Redirect No login needed ≤ 4.2.7.1 Fixed in 4.2.7.2 CVE-2025-24740 Patchstack
5.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Information Disclosure Sensitive Data Exposure No login needed ≤ 1.27.12 Fixed in 1.27.13 CVE-2025-24689 Patchstack
5.3 Medium LearnDash LMS Plugin sfwd-lms Broken Access Control No login needed ≤ 4.20.0.1 Fixed in 4.20.0.3 CVE-2025-24662 Patchstack
4.3 Medium Admin and Site Enhancements (ASE) Pro Plugin admin-site-enhancements-pro Broken Access Control ≤ 7.6.1.1 Fixed in 7.6.3 CVE-2025-24653 Patchstack
5.3 Medium Google Captcha Plugin google-captcha Authentication Bypass Captcha Bypass No login needed ≤ 1.78 Fixed in 1.79 CVE-2025-24628 Patchstack
6.4 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Easy Estimates and Invoices for WordPress plugin <=20.8.1 - Broken Access Control ≤ 20.8.1 Fixed in 20.8.2 CVE-2025-24606 Patchstack
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
5.3 Medium RSVPMarker Plugin rsvpmaker Broken Access Control No login needed ≤ 11.4.5 Fixed in 11.4.6 CVE-2025-24600 Patchstack
5.3 Medium picu Plugin picu Broken Access Control Online Photo Proofing Gallery plugin <= 2.4.0 - Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24590 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.7.0 Fixed in 6.7.1 CVE-2025-24537 Patchstack
5.4 Medium PAPERCITE Plugin papercite Broken Access Control ≤ 0.5.18 CVE-2025-23849 Patchstack
6.5 Medium WP Smart Tooltip Plugin wp-smart-tool-tip Cross-Site Scripting ≤ 1.0.0 CVE-2025-23669 Patchstack
6.5 Medium Donate visa Plugin donate-visa Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-23656 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only