WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,901–10,950 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 219 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
5.9 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.55 Fixed in 1.2.56 CVE-2025-24723 Patchstack
6.5 Medium Widget Countdown Plugin widget-countdown Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-24719 Patchstack
6.5 Medium BookingPress Plugin bookingpress-appointment-booking Cross-Site Scripting ≤ 1.1.25 Fixed in 1.1.26 CVE-2025-24732 Patchstack
5.9 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Scripting ≤ 2.38.3 Fixed in 2.38.4 CVE-2025-24731 Patchstack
4.3 Medium FluentSMTP Plugin fluent-smtp Cross-Site Request Forgery No login needed ≤ 2.2.80 Fixed in 2.2.81 CVE-2025-24739 Patchstack
5.4 Medium Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-24724 Patchstack
5.4 Medium Herd Effects Plugin mwp-herd-effect Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-24716 Patchstack
5.9 Medium Contact Form Email Plugin contact-form-to-email Cross-Site Scripting ≤ 1.3.52 Fixed in 1.3.53 CVE-2025-24727 Patchstack
5.4 Medium Modal Window Plugin modal-window Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.4 Fixed in 6.1.5 CVE-2025-24717 Patchstack
4.4 Medium Comment Edit Core – Simple Comment Editing Plugin simple-comment-editing Server-Side Request Forgery Simple Comment Editing Plugin <= 3.0.33 - Server Side Request Forgery (SSRF) ≤ 3.0.33 Fixed in 3.1.0 CVE-2025-24703 Patchstack
5.4 Medium Counter Box Plugin counter-box Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-24715 Patchstack
5.9 Medium FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-24722 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.13 Fixed in 4.2.14 CVE-2025-24706 Patchstack
6.5 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.5 Fixed in 1.2.1 CVE-2025-24709 Patchstack
5.4 Medium Radius Blocks Plugin radius-blocks Cross-Site Request Forgery WordPress Gutenberg Blocks Plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.1.2 Fixed in 2.2.0 CVE-2025-24712 Patchstack
5.4 Medium Popup Box Plugin popup-box Cross-Site Request Forgery No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-24711 Patchstack
4.3 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Request Forgery No login needed ≤ 5.1.8 Fixed in 5.1.9 CVE-2025-24698 Patchstack
5.4 Medium Bubble Menu – circle floating menu Plugin bubble-menu Cross-Site Request Forgery No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2025-24714 Patchstack
5.3 Medium WooCommerce Quick View Plugin woo-quick-view Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-24705 Patchstack
6.5 Medium Magic the Gathering Card Tooltips Plugin magic-the-gathering-card-tooltips Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-24704 Patchstack
5.9 Medium ShMapper by Teplitsa Plugin shmapper-by-teplitsa Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-24674 Patchstack
4.4 Medium Chained Quiz Plugin chained-quiz Server-Side Request Forgery ≤ 1.3.2.9 Fixed in 1.3.3 CVE-2025-24701 Patchstack
4.4 Medium Extensions For CF7 Plugin extensions-for-cf7 Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-24695 Patchstack
4.3 Medium Advanced Notifications Plugin advanced-notifications Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-24693 Patchstack
4.3 Medium People Lists Plugin people-lists Broken Access Control ≤ 1.3.10 Fixed in 2.0.0 CVE-2025-24691 Patchstack
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
6.5 Medium Listamester Plugin listamester Cross-Site Scripting ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-24678 Patchstack
6.5 Medium Show/Hide Shortcode Plugin showhide-shortcode Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-24687 Patchstack
4.3 Medium Super Block Slider Plugin super-block-slider Broken Access Control ≤ 2.7.9 Fixed in 2.8 CVE-2025-24682 Patchstack
6.5 Medium Xagio SEO Plugin xagio-seo Cross-Site Scripting ≤ 7.0.0.20 Fixed in 7.0.0.21 CVE-2025-24702 Patchstack
6.5 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting ≤ 7.2 Fixed in 7.3 CVE-2025-24675 Patchstack
5.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Cross-Site Scripting ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-24666 Patchstack
4.3 Medium Internal Links Manager Plugin seo-automated-link-building Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24679 Patchstack
6.5 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting ≤ 0.1.2 Fixed in 0.2.1 CVE-2025-24673 Patchstack
5.9 Medium Auction Nudge – Your eBay on Your Site Plugin auction-nudge Cross-Site Scripting Your eBay on Your Site plugin <= 7.2.0 - Cross Site Scripting (XSS) ≤ 7.2.0 Fixed in 7.2.1 CVE-2025-24658 Patchstack
5.9 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Cross-Site Scripting ≤ 33.0.8 Fixed in 33.0.9 CVE-2025-24668 Patchstack
4.3 Medium Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Broken Access Control ≤ 7.6.2 Fixed in 7.6.3 CVE-2025-24649 Patchstack
5.9 Medium Wishlist for WooCommerce Plugin wt-woocommerce-wishlist Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-24657 Patchstack
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
5.4 Medium WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Cross-Site Request Forgery No login needed ≤ 1.0.35 Fixed in 1.0.36 CVE-2025-24647 Patchstack
4.3 Medium Taxonomy/Term and Role based Discounts for WooCommerce Plugin taxonomy-discounts-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.1 Fixed in 5.2 CVE-2025-24625 Patchstack
4.3 Medium Really Simple SSL Plugin really-simple-ssl Cross-Site Request Forgery No login needed ≤ 9.1.4 Fixed in 9.2.0 CVE-2025-24623 Patchstack
6.5 Medium Create with Code Plugin create-with-code Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2025-24638 Patchstack
5.4 Medium WP Duplicate Plugin local-sync Broken Access Control ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24652 Patchstack
6.5 Medium Blur Text Plugin blur-text Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 Fixed in 2.0.0 CVE-2025-24627 Patchstack
5.9 Medium Orbisius Simple Notice Plugin orbisius-simple-notice Cross-Site Scripting ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-24634 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only