WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,051–11,100 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 222 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Go Maps Plugin wp-google-maps Cross-Site Request Forgery No login needed ≤ 9.0.40 Fixed in 9.0.41 CVE-2025-24742 Patchstack
4.7 Medium KB Support Plugin kb-support Open Redirect No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-24741 Patchstack
4.7 Medium LearnPress Plugin learnpress Open Redirect No login needed ≤ 4.2.7.1 Fixed in 4.2.7.2 CVE-2025-24740 Patchstack
8.8 High Better Find and Replace Plugin real-time-auto-find-and-replace Privilege Escalation ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-24734 Patchstack
7.1 High WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-dynamics-crm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24708 Patchstack
5.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Information Disclosure Sensitive Data Exposure No login needed ≤ 1.27.12 Fixed in 1.27.13 CVE-2025-24689 Patchstack
7.1 High WP Multistore Locator Plugin wp-multi-store-locator Cross-Site Scripting No login needed ≤ 2.4.7 Fixed in 2.5.1 CVE-2025-24680 Patchstack
9.8 Critical Save as PDF Plugin save-as-pdf-by-pdfcrowd PHP Object Injection No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-24671 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection No login needed ≤ 5.2.17 Fixed in 5.2.18 CVE-2025-24667 Patchstack
9.3 Critical Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition SQL Injection No login needed ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-24665 Patchstack
5.3 Medium LearnDash LMS Plugin sfwd-lms Broken Access Control No login needed ≤ 4.20.0.1 Fixed in 4.20.0.3 CVE-2025-24662 Patchstack
4.3 Medium Admin and Site Enhancements (ASE) Pro Plugin admin-site-enhancements-pro Broken Access Control ≤ 7.6.1.1 Fixed in 7.6.3 CVE-2025-24653 Patchstack
5.3 Medium Google Captcha Plugin google-captcha Authentication Bypass Captcha Bypass No login needed ≤ 1.78 Fixed in 1.79 CVE-2025-24628 Patchstack
7.1 High Music Store Plugin music-store Cross-Site Scripting WordPress eCommerce Plugin <= 1.1.19 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.2.0 CVE-2025-24626 Patchstack
6.4 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Easy Estimates and Invoices for WordPress plugin <=20.8.1 - Broken Access Control ≤ 20.8.1 Fixed in 20.8.2 CVE-2025-24606 Patchstack
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
5.3 Medium RSVPMarker Plugin rsvpmaker Broken Access Control No login needed ≤ 11.4.5 Fixed in 11.4.6 CVE-2025-24600 Patchstack
7.1 High Edwiser Bridge Plugin edwiser-bridge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.8 Fixed in 3.1.0 CVE-2025-24593 Patchstack
5.3 Medium picu Plugin picu Broken Access Control Online Photo Proofing Gallery plugin <= 2.4.0 - Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24590 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.7.0 Fixed in 6.7.1 CVE-2025-24537 Patchstack
5.4 Medium PAPERCITE Plugin papercite Broken Access Control ≤ 0.5.18 CVE-2025-23849 Patchstack
7.1 High LawPress – Law Firm Website Management Plugin lawpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2025-23756 Patchstack
7.1 High The Loops Plugin the-loops Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23754 Patchstack
7.1 High CGD Arrange Terms Plugin shopp-arrange Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-23752 Patchstack
6.5 Medium WP Smart Tooltip Plugin wp-smart-tool-tip Cross-Site Scripting ≤ 1.0.0 CVE-2025-23669 Patchstack
6.5 Medium Donate visa Plugin donate-visa Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-23656 Patchstack
7.1 High CubePM Plugin cubepm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23574 Patchstack
7.1 High RSVPMaker Volunteer Roles Plugin rsvpmaker-volunteer-roles Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23531 Patchstack
6.5 Medium Minterpress Plugin minterpress Broken Access Control Arbitrary Content Deletion ≤ 1.0.5 CVE-2025-23529 Patchstack
7.1 High Simple Locator Plugin simple-locator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-22513 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 3.4.0 Fixed in 3.4.2 CVE-2025-24754 Patchstack
8.1 High Morkva UA Shipping Plugin morkva-ua-shipping Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.20 CVE-2025-24685 Patchstack
9.3 Critical LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition SQL Injection No login needed ≤ 5.0.20 Fixed in 5.0.21 CVE-2025-24664 Patchstack
9.3 Critical Shipping for Nova Poshta Plugin nova-poshta-ttn SQL Injection No login needed ≤ 1.19.6 Fixed in 1.19.7 CVE-2025-24612 Patchstack
9.8 Critical FundPress Plugin fundpress PHP Object Injection No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24601 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-24584 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
7.1 High Passwordless WP – Login with your glance or fingerprint Plugin passwordless-wp Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23792 Patchstack
7.1 High Shipdeo Plugin shipdeo-woo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-23457 Patchstack
6.5 Medium Social Share Buttons Plugin share-button Path Traversal Unauthenticated Image Upload & Path Traversal No login needed ≤ 2.7 CVE-2024-13117 WPScan
7.5 High Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.14.5 CVE-2024-13562 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin learnpress Cross-Site Scripting WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name ≤ 4.2.7.5 CVE-2024-13599 Wordfence
6.4 Medium WordPress SEO Friendly Accordion FAQ with AI assisted content generation Plugin notice-faq Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-13458 Wordfence
7.6 High Email Subscription Popup Plugin email-subscribe SQL Injection ≤ 1.2.23 Fixed in 1.2.24 CVE-2025-24587 Patchstack
6.5 Medium Popup Maker Plugin popup-maker Cross-Site Scripting ≤ 1.20.2 Fixed in 1.20.3 CVE-2025-24746 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only