WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 10,951–11,000 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 220 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Powerful Auto Chat Plugin powers-triggers-of-woo-to-chat Cross-Site Scripting ≤ 1.9.8 CVE-2025-22292 Patchstack
4.3 Medium Meta Tag Manager Plugin meta-tag-manager Broken Access Control ≤ 3.1 Fixed in 3.2 CVE-2025-22260 Patchstack
4.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.17.4 Fixed in 2.17.5 CVE-2024-50500 Patchstack
7.5 High Admin and Site Enhancements (ASE) Pro Plugin admin-site-enhancements-pro Privilege Escalation ≤ 7.6.2.1 Fixed in 7.6.3 CVE-2024-43333 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.24 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.24 Fixed in 2.7.7.25 CVE-2025-24707 Patchstack
6.5 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.2 CVE-2025-24697 Patchstack
7.1 High Media Downloader Plugin media-downloader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.7.5 Fixed in 0.4.7.6 CVE-2025-24684 Patchstack
7.1 High Custom WP Store Locator Plugin custom-store-locator Cross-Site Scripting No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-24676 Patchstack
7.1 High Simple Membership Custom Messages Plugin simple-membership-custom-messages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-24660 Patchstack
7.1 High Realtyna Provisioning Plugin realtyna-provisioning Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-24656 Patchstack
7.1 High XML for Avito Plugin xml-for-avito Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24646 Patchstack
6.5 Medium WPGuppy Plugin wpguppy-lite Authentication Bypass Broken Authentication No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-24643 Patchstack
6.5 Medium Setup Default Featured Image Plugin setup-default-feature-image Broken Access Control No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-24642 Patchstack
6.5 Medium Korea for WooCommerce Plugin korea-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-24639 Patchstack
7.1 High BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-24631 Patchstack
7.1 High Sikshya LMS Plugin sikshya Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.21 Fixed in 0.0.22 CVE-2025-24630 Patchstack
7.1 High Import Excel to Gravity Forms Plugin gf-excel-import Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.18 Fixed in 1.18.1 CVE-2025-24629 Patchstack
7.1 High AIO Shortcodes Plugin aio-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-24620 Patchstack
7.5 High WOLF Plugin bulk-editor Path Traversal ≤ 1.0.8.5 Fixed in 1.0.8.6 CVE-2025-24605 Patchstack
7.1 High Landing Page Cat Plugin landing-page-cat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-24576 Patchstack
7.1 High PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-24574 Patchstack
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Arbitrary File Read No login needed ≤ 1.7.5 Fixed in 2.0.1 CVE-2025-24569 Patchstack
7.1 High WP Mailster Plugin wp-mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.15.0 Fixed in 1.8.16.0 CVE-2025-24559 Patchstack
7.1 High PlainInventory Plugin z-inventory-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-24557 Patchstack
7.5 High MooWoodle Plugin moowoodle Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-24556 Patchstack
7.1 High BSK Forms Validation Plugin bsk-gravity-forms-custom-validation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 Fixed in 1.8 CVE-2025-24545 Patchstack
7.1 High Bitcoin and Altcoin Wallets Plugin wallets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3.1 Fixed in 6.3.2 CVE-2025-24544 Patchstack
7.1 High DK White Label Plugin dk-white-label Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-24541 Patchstack
7.1 High ThriveDesk Plugin thrivedesk Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24536 Patchstack
7.1 High Lockets Plugin lockets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.999 CVE-2025-23923 Patchstack
7.1 High ApplicantPro Plugin applicantpro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-23920 Patchstack
7.5 High WP Cloud Plugin cloud Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-23819 Patchstack
7.1 High .TUBE Video Curator Plugin tube-video-curator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.9 CVE-2025-23799 Patchstack
7.1 High PAFacile Plugin pafacile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2025-23755 Patchstack
6.5 Medium Awesome Timeline Plugin awesome-timeline Cross-Site Scripting ≤ 1.0.1 CVE-2025-23747 Patchstack
7.1 High RomanCart Plugin romancart-on-wordpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.2 CVE-2025-23685 Patchstack
7.1 High WordPress Additional Logins Plugin wp-additional-logins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23614 Patchstack
7.1 High eMarksheet Plugin emarksheet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-23599 Patchstack
7.1 High Google Map With Fancybox Plugin location-piker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-23594 Patchstack
7.1 High EmailPress Plugin emailpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23593 Patchstack
7.1 High blu Logistics Plugin blu-logistics Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23591 Patchstack
7.1 High Dezdy Plugin dezdy-mcommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23590 Patchstack
7.1 High WOW Best CSS Compiler Plugin best-css-compiler Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2025-23588 Patchstack
7.1 High Bulk Categories Assign Plugin bulk-categories-assign Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23582 Patchstack
6.5 Medium Demo User DZS Plugin demo-user-dzs-showcase-your-admin-safely Cross-Site Scripting ≤ 1.1.0 CVE-2025-23581 Patchstack
6.5 Medium MLL Audio Player MP3 Ajax Plugin music-let-loose-mp3-audio-player Cross-Site Scripting ≤ 0.7 CVE-2025-23561 Patchstack
6.5 Medium WC Wallet Plugin wc-wallet Broken Access Control Arbitrary Content Deletion ≤ 2.2.0 CVE-2025-23527 Patchstack
7.1 High WPJobBoard Plugin wpjobboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.10.1 Fixed in 5.11.1 CVE-2025-24781 Patchstack
7.1 High VSTEMPLATE Creator Plugin vstemplate-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2025-23491 Patchstack
6.4 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.6.9 CVE-2024-13612 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only