WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,251–11,300 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 226 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Flexible Blogtitle Plugin flexible-blogtitle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23846 Patchstack
7.1 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23812 Patchstack
7.1 High InFunding Plugin infunding Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23768 Patchstack
7.1 High CMC MIGRATE Plugin cmc-migrate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.3 CVE-2025-23746 Patchstack
7.1 High Formatted post Plugin formatted-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.01 CVE-2025-23709 Patchstack
7.1 High ReadMe Creator Plugin readme-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23643 Patchstack
7.1 High WP IMAP Auth Plugin wp-imap-authentication Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.1 CVE-2025-23506 Patchstack
6.5 Medium Database Sync Plugin database-sync Information Disclosure Sensitive Data Exposure ≤ 0.5.1 CVE-2025-23486 Patchstack
7.1 High History timeline Plugin history-timeline Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7.2 CVE-2025-23475 Patchstack
7.1 High FWD Slider Plugin fwd-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23462 Patchstack
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.1 High Mapbox for WP Advanced Plugin mapbox-for-wp-advanced Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-22772 Patchstack
7.1 High a Gateway for Pasargad Bank on WooCommerce Plugin a-gateway-for-pasargad-bank-on-woocommerce Cross-Site Scripting No login needed ≤ 2.5.2 CVE-2025-23966 Patchstack
7.1 High Good Old Gallery Plugin good-old-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-23959 Patchstack
10.0 Critical user files Plugin user-files Arbitrary File Upload No login needed ≤ 2.4.2 CVE-2025-23953 Patchstack
8.1 High Improved Sale Badges – Free Version Plugin improved-sale-badges-free-version Local File Inclusion Free Version Plugin <= 1.0.1 - Local File Inclusion No login needed ≤ 1.0.1 CVE-2025-23949 Patchstack
8.1 High Background animation blocks Plugin background-animation-blocks Local File Inclusion No login needed ≤ 2.1.5 CVE-2025-23948 Patchstack
8.8 High WOOEXIM Plugin wooexim PHP Object Injection ≤ 5.0.0 CVE-2025-23944 Patchstack
9.1 Critical WP Load Gallery Plugin wp-load-gallery Arbitrary File Upload ≤ 2.1.6 CVE-2025-23942 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
9.8 Critical Quick Count Plugin quick-count PHP Object Injection No login needed ≤ 3.00 CVE-2025-23932 Patchstack
9.3 Critical WordPress Local SEO Plugin dh-local-seo SQL Injection No login needed ≤ 2.3 CVE-2025-23931 Patchstack
9.0 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Arbitrary File Upload No login needed ≤ 1.1.3 Fixed in 1.1.5 CVE-2025-23921 Patchstack
9.9 Critical Smallerik File Browser Plugin smallerik-file-browser Arbitrary File Upload ≤ 1.1 CVE-2025-23918 Patchstack
8.5 High Menus Plus+ Plugin menus-plus SQL Injection ≤ 1.9.6 CVE-2025-23910 Patchstack
7.1 High WP Block Pack Plugin wp-block-pack Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23874 Patchstack
7.1 High WordPress File Search Plugin wpfilesearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23867 Patchstack
7.1 High EU DSGVO Helper Plugin dsgvo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6.1 CVE-2025-23866 Patchstack
7.1 High WP2APP Plugin wp2appir Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 CVE-2025-23811 Patchstack
7.1 High Ultimate Subscribe Plugin ultimate-subscribe Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23806 Patchstack
7.1 High Snippy Plugin snippy Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23803 Patchstack
7.1 High Mass Messaging in BuddyPress Plugin mass-messaging-in-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.1 CVE-2025-23798 Patchstack
7.6 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution SQL Injection ≤ 1.2.1 CVE-2025-23784 Patchstack
7.5 High WM Options Import Export Plugin wm-options-import-export Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.1 CVE-2025-23781 Patchstack
7.5 High WPDB to Sql Plugin wpdb-to-sql Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2 CVE-2025-23774 Patchstack
7.1 High Fast Tube Plugin fast-tube Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.1 CVE-2025-23770 Patchstack
7.1 High Content Mirror Plugin content-mirror Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23769 Patchstack
7.1 High Pootle button Plugin pootle-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-23758 Patchstack
7.1 High Easy Filtering Plugin easy-filtering Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23732 Patchstack
7.1 High Jet Skinner for BuddyPress Plugin jet-skinner-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-23706 Patchstack
7.1 High Lime Developer Login Plugin lime-developer-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-23701 Patchstack
7.1 High yCyclista Plugin ycyclista Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-23700 Patchstack
7.1 High Podčlánková inzerce Plugin podclankova-inzerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.0 CVE-2025-23697 Patchstack
7.1 High Staging CDN Plugin staging-cdn Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23696 Patchstack
7.1 High CtyGrid Hyp3rL0cal Search Plugin hyp3rl0cal-city-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1.1 CVE-2025-23695 Patchstack
7.1 High Admin Menu Organizer Plugin admin-menu-organizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23686 Patchstack
4.3 Medium Debug Tool Plugin debug-tool Broken Access Control ≤ 2.2 CVE-2025-23684 Patchstack
7.1 High MACME Plugin macme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23683 Patchstack
7.1 High Preloader Quotes Plugin preloader-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23682 Patchstack
7.1 High REDIRECTION PLUS Plugin redirection-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23681 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only