WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,001–11,050 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 221 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets ≤ 3.11.11 CVE-2024-12477 Wordfence
5.9 Medium Toocheke Companion Plugin toocheke-companion Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.166 Fixed in 1.167 CVE-2025-23992 Patchstack
6.5 Medium Database Sync Plugin database-sync Information Disclosure Sensitive Data Exposure ≤ 0.5.1 CVE-2025-23486 Patchstack
4.3 Medium Debug Tool Plugin debug-tool Broken Access Control ≤ 2.2 CVE-2025-23684 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Retrieval ≤ 2.1.6 CVE-2024-13447 Wordfence
6.1 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.6.5 CVE-2024-13319 Wordfence
5.4 Medium AI Power: Complete AI Pack Plugin Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.8.96 CVE-2024-13360 Wordfence
6.3 Medium AI Power: Complete AI Pack Plugin gpt3-ai-content-generator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.8.96 CVE-2024-13361 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
6.1 Medium XML for Google Merchant Center Plugin xml-for-google-merchant-center Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.0.11 CVE-2024-13406 Wordfence
4.3 Medium WPBot Pro Wordpress Chatbot Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation ≤ 13.5.5 CVE-2024-12879 Wordfence
6.4 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.2 CVE-2024-13590 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.19 CVE-2024-13584 Wordfence
5.4 Medium WP-Polls Plugin wp-polls SQL Injection Unauthenticated SQL Injection to Stored Cross-Site Scripting No login needed ≤ 2.77.2 CVE-2024-13426 Wordfence
4.3 Medium AnyRoad Plugin anyguide Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-23996 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control Broken Access Control to Notice Dimissal ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-22722 Patchstack
4.3 Medium ApplyOnline Plugin apply-online Broken Access Control ≤ 2.6.7.1 Fixed in 2.6.7.2 CVE-2025-22721 Patchstack
6.5 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting ≤ 3.20.0 Fixed in 3.30.0 CVE-2025-22661 Patchstack
5.9 Medium Related Post Shortcode Plugin related-post-shortcode Cross-Site Scripting ≤ 1.2 CVE-2025-22276 Patchstack
6.5 Medium Weaver Themes Shortcode Compatibility Plugin weaver-themes-shortcode-compatibility Cross-Site Scripting ≤ 1.0.4 CVE-2025-22267 Patchstack
6.5 Medium Tamara Checkout Plugin tamara-checkout Cross-Site Scripting ≤ 1.9.9.1 Fixed in 1.9.9.1 CVE-2025-23997 Patchstack
6.5 Medium Flexible PDF Coupons Plugin flexible-coupons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.3 Fixed in 1.10.3 CVE-2025-22825 Patchstack
6.5 Medium Ad Blocking Detector Plugin ad-blocking-detector Cross-Site Scripting ≤ 3.6.0 CVE-2025-22732 Patchstack
6.5 Medium MailChimp Subscribe Forms Plugin mailchimp-subscribe-sm Cross-Site Scripting ≤ 4.1 Fixed in 4.2 CVE-2025-22727 Patchstack
6.5 Medium FAT Event Lite Plugin fat-event-lite Cross-Site Scripting ≤ 1.1 CVE-2025-22718 Patchstack
5.9 Medium Bonjour Bar Plugin bonjour-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-22262 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Content Injection HTML Injection No login needed ≤ 5.5.5 Fixed in 5.5.5 CVE-2024-56277 Patchstack
6.1 Medium wp-greet Plugin wp-greet Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.2 CVE-2024-13444 Wordfence
5.3 Medium Social Share, Social Login and Social Comments Plugin – Super Socializer Plugin super-socializer SQL Injection Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' No login needed ≤ 7.14 CVE-2024-13230 Wordfence
6.4 Medium FireCask Like & Share Button Plugin facebook-like-send-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 1.2 CVE-2024-11226 Wordfence
6.4 Medium Betheme Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 27.6.1 CVE-2025-0450 Wordfence
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.7.2 CVE-2024-13404 Wordfence
5.3 Medium Visual Website Collaboration, Feedback & Project Management – Atarim Plugin Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed ≤ 4.0.9 CVE-2024-12104 Wordfence
6.1 Medium WP-BibTeX Plugin wp-bibtex Cross-Site Request Forgery Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting No login needed ≤ 3.0.1 CVE-2024-12005 Wordfence
6.4 Medium Jet Elements Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.7.2.1 CVE-2025-0371 Wordfence
5.3 Medium 1003 Mortgage Application Plugin 1003-mortgage-application Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.87 CVE-2024-13536 Wordfence
5.5 Medium WP All Import Pro Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.9.7 CVE-2024-8722 Wordfence
6.4 Medium Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Plugin rate-star-review Cross-Site Scripting AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.3 CVE-2024-13392 Wordfence
6.4 Medium Utilities for MTG Plugin utilities-for-mtg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-13433 Wordfence
6.4 Medium Jet Engine Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter ≤ 3.6.2 CVE-2025-0369 Wordfence
6.4 Medium Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.31 CVE-2024-13393 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode ≤ 1.5.22 CVE-2024-12696 Wordfence
4.4 Medium Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) Plugin Cross-Site Scripting Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title ≤ 3.3.2 CVE-2024-13517 Wordfence
6.4 Medium JSM Screenshot Machine Shortcode Plugin screenshot-machine-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 CVE-2024-13385 Wordfence
4.4 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.9.80 CVE-2024-13519 Wordfence
6.1 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.7.2 CVE-2024-12385 Wordfence
4.3 Medium Buzz Club – Night Club, DJ and Music Festival Event Theme Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 2.0.4 CVE-2025-0515 Wordfence
4.3 Medium ShipWorks Connector for Woocommerce Plugin shipworks-e-commerce-bridge Cross-Site Request Forgery Cross-Site Request Forgery to Service Password/Username Update No login needed ≤ 5.2.5 CVE-2024-13317 Wordfence
6.1 Medium Webcamconsult Plugin webcamconsult Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.0 CVE-2024-13432 Wordfence
6.4 Medium MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet Plugin Cross-Site Scripting Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.29 CVE-2024-13391 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only