WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,401–11,450 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 229 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Salvador – AI Image Generator Plugin salvador-ai-image-generator Broken Access Control AI Image Generator plugin <= 1.0.11 - Broken Access Control ≤ 1.0.11 CVE-2025-23954 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 1.1 CVE-2025-23939 Patchstack
6.5 Medium EZPlayer Plugin ezplayer Cross-Site Scripting ≤ 1.0.10 CVE-2025-23950 Patchstack
6.5 Medium Enhanced YouTube Shortcode Plugin enhanced-youtube-shortcode Cross-Site Scripting ≤ 2.0.1 CVE-2025-23946 Patchstack
6.5 Medium PDF.js Shortcode Plugin pdfjs-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23943 Patchstack
6.5 Medium MeinTurnierplan.de Widget Viewer Plugin meinturnierplande-widget-viewer Cross-Site Scripting ≤ 1.1 CVE-2025-23941 Patchstack
6.5 Medium Gallery: Hybrid – Advanced Visual Gallery Plugin hybrid-gallery Cross-Site Scripting Advanced Visual Gallery plugin <= 1.4.0.2 - Cross Site Scripting (XSS) ≤ 1.4.0.2 CVE-2025-23951 Patchstack
6.5 Medium WP-Player Plugin wp-player Cross-Site Scripting ≤ 2.6.1 CVE-2025-23947 Patchstack
6.5 Medium Giveaways and Contests by PromoSimple Plugin giveaways-contests-by-promosimple Cross-Site Scripting ≤ 1.24 CVE-2025-23934 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 0.1.1 CVE-2025-23940 Patchstack
6.5 Medium Google Org Chart Plugin google-org-chart Cross-Site Scripting ≤ 1.0.1 CVE-2025-23928 Patchstack
6.5 Medium WP Photo Sphere Plugin wp-photo-sphere Cross-Site Scripting ≤ 3.8 CVE-2025-23924 Patchstack
6.5 Medium Magic Google Maps Plugin magic-google-maps Cross-Site Scripting ≤ 1.0.4 CVE-2025-23935 Patchstack
6.5 Medium WpF Ultimate Carousel Plugin wpf-ultimate-carousel Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2025-23933 Patchstack
4.3 Medium PayPal Marketing Solutions Plugin paypal-promotions-and-insights Broken Access Control ≤ 1.2 CVE-2025-23930 Patchstack
5.4 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control ≤ 3.3.8 CVE-2025-23917 Patchstack
6.5 Medium CC Circle Progress Bar Plugin cc-circle-progress-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-23936 Patchstack
6.5 Medium Feedburner Optin Form Plugin feedburner-optin-form Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2.8 CVE-2025-23925 Patchstack
6.5 Medium Incredible Font Awesome Plugin incredible-font-awesome Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23927 Patchstack
4.3 Medium Email Capture & Lead Generation Plugin email-capture-lead-generation Broken Access Control ≤ 1.0.2 CVE-2025-23929 Patchstack
10.0 Critical iSpring Embedder Plugin embed-ispring Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.0 CVE-2025-23922 Patchstack
7.5 High FAT Event Lite Plugin fat-event-lite Local File Inclusion Authenticated Non-Arbitrary Local File Inclusion ≤ 1.1 CVE-2025-23915 Patchstack
6.5 Medium Ajax WP Query Search Filter Plugin ajax-wp-query-search-filter Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.7 CVE-2025-23926 Patchstack
5.4 Medium WP Meetup Plugin wp-meetup Broken Access Control Settings Change ≤ 2.3.0 CVE-2025-23916 Patchstack
5.4 Medium Slides & Presentations Plugin slide Content Injection ≤ 0.0.39 CVE-2025-23919 Patchstack
8.5 High WordPress Custom Sidebar Plugin wordpress-custom-sidebar SQL Injection ≤ 2.3 CVE-2025-23912 Patchstack
7.1 High GravatarLocalCache Plugin gravatarlocalcache Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.2 CVE-2025-23901 Patchstack
8.5 High WordPress Google Map Professional Plugin google-map-professional SQL Injection ≤ 1.0 CVE-2025-23913 Patchstack
8.5 High Solidres – Hotel booking Plugin solidres SQL Injection Hotel booking plugin for WordPress Plugin <= 0.9.4 - SQL Injection ≤ 0.9.4 CVE-2025-23911 Patchstack
6.5 Medium Compare Ninja Plugin compare-ninja-comparison-tables Cross-Site Scripting ≤ 2.1.0 CVE-2025-23909 Patchstack
6.5 Medium Pastebin Plugin pastebin-embed Cross-Site Scripting ≤ 1.5 CVE-2025-23908 Patchstack
7.1 High Genki Announcement Plugin genki-announcement Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23900 Patchstack
7.1 High Error Notification Plugin error-notification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.7 CVE-2025-23902 Patchstack
6.5 Medium Bookalet Plugin bookalet Cross-Site Scripting ≤ 1.0.3 CVE-2025-23899 Patchstack
6.5 Medium Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Scripting ≤ 2.3 CVE-2025-23897 Patchstack
7.1 High Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3 CVE-2025-23898 Patchstack
6.5 Medium Blog Summary Plugin blog-summary Cross-Site Scripting ≤ 0.1.2 β CVE-2025-23887 Patchstack
6.5 Medium Yet Another Countdown Plugin yacp Cross-Site Scripting ≤ 1.0.1 CVE-2025-23891 Patchstack
6.5 Medium Progress Tracker Plugin progress-tracker Cross-Site Scripting ≤ 0.9.3 CVE-2025-23892 Patchstack
7.1 High Annie Plugin annie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 CVE-2025-23884 Patchstack
6.5 Medium Mindmeister Shortcode Plugin mindmeister-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23896 Patchstack
6.5 Medium Easy Tweet Embed Plugin easy-tweet-embed Cross-Site Scripting ≤ 1.7 CVE-2025-23890 Patchstack
7.1 High Add RSS Plugin add-rss Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-23895 Patchstack
6.5 Medium WP krpano Plugin wp-krpano Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 CVE-2025-23876 Patchstack
6.5 Medium GMap Shortcode Plugin gmap-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23893 Patchstack
7.1 High Better Protected Pages Plugin better-protected-pages Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-23875 Patchstack
6.5 Medium Annie Plugin annie Cross-Site Scripting ≤ 2.1.1 CVE-2025-23886 Patchstack
7.1 High amr personalise Plugin amr-personalise Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.10 CVE-2025-23880 Patchstack
5.9 Medium Post-to-Post Links Plugin easy-post-to-post-links Cross-Site Scripting ≤ 4.2 CVE-2025-23878 Patchstack
6.5 Medium Category D3 Tree Plugin category-d3-tree Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23873 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only