WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,001–11,050 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 221 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.3 Medium MagicForm - WordPress Form Builder Plugin magicform Broken Access Control WordPress Form Builder <= 1.6.2 - Missing Authorization ≤ 1.6.2 CVE-2025-0939 Wordfence
5.3 Medium Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings Plugin directorist Information Disclosure AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure No login needed ≤ 8.0.12 CVE-2024-12041 Wordfence
8.8 High ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 3.2.6 CVE-2024-12171 Wordfence
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
5.3 Medium WordPress Contact Forms by Cimatti Plugin Broken Access Control Missing Authorization to Unauthenticated Form Submission Download No login needed ≤ 1.9.4 CVE-2024-12184 Wordfence
7.1 High EZPZ SAML SP Single Sign On (SSO) Plugin ezpz-sp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-24749 Patchstack
7.1 High WP Sessions Time Monitoring Full Automatic Plugin activitytime Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-24718 Patchstack
7.1 High Gwolle Guestbook Plugin gwolle-gb Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24710 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.3.3 Fixed in 6.0.3.4 CVE-2025-24686 Patchstack
7.1 High Paytm Payment Donation Plugin paytm-donation Cross-Site Scripting Donation Plugin plugin <= 2.3.1 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-24635 Patchstack
7.1 High Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Scripting WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.9.0 -Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.0 Fixed in 4.9.1 CVE-2025-24632 Patchstack
7.1 High PORTONE 우커머스 결제 Plugin iamport-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.4 Fixed in 3.2.6 CVE-2025-24609 Patchstack
7.1 High GD Mail Queue Plugin gd-mail-queue Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3 Fixed in 4.4 CVE-2025-24608 Patchstack
6.5 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Information Disclosure Sensitive Data Exposure ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-24597 Patchstack
7.1 High Cleanup – Directory Listing & Classifieds Plugin cleanup-light Cross-Site Scripting Directory Listing & Classifieds plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24563 Patchstack
7.1 High Awesome Event Booking Plugin awesome-event-booking Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-24560 Patchstack
7.1 High Radio Buttons and Swatches for WooCommerce Plugin variations-radio-buttons-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-24551 Patchstack
7.1 High Post Meta Plugin post-meta Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-24549 Patchstack
7.1 High SKT Donation Plugin skt-donation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 Fixed in 2.0 CVE-2025-24535 Patchstack
7.1 High DPortfolio Plugin dportfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-24534 Patchstack
7.1 High Affiliate Tools Việt Nam Plugin affiliate-tools-viet-nam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.17 CVE-2025-23759 Patchstack
7.1 High WP OpenSearch Plugin wp-opensearch Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23671 Patchstack
7.1 High Notifikácie.sk Plugin notifikacie-sk Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23596 Patchstack
7.1 High Scroll Styler Plugin scroll-styler Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23990 Patchstack
7.1 High Internal Link Builder Plugin internal-link-builder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23989 Patchstack
6.5 Medium Designer Plugin designer Cross-Site Scripting ≤ 1.6.4 CVE-2025-23987 Patchstack
5.4 Medium Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23985 Patchstack
7.1 High Full Circle Plugin full-circle Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.5.7.8 CVE-2025-23980 Patchstack
7.1 High FlashCounter Plugin flashcounter Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.8 CVE-2025-23978 Patchstack
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
7.1 High Issuu Panel Plugin issuu-panel Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-23976 Patchstack
6.5 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Scripting ≤ 1.1.2 CVE-2025-22757 Patchstack
5.8 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-22720 Patchstack
7.1 High Pretty Url Plugin pretty-url Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-22564 Patchstack
7.1 High Hide Login+ Plugin hide-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.1 CVE-2025-22341 Patchstack
7.1 High CloudFlare(R) Cache Purge Plugin cloudflare-cache-purge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-22332 Patchstack
6.5 Medium EMI Calculator Plugin emi-calculator Broken Access Control Settings Change No login needed ≤ 1.1 CVE-2025-22265 Patchstack
5.4 Medium Oshine Modules Plugin oshine-modules Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44055 Patchstack
4.3 Medium HT Event – WordPress Event Manager Plugin for Elementor Plugin Information Disclosure WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor ≤ 1.4.7 CVE-2024-13216 Wordfence
6.4 Medium WPRadio – WordPress Radio Streaming Plugin wpradio Cross-Site Scripting WordPress Radio Streaming Plugin <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-13397 Wordfence
6.5 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll SQL Injection Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) SQL Injection ≤ 1.7.5 CVE-2024-13596 Wordfence
9.8 Critical iControlWP – Multiple WordPress Site Manager Plugin worpit-admin-dashboard-plugin PHP Object Injection Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.5 CVE-2024-13742 Wordfence
7.3 High Contact Form & SMTP Plugin for WordPress by PirateForms Plugin pirate-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.6.0 CVE-2024-13453 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter ≤ 1.9.9 CVE-2024-13732 Wordfence
4.8 Medium Social Share Buttons Plugin share-button Cross-Site Scripting Admin+ Stored XSS ≤ 2.7 CVE-2024-12807 WPScan
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
5.3 Medium Houzez Plugin houzez Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.2 CVE-2025-24747 Patchstack
4.3 Medium Bridge Core Plugin bridge-core Broken Access Control ≤ 3.3 Fixed in 3.3.1 CVE-2025-24744 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-24743 Patchstack
7.1 High Fare Calculator Plugin fare-calculator Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-23982 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only