WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,051–11,100 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 222 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium List category posts Plugin list-category-posts Cross-Site Scripting Author+ Stored XSS < 0.90.3 Fixed in 0.90.3 CVE-2024-9020 WPScan
6.1 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.5 CVE-2024-13516 Wordfence
5.3 Medium Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member Information Disclosure User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure No login needed ≤ 2.9.1 CVE-2025-0318 Wordfence
6.1 Medium Image Source Control Lite – Show Image Credits and Captions Plugin image-source-control-isc Cross-Site Scripting Show Image Credits and Captions <= 2.28.0 - Reflected Cross-Site Scripting No login needed ≤ 2.28.0 CVE-2024-13515 Wordfence
4.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name ≤ 4.1.25 CVE-2025-0554 Wordfence
5.3 Medium Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Plugin evergreen-content-poster Broken Access Control Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 1.4.4 CVE-2024-12071 Wordfence
5.4 Medium GravityForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter No login needed 2.9.0.1 – 2.9.1.3 CVE-2024-13378 Wordfence
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Missing Authorization No login needed ≤ 2.1.5 CVE-2024-12370 Wordfence
6.1 Medium Proofreading Plugin proofreading Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.1.1 CVE-2024-12466 Wordfence
4.4 Medium RSS Icon Widget Plugin rss-icon-widget Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.2 CVE-2024-12203 Wordfence
5.3 Medium Moving Users Plugin moving-users Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.05 CVE-2024-12637 Wordfence
6.4 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via book Parameter ≤ 1.0.8 CVE-2024-12598 Wordfence
6.4 Medium quote-posttype-plugin Plugin quote-post-type-plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-13386 Wordfence
6.5 Medium Sandbox Plugin sandbox Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sandbox Download ≤ 0.4 CVE-2024-13367 Wordfence
6.1 Medium Sandbox Plugin sandbox Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.4 CVE-2024-13366 Wordfence
6.4 Medium Glofox Shortcodes Plugin glofox-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6 CVE-2024-12508 Wordfence
6.5 Medium Eventer Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 3.9.7 CVE-2024-10799 Wordfence
6.4 Medium Checkout for PayPal Plugin checkout-for-paypal Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.32 CVE-2024-13398 Wordfence
6.1 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.2 CVE-2024-13434 Wordfence
6.4 Medium Payment Button for PayPal Plugin wp-paypal Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3.35 CVE-2024-13401 Wordfence
6.5 Medium SOCIAL.NINJA Plugin seo-meta Cross-Site Scripting ≤ 0.2 CVE-2025-23907 Patchstack
6.5 Medium Metaphor Widgets Plugin mtphr-widgets Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.4 CVE-2025-23816 Patchstack
5.3 Medium Copy Move Posts Plugin copy-move-posts Broken Access Control No login needed ≤ 1.6 CVE-2025-23764 Patchstack
5.4 Medium Woo Tuner Plugin woo-tuner Broken Access Control ≤ 0.1.2 CVE-2025-23761 Patchstack
4.3 Medium Sur.ly Plugin surly Broken Access Control ≤ 3.0.3 CVE-2025-23957 Patchstack
6.5 Medium Kopa Nictitate Toolkit Plugin kopa-nictitate-toolkit Cross-Site Scripting ≤ 1.0.2 CVE-2025-23965 Patchstack
5.4 Medium WordPress Graphs & Charts Plugin graph-lite Broken Access Control ≤ 2.0.8 CVE-2025-23961 Patchstack
4.3 Medium Xola Plugin xola-bookings-for-tours-activities Broken Access Control ≤ 1.6 CVE-2025-23955 Patchstack
5.4 Medium Mark Posts Plugin mark-posts Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-23963 Patchstack
4.3 Medium Goldstar Plugin goldstar Broken Access Control ≤ 2.1.1 CVE-2025-23962 Patchstack
4.3 Medium Salvador – AI Image Generator Plugin salvador-ai-image-generator Broken Access Control AI Image Generator plugin <= 1.0.11 - Broken Access Control ≤ 1.0.11 CVE-2025-23954 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 1.1 CVE-2025-23939 Patchstack
6.5 Medium EZPlayer Plugin ezplayer Cross-Site Scripting ≤ 1.0.10 CVE-2025-23950 Patchstack
6.5 Medium Enhanced YouTube Shortcode Plugin enhanced-youtube-shortcode Cross-Site Scripting ≤ 2.0.1 CVE-2025-23946 Patchstack
6.5 Medium PDF.js Shortcode Plugin pdfjs-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23943 Patchstack
6.5 Medium MeinTurnierplan.de Widget Viewer Plugin meinturnierplande-widget-viewer Cross-Site Scripting ≤ 1.1 CVE-2025-23941 Patchstack
6.5 Medium Gallery: Hybrid – Advanced Visual Gallery Plugin hybrid-gallery Cross-Site Scripting Advanced Visual Gallery plugin <= 1.4.0.2 - Cross Site Scripting (XSS) ≤ 1.4.0.2 CVE-2025-23951 Patchstack
6.5 Medium WP-Player Plugin wp-player Cross-Site Scripting ≤ 2.6.1 CVE-2025-23947 Patchstack
6.5 Medium Giveaways and Contests by PromoSimple Plugin giveaways-contests-by-promosimple Cross-Site Scripting ≤ 1.24 CVE-2025-23934 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 0.1.1 CVE-2025-23940 Patchstack
6.5 Medium Google Org Chart Plugin google-org-chart Cross-Site Scripting ≤ 1.0.1 CVE-2025-23928 Patchstack
6.5 Medium WP Photo Sphere Plugin wp-photo-sphere Cross-Site Scripting ≤ 3.8 CVE-2025-23924 Patchstack
6.5 Medium Magic Google Maps Plugin magic-google-maps Cross-Site Scripting ≤ 1.0.4 CVE-2025-23935 Patchstack
6.5 Medium WpF Ultimate Carousel Plugin wpf-ultimate-carousel Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2025-23933 Patchstack
4.3 Medium PayPal Marketing Solutions Plugin paypal-promotions-and-insights Broken Access Control ≤ 1.2 CVE-2025-23930 Patchstack
5.4 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control ≤ 3.3.8 CVE-2025-23917 Patchstack
6.5 Medium CC Circle Progress Bar Plugin cc-circle-progress-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-23936 Patchstack
6.5 Medium Feedburner Optin Form Plugin feedburner-optin-form Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2.8 CVE-2025-23925 Patchstack
6.5 Medium Incredible Font Awesome Plugin incredible-font-awesome Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23927 Patchstack
4.3 Medium Email Capture & Lead Generation Plugin email-capture-lead-generation Broken Access Control ≤ 1.0.2 CVE-2025-23929 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only