WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,101–11,150 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 223 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ajax WP Query Search Filter Plugin ajax-wp-query-search-filter Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.7 CVE-2025-23926 Patchstack
5.4 Medium WP Meetup Plugin wp-meetup Broken Access Control Settings Change ≤ 2.3.0 CVE-2025-23916 Patchstack
5.4 Medium Slides & Presentations Plugin slide Content Injection ≤ 0.0.39 CVE-2025-23919 Patchstack
6.5 Medium Compare Ninja Plugin compare-ninja-comparison-tables Cross-Site Scripting ≤ 2.1.0 CVE-2025-23909 Patchstack
6.5 Medium Pastebin Plugin pastebin-embed Cross-Site Scripting ≤ 1.5 CVE-2025-23908 Patchstack
6.5 Medium Bookalet Plugin bookalet Cross-Site Scripting ≤ 1.0.3 CVE-2025-23899 Patchstack
6.5 Medium Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Scripting ≤ 2.3 CVE-2025-23897 Patchstack
6.5 Medium Blog Summary Plugin blog-summary Cross-Site Scripting ≤ 0.1.2 β CVE-2025-23887 Patchstack
6.5 Medium Yet Another Countdown Plugin yacp Cross-Site Scripting ≤ 1.0.1 CVE-2025-23891 Patchstack
6.5 Medium Progress Tracker Plugin progress-tracker Cross-Site Scripting ≤ 0.9.3 CVE-2025-23892 Patchstack
6.5 Medium Mindmeister Shortcode Plugin mindmeister-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23896 Patchstack
6.5 Medium Easy Tweet Embed Plugin easy-tweet-embed Cross-Site Scripting ≤ 1.7 CVE-2025-23890 Patchstack
6.5 Medium WP krpano Plugin wp-krpano Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 CVE-2025-23876 Patchstack
6.5 Medium GMap Shortcode Plugin gmap-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23893 Patchstack
6.5 Medium Annie Plugin annie Cross-Site Scripting ≤ 2.1.1 CVE-2025-23886 Patchstack
5.9 Medium Post-to-Post Links Plugin easy-post-to-post-links Cross-Site Scripting ≤ 4.2 CVE-2025-23878 Patchstack
6.5 Medium Category D3 Tree Plugin category-d3-tree Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23873 Patchstack
6.5 Medium Nite Shortcodes Plugin nite-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23877 Patchstack
6.5 Medium WCS QR Code Generator Plugin wcs-qr-code-generator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23864 Patchstack
6.5 Medium Chess Tempo Viewer Plugin chesstempoviewer Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.9.5 CVE-2025-23868 Patchstack
6.5 Medium Winning Portfolio Plugin winning-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23865 Patchstack
6.5 Medium Rollover Tab Plugin rollover-tab Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-23863 Patchstack
5.9 Medium Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com Plugin shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com Cross-Site Scripting ≤ 3.3 CVE-2025-23854 Patchstack
6.5 Medium Daily Proverb Plugin daily-proverb Cross-Site Scripting ≤ 2.0.3 CVE-2025-23859 Patchstack
5.3 Medium Contact Form 7 Anti Spambot Plugin contact-form-7-anti-spambot Broken Access Control No login needed ≤ 1.0.1 CVE-2025-23862 Patchstack
6.5 Medium Charity-thermometer Plugin charitydonation-thermometer Cross-Site Scripting ≤ 1.1.2 CVE-2025-23860 Patchstack
6.5 Medium Simple Vertical Timeline Plugin simple-vertical-timeline Cross-Site Scripting ≤ 0.1 CVE-2025-23856 Patchstack
6.5 Medium Top Flash Embed Plugin top-flash-embed Cross-Site Scripting ≤ 0.3.4 CVE-2025-23841 Patchstack
6.5 Medium JB Horizontal Scroller News Ticker Plugin jb-horizontal-scroller-news-ticker Cross-Site Scripting ≤ 1.0 CVE-2025-23830 Patchstack
6.5 Medium QR Code Generator Plugin qrcode-wprhe Cross-Site Scripting ≤ 1.2.6 CVE-2025-23831 Patchstack
6.5 Medium Links/Problem Reporter Plugin report-broken-links Cross-Site Scripting ≤ 2.6.0 CVE-2025-23833 Patchstack
6.5 Medium FontAwesome.io ShortCodes Plugin fontawesomeio-shortcodes Cross-Site Scripting ≤ 1.0 CVE-2025-23824 Patchstack
6.5 Medium Easy Shortcode Buttons Plugin easy-shortcode-buttons Cross-Site Scripting ≤ 1.2 CVE-2025-23825 Patchstack
6.5 Medium Spiderpowa Embed PDF Plugin spiderpowa-embed-pdf Cross-Site Scripting ≤ 1.0 CVE-2025-23807 Patchstack
6.5 Medium Easy FAQs Plugin easy-faqs Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.1 CVE-2025-23795 Patchstack
6.5 Medium WP-Revive Adserver Plugin wp-revive-adserver Cross-Site Scripting ≤ 2.2.1 CVE-2025-23802 Patchstack
6.5 Medium Easy Portfolio Plugin easy-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-23796 Patchstack
6.5 Medium Horizontal Line Shortcode Plugin horizontal-line-shortcode Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23791 Patchstack
6.5 Medium wp_amaps Plugin wp-amaps Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-23794 Patchstack
4.3 Medium AI Responsive Gallery Album Plugin ai-responsive-gallery-album Broken Access Control ≤ 1.4 CVE-2025-23785 Patchstack
5.4 Medium User Sync ActiveCampaign Plugin registered-user-sync-activecampaign Broken Access Control ≤ 1.3.2 CVE-2025-23778 Patchstack
6.5 Medium GDPR Personal Data Reports Plugin gdpr-personal-data-reports Cross-Site Scripting ≤ 1.0.5 CVE-2025-23777 Patchstack
6.5 Medium imaGenius Plugin imagenius Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-23772 Patchstack
6.5 Medium GMAPS for WPBakery Page Builder Free Plugin gmaps-for-visual-composer-free Cross-Site Scripting ≤ 1.2 CVE-2025-23775 Patchstack
4.3 Medium Cache Sniper for Nginx Plugin snipe-nginx-cache Broken Access Control ≤ 1.0.4.2 CVE-2025-23776 Patchstack
4.3 Medium W3SPEEDSTER Plugin w3speedster-wp Cross-Site Request Forgery No login needed ≤ 7.33 CVE-2025-23765 Patchstack
6.5 Medium Greek Namedays Widget From Eortologio.Net Plugin greek-namedays-widget Cross-Site Scripting ≤ 20191113 CVE-2025-23783 Patchstack
6.5 Medium Marmoset Viewer Plugin marmoset-viewer Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.9.3 CVE-2025-23767 Patchstack
6.5 Medium QuoteMedia Tools Plugin quotemedia-tools Cross-Site Scripting ≤ 1.0 CVE-2025-23644 Patchstack
6.5 Medium Sidebar-Content from Shortcode Plugin sidebar-content-from-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23642 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only