WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,101–1,150 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-50044 Patchstack
7.1 High Virtual Moderator Plugin virtual-moderator Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52772 Patchstack
7.1 High TinyNav Plugin tinynav Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52781 Patchstack
7.1 High Logo Manager For Samandehi Plugin samandehi-logo-manager Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-52780 Patchstack
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.1 High Lewe ChordPress Plugin chordpress Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.1 CVE-2025-52789 Patchstack
7.1 High Bluff Post Plugin bluff-post Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-52784 Patchstack
7.1 High Knowledge Base – Knowledge Base Maker Plugin knowledge-base-maker Cross-Site Request Forgery Knowledge Base Maker plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2025-52791 Patchstack
7.1 High WP-DownloadCounter Plugin wp-downloadcounter Cross-Site Request Forgery No login needed ≤ 1.01 CVE-2025-52790 Patchstack
7.1 High Esselink.nu Settings Plugin esselinknu-settings Cross-Site Request Forgery No login needed ≤ 4.5 CVE-2025-52793 Patchstack
7.1 High WP User Stylesheet Switcher Plugin wp-user-stylesheet-switcher Cross-Site Request Forgery No login needed ≤ v2.2.0 CVE-2025-52792 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Request Forgery No login needed ≤ 5.0.6 CVE-2025-52795 Patchstack
7.1 High Creative Contact Form Plugin sexy-contact-form Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-52794 Patchstack
8.8 High Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-52825 Patchstack
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
4.3 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-49856 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-49865 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
6.1 Medium XiSearch bar Plugin xisearch-bar Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.6 CVE-2025-6063 Wordfence
4.3 Medium Yougler Blogger Profile Page Plugin yougler-blogger-profile-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ v1.01 CVE-2025-6062 Wordfence
4.3 Medium AI Image Lab – Free AI Image Generator Plugin ai-image-generator-lab Cross-Site Request Forgery Free AI Image Generator <= 1.0.6 - Cross-Site Request Forgery to API Key Update No login needed ≤ 1.0.6 CVE-2025-4592 Wordfence
6.1 Medium Zen Sticky Social Plugin zen-social-sticky Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.3 CVE-2025-6055 Wordfence
6.1 Medium Easy Flashcards Plugin easy-flashcards Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.1 CVE-2025-6040 Wordfence
6.1 Medium WP URL Shortener Plugin wp-url-shortener Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-6064 Wordfence
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed ≤ 2.27.21 CVE-2025-6059 Wordfence
4.3 Medium WP Sliding Login/Dashboard Panel Plugin wp-sliding-logindashboard-panel Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.1.1 CVE-2025-5928 Wordfence
5.3 Medium Digital Marketing and Agency Templates Addons for Elementor Plugin digital-marketing-agency-templates-for-elementor Cross-Site Request Forgery Cross-Site Request Forgery to Import No login needed ≤ 1.1.1 CVE-2025-5938 Wordfence
4.3 Medium WP2HTML Plugin wp2html Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.2 CVE-2025-5930 Wordfence
6.1 Medium Link Shield Plugin link-shield Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.5.4 CVE-2025-5926 Wordfence
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
4.3 Medium Bunny’s Print CSS Plugin bunnys-print-css Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 0.95 CVE-2025-5925 Wordfence
7.1 High Konami Easter Egg Plugin konami-easter-egg Cross-Site Request Forgery No login needed ≤ v0.4 CVE-2025-49425 Patchstack
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium Wp Easy Allopass Plugin wordpress-easy-allopass Cross-Site Request Forgery No login needed ≤ 4.1.1 CVE-2025-49435 Patchstack
4.3 Medium WP Security Master Plugin wp-security-master Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-49440 Patchstack
4.3 Medium Admin Notes Plugin admin-note Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49446 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
7.1 High BP Profile as Homepage Plugin bp-profile-as-homepage Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1 CVE-2025-49453 Patchstack
5.4 Medium Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Request Forgery No login needed ≤ 1.0.4 CVE-2025-24772 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
4.3 Medium WP Media File Type Manager Plugin wp-media-file-type-manager Cross-Site Request Forgery No login needed ≤ 2.3.1 CVE-2025-27359 Patchstack
7.1 High Post Author Plugin post-author Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28950 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
4.3 Medium CubePoints Plugin cubepoints Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-28952 Patchstack
7.1 High Free WP Mail SMTP Plugin free-wp-mail-smtp Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-28974 Patchstack
7.1 High Recent Posts Slider Responsive Plugin recent-posts-slider-responsive Cross-Site Request Forgery No login needed ≤ 1.0.1 CVE-2025-28966 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only