WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,351–11,400 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 228 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Tamara Checkout Plugin tamara-checkout Cross-Site Scripting ≤ 1.9.9.1 Fixed in 1.9.9.1 CVE-2025-23997 Patchstack
6.5 Medium Flexible PDF Coupons Plugin flexible-coupons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.3 Fixed in 1.10.3 CVE-2025-22825 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.18 Fixed in 3.6.19 CVE-2025-22733 Patchstack
6.5 Medium Ad Blocking Detector Plugin ad-blocking-detector Cross-Site Scripting ≤ 3.6.0 CVE-2025-22732 Patchstack
6.5 Medium MailChimp Subscribe Forms Plugin mailchimp-subscribe-sm Cross-Site Scripting ≤ 4.1 Fixed in 4.2 CVE-2025-22727 Patchstack
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Arbitrary File Upload ≤ 1.6.7 Fixed in 1.7.0 CVE-2025-22723 Patchstack
7.1 High VikAppointments Services Booking Calendar Plugin vikappointments Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-22719 Patchstack
6.5 Medium FAT Event Lite Plugin fat-event-lite Cross-Site Scripting ≤ 1.1 CVE-2025-22718 Patchstack
7.5 High My Tickets Plugin my-tickets Broken Access Control No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2025-22717 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-22716 Patchstack
7.1 High Image Source Control Plugin image-source-control-isc Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.29.0 Fixed in 2.29.1 CVE-2025-22711 Patchstack
7.6 High Smart Manager Plugin smart-manager-for-wp-e-commerce SQL Injection ≤ 8.52.0 Fixed in 8.53.0 CVE-2025-22710 Patchstack
7.1 High Verge3D Plugin verge3d Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-22709 Patchstack
7.1 High Social Pug: Author Box Plugin social-pug-author-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-22706 Patchstack
5.9 Medium Bonjour Bar Plugin bonjour-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-22262 Patchstack
9.8 Critical Easy Real Estate Plugin easy-real-estate Privilege Escalation No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-32555 Patchstack
7.1 High Brizy Pro Plugin brizy-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2025-22763 Patchstack
7.1 High WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-22735 Patchstack
9.3 Critical Multiple Carousel Plugin multicarousel SQL Injection No login needed ≤ 2.0 CVE-2025-22553 Patchstack
7.1 High Private Messages for UserPro Plugin userpro-messaging Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.10.0 CVE-2025-22322 Patchstack
7.5 High Standard Box Sizes – for WooCommerce Plugin standard-box-sizes Broken Access Control No login needed ≤ 1.6.13 Fixed in 1.6.14 CVE-2025-22318 Patchstack
7.5 High Private Messages for UserPro Plugin userpro-messaging Local File Inclusion No login needed ≤ 4.10.0 CVE-2025-22311 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Content Injection HTML Injection No login needed ≤ 5.5.5 Fixed in 5.5.5 CVE-2024-56277 Patchstack
9.0 Critical Fancy Product Designer Plugin fancy-product-designer Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51919 Patchstack
9.8 Critical Homey Login Register Plugin homey-login-register Privilege Escalation No login needed ≤ 2.4.0 CVE-2024-51888 Patchstack
9.3 Critical Fancy Product Designer Plugin fancy-product-designer SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51818 Patchstack
7.1 High ARPrice Plugin arprice Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49700 Patchstack
8.8 High ARPrice Plugin arprice PHP Object Injection ≤ 4.1.3 Fixed in 4.2 CVE-2024-49699 Patchstack
9.8 Critical ARPrice Plugin arprice PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49688 Patchstack
8.5 High ARPrice Plugin arprice SQL Injection ≤ 4.1.3 Fixed in 4.2 CVE-2024-49666 Patchstack
9.3 Critical ARPrice Plugin arprice SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49655 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49333 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49303 Patchstack
7.1 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-49300 Patchstack
7.5 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended SQL Injection WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module No login needed ≤ 3.0.12 CVE-2024-13184 Wordfence
4.3 Medium Buzz Club – Night Club, DJ and Music Festival Event Theme Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 2.0.4 CVE-2025-0515 Wordfence
4.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name ≤ 4.1.25 CVE-2025-0554 Wordfence
6.5 Medium SOCIAL.NINJA Plugin seo-meta Cross-Site Scripting ≤ 0.2 CVE-2025-23907 Patchstack
6.5 Medium Metaphor Widgets Plugin mtphr-widgets Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.4 CVE-2025-23816 Patchstack
5.3 Medium Copy Move Posts Plugin copy-move-posts Broken Access Control No login needed ≤ 1.6 CVE-2025-23764 Patchstack
7.1 High root Cookie Plugin root-cookie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6 CVE-2025-23815 Patchstack
7.1 High Auto FTP Plugin auto-ftp Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23793 Patchstack
5.4 Medium Woo Tuner Plugin woo-tuner Broken Access Control ≤ 0.1.2 CVE-2025-23761 Patchstack
7.1 High Chatter Plugin chatter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23760 Patchstack
4.3 Medium Sur.ly Plugin surly Broken Access Control ≤ 3.0.3 CVE-2025-23957 Patchstack
6.5 Medium Kopa Nictitate Toolkit Plugin kopa-nictitate-toolkit Cross-Site Scripting ≤ 1.0.2 CVE-2025-23965 Patchstack
5.4 Medium WordPress Graphs & Charts Plugin graph-lite Broken Access Control ≤ 2.0.8 CVE-2025-23961 Patchstack
4.3 Medium Xola Plugin xola-bookings-for-tours-activities Broken Access Control ≤ 1.6 CVE-2025-23955 Patchstack
5.4 Medium Mark Posts Plugin mark-posts Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-23963 Patchstack
4.3 Medium Goldstar Plugin goldstar Broken Access Control ≤ 2.1.1 CVE-2025-23962 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only