WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,451–11,500 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 230 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Nite Shortcodes Plugin nite-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23877 Patchstack
7.1 High PayForm Plugin payform Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-23872 Patchstack
6.5 Medium WCS QR Code Generator Plugin wcs-qr-code-generator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23864 Patchstack
7.1 High LSD Google Maps Embedder Plugin lsd-google-maps-embedder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23871 Patchstack
6.5 Medium Chess Tempo Viewer Plugin chesstempoviewer Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.9.5 CVE-2025-23868 Patchstack
6.5 Medium Winning Portfolio Plugin winning-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23865 Patchstack
7.1 High Copyright Safeguard Footer Notice Plugin copyright-safeguard-footer-notice Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 3.0 CVE-2025-23870 Patchstack
6.5 Medium Rollover Tab Plugin rollover-tab Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-23863 Patchstack
7.1 High CJ Custom Content Plugin cj-custom-content Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-23869 Patchstack
5.9 Medium Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com Plugin shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com Cross-Site Scripting ≤ 3.3 CVE-2025-23854 Patchstack
6.5 Medium Daily Proverb Plugin daily-proverb Cross-Site Scripting ≤ 2.0.3 CVE-2025-23859 Patchstack
5.3 Medium Contact Form 7 Anti Spambot Plugin contact-form-7-anti-spambot Broken Access Control No login needed ≤ 1.0.1 CVE-2025-23862 Patchstack
6.5 Medium Charity-thermometer Plugin charitydonation-thermometer Cross-Site Scripting ≤ 1.1.2 CVE-2025-23860 Patchstack
7.1 High Debt Calculator Plugin debt-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23861 Patchstack
6.5 Medium Simple Vertical Timeline Plugin simple-vertical-timeline Cross-Site Scripting ≤ 0.1 CVE-2025-23856 Patchstack
7.1 High Hotspots Analytics Plugin hotspots Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.12 CVE-2025-23848 Patchstack
7.1 High Gallery Plugin wordpress-gallery-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23842 Patchstack
6.5 Medium Top Flash Embed Plugin top-flash-embed Cross-Site Scripting ≤ 0.3.4 CVE-2025-23841 Patchstack
6.5 Medium JB Horizontal Scroller News Ticker Plugin jb-horizontal-scroller-news-ticker Cross-Site Scripting ≤ 1.0 CVE-2025-23830 Patchstack
7.1 High Custom Widget Classes Plugin custom-widget-classes Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23844 Patchstack
6.5 Medium QR Code Generator Plugin qrcode-wprhe Cross-Site Scripting ≤ 1.2.6 CVE-2025-23831 Patchstack
7.1 High WordPress Data Guard Plugin wordpress-data-guards Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 8 CVE-2025-23828 Patchstack
7.1 High Stop Comment Spam Plugin stop-comment-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5.3 Fixed in 0.5.4 CVE-2025-23826 Patchstack
6.5 Medium Links/Problem Reporter Plugin report-broken-links Cross-Site Scripting ≤ 2.6.0 CVE-2025-23833 Patchstack
6.5 Medium FontAwesome.io ShortCodes Plugin fontawesomeio-shortcodes Cross-Site Scripting ≤ 1.0 CVE-2025-23824 Patchstack
7.1 High CNZZ&51LA Plugin cnzz51la-for-wordpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23823 Patchstack
6.5 Medium Easy Shortcode Buttons Plugin easy-shortcode-buttons Cross-Site Scripting ≤ 1.2 CVE-2025-23825 Patchstack
7.1 High WP Cookies Alert Plugin wp-cookies-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-23821 Patchstack
7.1 High Admin Cleanup Plugin admin-cleanup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2025-23832 Patchstack
7.1 High Strx Magic Floating Sidebar Maker Plugin strx-magic-floating-sidebar-maker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23827 Patchstack
7.1 High Content Security Policy Pro Plugin content-security-policy-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.5 CVE-2025-23820 Patchstack
7.1 High More Link Modifier Plugin more-link-modifier Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2025-23818 Patchstack
7.1 High Category Custom Fields Plugin categorycustomfields Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23822 Patchstack
6.5 Medium Spiderpowa Embed PDF Plugin spiderpowa-embed-pdf Cross-Site Scripting ≤ 1.0 CVE-2025-23807 Patchstack
7.1 High Custom List Table Example Plugin custom-list-table-example Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23808 Patchstack
7.1 High MHR-Custom-Anti-Copy Plugin mhr-custom-anti-copy Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 2.0 CVE-2025-23817 Patchstack
7.1 High SEOReseller Partner Plugin sr-partner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.15 CVE-2025-23805 Patchstack
7.1 High Len Slider Plugin len-slider Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 CVE-2025-23810 Patchstack
7.1 High WP Service Payment Form With Authorize.net Plugin wp-service-payment-form-with-authorizenet Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-23804 Patchstack
7.1 High Style Admin Plugin style-admin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.3 CVE-2025-23801 Patchstack
9.8 Critical WP Options Editor Plugin wp-options-editor Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.1 CVE-2025-23797 Patchstack
6.5 Medium Easy FAQs Plugin easy-faqs Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.1 CVE-2025-23795 Patchstack
6.5 Medium WP-Revive Adserver Plugin wp-revive-adserver Cross-Site Scripting ≤ 2.2.1 CVE-2025-23802 Patchstack
7.1 High OrangeBox Plugin orangebox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0 CVE-2025-23800 Patchstack
6.5 Medium Easy Portfolio Plugin easy-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-23796 Patchstack
6.5 Medium Horizontal Line Shortcode Plugin horizontal-line-shortcode Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23791 Patchstack
6.5 Medium wp_amaps Plugin wp-amaps Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-23794 Patchstack
7.6 High Easy Code Snippets Plugin easy-code-snippets SQL Injection ≤ 1.0.2 CVE-2025-23780 Patchstack
4.3 Medium AI Responsive Gallery Album Plugin ai-responsive-gallery-album Broken Access Control ≤ 1.4 CVE-2025-23785 Patchstack
5.4 Medium User Sync ActiveCampaign Plugin registered-user-sync-activecampaign Broken Access Control ≤ 1.3.2 CVE-2025-23778 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only