WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 11,351–11,400 of 17,051 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Tamara Checkout | Cross-Site Scripting |
≤ 1.9.9.1 Fixed in 1.9.9.1 |
CVE-2025-23997 |
Patchstack | |
| 6.5 Medium | Flexible PDF Coupons | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.10.3 Fixed in 1.10.3 |
CVE-2025-22825 |
Patchstack | |
| 7.1 High | My auctions allegro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.6.18 Fixed in 3.6.19 |
CVE-2025-22733 |
Patchstack | |
| 6.5 Medium | Ad Blocking Detector | Cross-Site Scripting |
≤ 3.6.0 |
CVE-2025-22732 |
Patchstack | |
| 6.5 Medium | MailChimp Subscribe Forms | Cross-Site Scripting |
≤ 4.1 Fixed in 4.2 |
CVE-2025-22727 |
Patchstack | |
| 9.1 Critical | Barcode Scanner with Inventory & Order Manager | Arbitrary File Upload |
≤ 1.6.7 Fixed in 1.7.0 |
CVE-2025-22723 |
Patchstack | |
| 7.1 High | VikAppointments Services Booking Calendar | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.16 Fixed in 1.2.17 |
CVE-2025-22719 |
Patchstack | |
| 6.5 Medium | FAT Event Lite | Cross-Site Scripting |
≤ 1.1 |
CVE-2025-22718 |
Patchstack | |
| 7.5 High | My Tickets | Broken Access Control No login needed |
≤ 2.0.9 Fixed in 2.0.10 |
CVE-2025-22717 |
Patchstack | |
| 8.5 High | Taskbuilder | SQL Injection |
≤ 3.0.6 Fixed in 3.0.7 |
CVE-2025-22716 |
Patchstack | |
| 7.1 High | Image Source Control | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.29.0 Fixed in 2.29.1 |
CVE-2025-22711 |
Patchstack | |
| 7.6 High | Smart Manager | SQL Injection |
≤ 8.52.0 Fixed in 8.53.0 |
CVE-2025-22710 |
Patchstack | |
| 7.1 High | Verge3D | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.8.0 Fixed in 4.8.1 |
CVE-2025-22709 |
Patchstack | |
| 7.1 High | Social Pug: Author Box | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-22706 |
Patchstack | |
| 5.9 Medium | Bonjour Bar | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-22262 |
Patchstack | |
| 9.8 Critical | Easy Real Estate | Privilege Escalation No login needed |
≤ 2.2.9 Fixed in 2.3.0 |
CVE-2024-32555 |
Patchstack | |
| 7.1 High | Brizy Pro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.1 |
CVE-2025-22763 |
Patchstack | |
| 7.1 High | WordPress Tag Cloud Plugin – Tag Groups | Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2025-22735 |
Patchstack | |
| 9.3 Critical | Multiple Carousel | SQL Injection No login needed |
≤ 2.0 |
CVE-2025-22553 |
Patchstack | |
| 7.1 High | Private Messages for UserPro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.10.0 |
CVE-2025-22322 |
Patchstack | |
| 7.5 High | Standard Box Sizes – for WooCommerce | Broken Access Control No login needed |
≤ 1.6.13 Fixed in 1.6.14 |
CVE-2025-22318 |
Patchstack | |
| 7.5 High | Private Messages for UserPro | Local File Inclusion No login needed |
≤ 4.10.0 |
CVE-2025-22311 |
Patchstack | |
| 5.3 Medium | Poll Maker | Content Injection HTML Injection No login needed |
≤ 5.5.5 Fixed in 5.5.5 |
CVE-2024-56277 |
Patchstack | |
| 9.0 Critical | Fancy Product Designer | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 6.4.3 Fixed in 6.4.4 |
CVE-2024-51919 |
Patchstack | |
| 9.8 Critical | Homey Login Register | Privilege Escalation No login needed |
≤ 2.4.0 |
CVE-2024-51888 |
Patchstack | |
| 9.3 Critical | Fancy Product Designer | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.4.3 Fixed in 6.4.4 |
CVE-2024-51818 |
Patchstack | |
| 7.1 High | ARPrice | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49700 |
Patchstack | |
| 8.8 High | ARPrice | PHP Object Injection |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49699 |
Patchstack | |
| 9.8 Critical | ARPrice | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49688 |
Patchstack | |
| 8.5 High | ARPrice | SQL Injection |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49666 |
Patchstack | |
| 9.3 Critical | ARPrice | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49655 |
Patchstack | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49333 |
Patchstack | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49303 |
Patchstack | |
| 7.1 High | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-49300 |
Patchstack | |
| 7.5 High | The Ultimate WordPress Toolkit – WP Extended | SQL Injection WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module No login needed |
≤ 3.0.12 |
CVE-2024-13184 |
Wordfence | |
| 4.3 Medium | Buzz Club – Night Club, DJ and Music Festival Event | Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update |
≤ 2.0.4 |
CVE-2025-0515 |
Wordfence | |
| 4.4 Medium | Podlove Podcast Publisher | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name |
≤ 4.1.25 |
CVE-2025-0554 |
Wordfence | |
| 6.5 Medium | SOCIAL.NINJA | Cross-Site Scripting |
≤ 0.2 |
CVE-2025-23907 |
Patchstack | |
| 6.5 Medium | Metaphor Widgets | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 2.4 |
CVE-2025-23816 |
Patchstack | |
| 5.3 Medium | Copy Move Posts | Broken Access Control No login needed |
≤ 1.6 |
CVE-2025-23764 |
Patchstack | |
| 7.1 High | root Cookie | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.6 |
CVE-2025-23815 |
Patchstack | |
| 7.1 High | Auto FTP | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-23793 |
Patchstack | |
| 5.4 Medium | Woo Tuner | Broken Access Control |
≤ 0.1.2 |
CVE-2025-23761 |
Patchstack | |
| 7.1 High | Chatter | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0.1 |
CVE-2025-23760 |
Patchstack | |
| 4.3 Medium | Sur.ly | Broken Access Control |
≤ 3.0.3 |
CVE-2025-23957 |
Patchstack | |
| 6.5 Medium | Kopa Nictitate Toolkit | Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-23965 |
Patchstack | |
| 5.4 Medium | WordPress Graphs & Charts | Broken Access Control |
≤ 2.0.8 |
CVE-2025-23961 |
Patchstack | |
| 4.3 Medium | Xola | Broken Access Control |
≤ 1.6 |
CVE-2025-23955 |
Patchstack | |
| 5.4 Medium | Mark Posts | Broken Access Control |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2025-23963 |
Patchstack | |
| 4.3 Medium | Goldstar | Broken Access Control |
≤ 2.1.1 |
CVE-2025-23962 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.