WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,301–11,350 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 227 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High FP RSS Category Excluder Plugin fp-rss-category-excluder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23679 Patchstack
7.1 High LocalGrid Plugin localgrid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23678 Patchstack
7.1 High LH Email Plugin lh-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2025-23676 Patchstack
7.1 High Bit.ly linker Plugin bitly-linker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23674 Patchstack
7.1 High Instant Appointment Plugin instant-appointment Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23672 Patchstack
7.1 High Content Planner Plugin content-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23631 Patchstack
7.1 High Cyber Slider Plugin cyber-new-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23630 Patchstack
7.1 High Unique UX Plugin unique-ux Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.2 CVE-2025-23625 Patchstack
7.1 High WH Cache & Security Plugin wh-cache-and-security Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23611 Patchstack
7.1 High Ultimate Events Plugin ultimate-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23610 Patchstack
7.1 High Tagesteller Plugin tagesteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v.1.1 CVE-2025-23609 Patchstack
7.1 High CAMOO SMS Plugin camoo-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.1 CVE-2025-23607 Patchstack
7.1 High Calendi Plugin calendi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-23606 Patchstack
7.1 High Call To Action Popup Plugin call-to-action-popup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23605 Patchstack
7.1 High Rezdy Reloaded Plugin reloaded-rezdy Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23604 Patchstack
7.1 High Group category creator Plugin group-category-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0.3 CVE-2025-23603 Patchstack
7.1 High EELV Newsletter Plugin eelv-newsletter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.2 CVE-2025-23602 Patchstack
7.1 High Tab My Content Plugin tab-my-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23601 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
7.1 High dForms Plugin dforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23592 Patchstack
7.1 High ContentOptin Lite Plugin contentoptin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23589 Patchstack
7.1 High Explara Membership Plugin explara-membership Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23583 Patchstack
7.1 High Custom CSS Addons Plugin css-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23578 Patchstack
7.5 High XLSXviewer Plugin xlsx-viewer Arbitrary File Deletion No login needed ≤ 2.1.1 CVE-2025-23562 Patchstack
7.1 High Responsivity Plugin responsivity Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.6 CVE-2025-23548 Patchstack
7.1 High REAL WordPress Sidebar Plugin drag-and-drop-custom-sidebar Cross-Site Scripting No login needed ≤ 0.1 CVE-2025-23535 Patchstack
7.5 High Team 118GROUP Agent Plugin team-118group-agent Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.6.0 CVE-2025-23512 Patchstack
7.1 High HyperComments Plugin comments-with-hypercommentscom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.6 CVE-2025-23509 Patchstack
7.1 High Blrt WP Embed Plugin blrt-wp-embed Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.9 CVE-2025-23507 Patchstack
7.1 High Customizable Captcha and Contact Us Plugin customizable-captcha-and-contact-us-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23503 Patchstack
7.1 High Simple Custom post type custom field Plugin simple-content-construction-kit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23500 Patchstack
7.1 High Translation.Pro Plugin translation-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23498 Patchstack
7.1 High WooCommerce Order Search Plugin woocommerce-order-searching Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-23495 Patchstack
4.3 Medium WPBot Pro Wordpress Chatbot Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation ≤ 13.5.5 CVE-2024-12879 Wordfence
9.8 Critical WPBot Pro Wordpress Chatbot Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 13.5.4 CVE-2024-13091 Wordfence
4.3 Medium AnyRoad Plugin anyguide Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-23996 Patchstack
7.1 High Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings plugin <= 5.5.0 - CSRF to Settings Update & Stored XSS No login needed ≤ 5.5.0 CVE-2025-23994 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control Broken Access Control to Notice Dimissal ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-22722 Patchstack
4.3 Medium ApplyOnline Plugin apply-online Broken Access Control ≤ 2.6.7.1 Fixed in 2.6.7.2 CVE-2025-22721 Patchstack
6.5 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting ≤ 3.20.0 Fixed in 3.30.0 CVE-2025-22661 Patchstack
7.1 High BizLibrary Plugin bizlibrary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23580 Patchstack
7.1 High SexBundle Plugin sexbundle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23551 Patchstack
7.1 High WP-Announcements Plugin wp-announcements Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-23489 Patchstack
8.2 High Realty Workstation Plugin realty-workstation Broken Access Control No login needed ≤ 1.0.45 CVE-2025-23477 Patchstack
5.9 Medium Related Post Shortcode Plugin related-post-shortcode Cross-Site Scripting ≤ 1.2 CVE-2025-22276 Patchstack
6.5 Medium Weaver Themes Shortcode Compatibility Plugin weaver-themes-shortcode-compatibility Cross-Site Scripting ≤ 1.0.4 CVE-2025-22267 Patchstack
7.1 High Social2Blog Plugin social2blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.990 CVE-2025-23461 Patchstack
7.1 High Nature FlipBook Plugin vertical-diamond-flipbook-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2025-23454 Patchstack
7.1 High PPO Call To Actions Plugin ppo-call-to-actions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.3 CVE-2025-24001 Patchstack
7.1 High UltraLight Plugin the-ultralight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23998 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only