WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,151–11,200 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 224 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Internal Links Manager Plugin seo-automated-link-building Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24679 Patchstack
6.5 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting ≤ 0.1.2 Fixed in 0.2.1 CVE-2025-24673 Patchstack
8.5 High SERPed.net Plugin serped-net SQL Injection ≤ 4.4 Fixed in 4.6 CVE-2025-24669 Patchstack
5.9 Medium Auction Nudge – Your eBay on Your Site Plugin auction-nudge Cross-Site Scripting Your eBay on Your Site plugin <= 7.2.0 - Cross Site Scripting (XSS) ≤ 7.2.0 Fixed in 7.2.1 CVE-2025-24658 Patchstack
8.5 High Form Builder CP Plugin cp-easy-form-builder SQL Injection ≤ 1.2.41 Fixed in 1.2.42 CVE-2025-24672 Patchstack
5.9 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Cross-Site Scripting ≤ 33.0.8 Fixed in 33.0.9 CVE-2025-24668 Patchstack
7.6 High WPDM – Premium Packages Plugin wpdm-premium-packages SQL Injection Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection ≤ 5.9.6 Fixed in 5.9.7 CVE-2025-24659 Patchstack
4.3 Medium Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Broken Access Control ≤ 7.6.2 Fixed in 7.6.3 CVE-2025-24649 Patchstack
7.6 High Simple Download Monitor Plugin simple-download-monitor SQL Injection ≤ 3.9.25 Fixed in 3.9.26 CVE-2025-24663 Patchstack
5.9 Medium Wishlist for WooCommerce Plugin wt-woocommerce-wishlist Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-24657 Patchstack
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
9.1 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.15.3 Fixed in 2.15.4 CVE-2025-24650 Patchstack
5.4 Medium WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Cross-Site Request Forgery No login needed ≤ 1.0.35 Fixed in 1.0.36 CVE-2025-24647 Patchstack
4.3 Medium Taxonomy/Term and Role based Discounts for WooCommerce Plugin taxonomy-discounts-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.1 Fixed in 5.2 CVE-2025-24625 Patchstack
4.3 Medium Really Simple SSL Plugin really-simple-ssl Cross-Site Request Forgery No login needed ≤ 9.1.4 Fixed in 9.2.0 CVE-2025-24623 Patchstack
6.5 Medium Create with Code Plugin create-with-code Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2025-24638 Patchstack
5.4 Medium WP Duplicate Plugin local-sync Broken Access Control ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24652 Patchstack
6.5 Medium Blur Text Plugin blur-text Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 Fixed in 2.0.0 CVE-2025-24627 Patchstack
5.9 Medium Orbisius Simple Notice Plugin orbisius-simple-notice Cross-Site Scripting ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-24634 Patchstack
4.3 Medium FV Thoughtful Comments Plugin thoughtful-comments Broken Access Control ≤ 0.3.5 Fixed in 0.3.6 CVE-2025-24613 Patchstack
5.4 Medium Job Board Manager Plugin job-board-manager Cross-Site Request Forgery No login needed ≤ 2.1.59 Fixed in 2.1.60 CVE-2025-24622 Patchstack
6.5 Medium Restrict Anonymous Access Plugin restrict-anonymous-access Cross-Site Scripting ≤ 1.2 Fixed in 1.2.1 CVE-2025-24610 Patchstack
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-24618 Patchstack
7.1 High MachForm Shortcode Plugin machform-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-24636 Patchstack
5.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24633 Patchstack
4.9 Medium WP Ultimate Exporter Plugin wp-ultimate-exporter Path Traversal Arbitrary File Read ≤ 2.9 Fixed in 2.9.1 CVE-2025-24611 Patchstack
5.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control No login needed ≤ 3.8.7 Fixed in 3.9.0 CVE-2025-24596 Patchstack
5.4 Medium VPSUForm Plugin v-form Broken Access Control ≤ 3.0.5 Fixed in 3.0.7 CVE-2025-24604 Patchstack
6.5 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Cross-Site Request Forgery CSRF to Broken Access Control No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-24594 Patchstack
7.1 High KBucket Plugin kbucket Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 4.1.6 Fixed in 4.2.2 CVE-2025-24562 Patchstack
6.5 Medium All Embed – Elementor Addons Plugin all-embed-addons-for-elementor Cross-Site Scripting Elementor Addons plugin <= 1.1.3 - Cross Site Scripting (XSS) ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-24595 Patchstack
6.5 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.78.258 Fixed in 1.79.262 CVE-2025-24572 Patchstack
6.5 Medium Patreon Plugin patreon-connect Broken Access Control No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-24588 Patchstack
4.3 Medium Ultimate Coming Soon & Maintenance Plugin ultimate-coming-soon Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-24543 Patchstack
6.5 Medium PageLayer Plugin pagelayer Cross-Site Scripting ≤ 1.9.4 Fixed in 1.9.5 CVE-2025-24573 Patchstack
5.3 Medium Paytium Plugin paytium Information Disclosure Full Path Disclosure (FPD) No login needed ≤ 4.4.11 Fixed in 4.4.12 CVE-2025-24552 Patchstack
6.5 Medium Caching Compatible Cookie Opt-In and JavaScript Plugin caching-compatible-cookie-optin-and-javascript Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.0.10 Fixed in 0.0.11 CVE-2025-24547 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting No login needed ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-24570 Patchstack
4.3 Medium JSM Show Post Metadata Plugin jsm-show-post-meta Broken Access Control ≤ 4.6.0 Fixed in 4.6.1 CVE-2025-24589 Patchstack
5.9 Medium Nested Pages Plugin wp-nested-pages Cross-Site Scripting ≤ 3.2.9 Fixed in 3.2.10 CVE-2025-24579 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 5.9.7 Fixed in 5.9.8 CVE-2025-24585 Patchstack
6.5 Medium Icegram Plugin icegram Cross-Site Scripting ≤ 3.1.31 Fixed in 3.1.32 CVE-2025-24542 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-24578 Patchstack
4.3 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-24591 Patchstack
5.4 Medium WP Fast Total Search Plugin fulltext-search Broken Access Control ≤ 1.78.258 Fixed in 1.79.262 CVE-2025-24571 Patchstack
5.4 Medium Ultimate Coming Soon & Maintenance Plugin ultimate-coming-soon Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-24546 Patchstack
5.3 Medium 12 Step Meeting List Plugin 12-step-meeting-list Information Disclosure Sensitive Data Exposure No login needed ≤ 3.16.5 Fixed in 3.16.6 CVE-2025-24582 Patchstack
7.1 High ReviewsTap Plugin reviewstap Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-24561 Patchstack
6.5 Medium 12 Step Meeting List Plugin 12-step-meeting-list Broken Access Control Arbitrary Content Deletion ≤ 3.16.5 Fixed in 3.16.6 CVE-2025-24580 Patchstack
6.5 Medium HelloAsso Plugin helloasso Cross-Site Scripting ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-24575 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only