WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,051–1,100 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium CLP – Custom Login Page by NiteoThemes Plugin clp-custom-login-page Cross-Site Request Forgery Custom Login Page by NiteoThemes plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.5.5 CVE-2025-31769 Patchstack
4.3 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Request Forgery No login needed ≤ 5.4.1 CVE-2025-31763 Patchstack
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
4.3 Medium Apimo Connector Plugin apimo Cross-Site Request Forgery No login needed ≤ 2.6.5.1 CVE-2025-31602 Patchstack
4.3 Medium DesignO Plugin designo Cross-Site Request Forgery No login needed ≤ 2.6.0 CVE-2025-31600 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
4.3 Medium Multi Days Events and Multi Events in One Day Calendar Plugin dragon-calendar-free-version Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31572 Patchstack
6.4 Medium WP Link Preview Plugin wp-link-preview Server-Side Request Forgery ≤ 1.4.1 CVE-2025-31527 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
4.3 Medium WP Supersized Plugin wp-supersized Cross-Site Request Forgery No login needed ≤ 3.1.6 CVE-2025-31438 Patchstack
5.4 Medium Browser Caching with .htaccess Plugin browser-caching-with-htaccess Cross-Site Request Forgery No login needed 1.2.1 CVE-2025-31439 Patchstack
5.4 Medium Simple Trackback Disabler Plugin simple-trackback-disabler Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-31448 Patchstack
5.4 Medium NertWorks All in One Social Share Tools Plugin nertworks-all-in-one-social-share-tools Cross-Site Request Forgery No login needed ≤ 1.26 CVE-2025-31447 Patchstack
4.3 Medium Ultimate Security Checker Plugin ultimate-security-checker Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Security Rescan No login needed ≤ 4.2 CVE-2025-31456 Patchstack
5.4 Medium LWS SMS Plugin lws-sms Cross-Site Request Forgery No login needed ≤ 2.4.1 CVE-2025-31457 Patchstack
4.3 Medium WP Database Optimizer Plugin wp-database-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.1.3 CVE-2025-31474 Patchstack
4.9 Medium WP Compress for MainWP Plugin wp-compress-mainwp Server-Side Request Forgery ≤ 6.30.03 Fixed in 6.30.06 CVE-2025-31076 Patchstack
4.3 Medium Usermaven Plugin usermaven Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-31079 Patchstack
6.1 Medium tagDiv Composer Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 5.3 CVE-2025-1705 Wordfence
5.4 Medium Easy Booked – Appointment Booking and Scheduling Management System Plugin easy-booked Cross-Site Request Forgery No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-22634 Patchstack
4.3 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22637 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
4.3 Medium Product Author for WooCommerce Plugin wc-product-author Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-30872 Patchstack
4.3 Medium 3DPrint Lite Plugin 3dprint-lite Cross-Site Request Forgery No login needed ≤ 2.1.3.5 Fixed in 2.1.3.6 CVE-2025-30865 Patchstack
4.3 Medium Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-30863 Patchstack
4.3 Medium reCAPTCHA for all Plugin recaptcha-for-all Cross-Site Request Forgery No login needed ≤ 2.22 Fixed in 2.23 CVE-2025-30862 Patchstack
4.3 Medium Custom Field For WP Job Manager Plugin custom-field-for-wp-job-manager Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-30856 Patchstack
4.3 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-30854 Patchstack
4.3 Medium Christmas Panda Plugin christmas-panda Cross-Site Request Forgery No login needed ≤ 1.0.4 Fixed in 1.1.0 CVE-2025-30842 Patchstack
4.3 Medium Verge3D Plugin verge3d Cross-Site Request Forgery No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-30833 Patchstack
4.3 Medium Anthologize Plugin anthologize Cross-Site Request Forgery No login needed ≤ 0.8.2 Fixed in 0.8.3 CVE-2025-30823 Patchstack
4.3 Medium Custom Login Logo Plugin ideal-wp-login-logo-changer Cross-Site Request Forgery No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30822 Patchstack
4.3 Medium publish post email notification Plugin publish-post-email-notification Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.2.3 Fixed in 1.0.2.4 CVE-2025-30816 Patchstack
4.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2025-30815 Patchstack
4.3 Medium ValidateCertify Plugin validar-certificados-de-cursos Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-30811 Patchstack
4.3 Medium Flexible Cookies Plugin flexible-cookies Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-30805 Patchstack
4.3 Medium wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-30804 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
4.3 Medium Football Pool Plugin football-pool Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2025-30764 Patchstack
6.4 Medium Zapier Plugin zapier Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user Function ≤ 1.5.1 CVE-2024-13411 Wordfence
5.8 Medium WP Compress Plugin wp-compress-image-optimizer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via init Function No login needed ≤ 6.30.15 CVE-2025-2109 Wordfence
4.3 Medium Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings <= 5.5.0 - Cross-Site Request Forgery to Settings Update No login needed ≤ 5.5.0 CVE-2024-13710 Wordfence
4.3 Medium teachPress Plugin teachpress Cross-Site Request Forgery Cross-Site Request Forgery to Import Delete No login needed ≤ 9.0.9 CVE-2025-1320 Wordfence
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only