WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,851–11,900 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 238 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium MyBookTable Bookstore Plugin mybooktable Cross-Site Request Forgery No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-22301 Patchstack
5.3 Medium WP Wand Plugin ai-content-generation Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-22302 Patchstack
5.3 Medium WP Mailster Plugin wp-mailster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.17.0 Fixed in 1.8.18.0 CVE-2025-22303 Patchstack
6.5 Medium Hero Banner Ultimate Plugin hero-banner-ultimate Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-22305 Patchstack
4.3 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Broken Access Control ≤ 7.5 Fixed in 7.6 CVE-2025-22304 Patchstack
6.5 Medium Smart Custom Fields Plugin smart-custom-fields Cross-Site Scripting ≤ 5.0.0 Fixed in 5.0.1 CVE-2025-22308 Patchstack
6.5 Medium SpeakOut! Email Petitions Plugin speakout Cross-Site Scripting ≤ 4.4.2 Fixed in 4.5.0 CVE-2025-22309 Patchstack
6.5 Medium TemplatesNext ToolKit Plugin templatesnext-toolkit Cross-Site Scripting ≤ 3.2.9 CVE-2025-22310 Patchstack
6.5 Medium Typing Text Plugin typing-text Cross-Site Scripting ≤ 1.2.7 CVE-2025-22315 Patchstack
6.5 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting ≤ 1.2.9 Fixed in 1.2.9.1 CVE-2025-22312 Patchstack
5.9 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2025-22316 Patchstack
7.1 High ProductDyno Plugin productdyno Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.24 Fixed in 1.0.25 CVE-2025-22320 Patchstack
6.5 Medium Image Hover Effects for Elementor Plugin image-hover-effects-elementor-addon Cross-Site Scripting ≤ 1.0.2.4 CVE-2025-22323 Patchstack
6.5 Medium ElementsCSS Addons for Elementor Plugin css-for-elementor Cross-Site Scripting ≤ 1.0.8.9 CVE-2025-22321 Patchstack
7.1 High OZ Canonical Plugin oz-canonical Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-22324 Patchstack
7.1 High Autocompleter Plugin autocompleter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.5.2 CVE-2025-22325 Patchstack
7.1 High 5centsCDN Plugin 5centscdn Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.4.15 CVE-2025-22326 Patchstack
7.1 High Elevio Plugin elevio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.4.1 CVE-2025-22328 Patchstack
6.5 Medium EO4WP Plugin fw-integration-for-emailoctopus Cross-Site Scripting ≤ 1.0.8.1 Fixed in 1.0.8.2 CVE-2025-22327 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.31 Fixed in 2.4.32 CVE-2025-22333 Patchstack
7.1 High Wizhi Multi Filters by Wenprise Plugin wizhi-multi-filters Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.8.6 CVE-2025-22336 Patchstack
6.5 Medium Store Commerce Plugin store-commerce Cross-Site Scripting ≤ 1.2.3 CVE-2025-22339 Patchstack
7.1 High wpSOL Plugin wpsol Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 CVE-2025-22343 Patchstack
7.1 High WP Simple Sitemap Plugin wp-simple-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2 CVE-2025-22342 Patchstack
8.2 High BSK Forms Blacklist Plugin bsk-gravityforms-blacklist Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 3.9 Fixed in 4.0 CVE-2025-22347 Patchstack
8.5 High DynamicTags Plugin dynamictags SQL Injection ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-22348 Patchstack
7.6 High Auction Plugin wp-auctions SQL Injection ≤ 3.7 CVE-2025-22349 Patchstack
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
7.6 High Contact Form 7 Database – CFDB7 Plugin advanced-cf7-database SQL Injection CFDB7 plugin <= 1.0.0 - SQL Injection ≤ 1.0.0 CVE-2025-22351 Patchstack
7.1 High BVD Easy Gallery Manager Plugin bvd-easy-gallery-manager Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-22353 Patchstack
7.1 High Kikx Simple Post Author Filter Plugin sa-post-author-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22355 Patchstack
7.1 High Target Notifications Plugin target-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-22357 Patchstack
7.1 High SyncFields Plugin syncfields Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-22359 Patchstack
7.1 High Wp advertising management Plugin advertising-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-22358 Patchstack
6.5 Medium WPAchievements Free Plugin wpachievements-free Cross-Site Scripting ≤ 1.2.0 CVE-2025-22362 Patchstack
7.5 High Ach Invoice App Plugin ach-invoice-app Local File Inclusion No login needed ≤ 1.0.1 CVE-2025-22364 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal ≤ 4.24.15 CVE-2024-12719 Wordfence
4.3 Medium Aurum - WordPress & WooCommerce Shopping Theme Broken Access Control WordPress & WooCommerce Shopping Theme <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Demo Content Import ≤ 4.0.2 CVE-2024-12781 Wordfence
4.8 Medium WordPress Auction Plugin Cross-Site Scripting Editor+ Stored XSS ≤ 3.7 CVE-2024-8857 WPScan
9.8 Critical WordPress Auction Plugin SQL Injection Editor+ SQL Injection No login needed ≤ 3.7 CVE-2024-8855 WPScan
6.4 Medium Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites Plugin common-ninja Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11382 Wordfence
6.1 Medium Financial Stocks & Crypto Market Data Plugin live-stock-prices-for-wordpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.10.3 CVE-2024-11690 Wordfence
6.4 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll Cross-Site Scripting Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.5 CVE-2024-12528 Wordfence
6.5 Medium Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler Plugin cf7-styler Arbitrary Shortcode Execution CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-12419 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
6.4 Medium Taskbuilder – WordPress Project & Task Management Plugin taskbuilder Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode ≤ 3.0.6 CVE-2024-11930 Wordfence
6.1 Medium WP Smart Import : Import any XML File to Plugin wp-smart-import Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-12701 Wordfence
7.3 High WordPress Popular Posts Plugin wordpress-popular-posts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.0 CVE-2024-11733 Wordfence
5.4 Medium Post Teaser Plugin post-teaser Broken Access Control Auth. Broken Access Control ≤ 4.1.5 CVE-2022-45811 Patchstack
5.3 Medium WP Table Manager Plugin wp-table-manager Broken Access Control No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2022-47601 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only