WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,151–1,200 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 CVE-2024-13774 Wordfence
6.1 Medium Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins Plugin related-post Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed 2.0.59 CVE-2024-12634 Wordfence
5.5 Medium WPGet API Plugin wpgetapi Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.2.10 CVE-2024-13857 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence
4.3 Medium Homey Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed ≤ 2.4.3 CVE-2025-0748 Wordfence
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed ≤ 4.2.2 CVE-2025-1383 Wordfence
4.3 Medium Spreadsheet Integration Plugin wpgsi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed ≤ 3.8.2 CVE-2025-1463 Wordfence
6.3 Medium bbPress Plugin bbpress Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed ≤ 2.6.11 CVE-2025-1435 Wordfence
4.3 Medium I Am Gloria Plugin gloria-assistant-by-webtronic-labs Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-0990 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
5.4 Medium Theme Options Z Plugin theme-options-z Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-25121 Patchstack
4.8 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Server-Side Request Forgery Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links No login needed ≤ 2.7.4 CVE-2024-13697 Wordfence
4.3 Medium Simple:Press Plugin simplepress Cross-Site Request Forgery Cross-Site Request Forgery to Unauthorized Post Editing No login needed ≤ 6.10.12 CVE-2024-13518 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
6.4 Medium URL Media Uploader Plugin url-media-uploader Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via DNS Rebinding ≤ 1.0.0 CVE-2025-1662 Wordfence
4.3 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 3.1.0 CVE-2025-1506 Wordfence
4.3 Medium RateMyAgent Official Plugin ratemyagent-official Cross-Site Request Forgery Cross-Site Request Forgery to API Key Update No login needed ≤ 1.4.0 CVE-2025-0801 Wordfence
4.9 Medium Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Server-Side Request Forgery WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery ≤ 1.16.8 CVE-2024-13907 Wordfence
5.3 Medium OneStore Sites Plugin onestore-sites Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 0.1.1 CVE-2024-13905 Wordfence
4.3 Medium School Management System – SakolaWP Plugin sakolawp-lite Cross-Site Request Forgery SakolaWP <= 1.0.8 - Cross-Site Request Forgery to Exam Setting Manipulation No login needed ≤ 1.0.8 CVE-2024-13647 Wordfence
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
4.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.1.6 CVE-2024-13560 Wordfence
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
6.4 Medium Enfold Theme Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id ≤ 6.0.9 CVE-2024-13695 Wordfence
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Cross-Site Request Forgery in wfu_file_details No login needed ≤ 4.25.2 CVE-2024-13494 Wordfence
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack
4.3 Medium RAYS Grid Plugin rays-grid Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-27317 Patchstack
4.3 Medium JPG, PNG Compression and Optimization Plugin wp-image-compression Cross-Site Request Forgery No login needed ≤ 1.7.35 CVE-2025-27316 Patchstack
4.3 Medium All-In-One Cufon Plugin all-in-one-cufon Cross-Site Request Forgery No login needed ≤ 1.3.0 CVE-2025-27315 Patchstack
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack
4.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Cross-Site Request Forgery Cross-Site Request Forgery to Custom CSS Update No login needed ≤ 3.51 CVE-2024-13883 Wordfence
6.4 Medium Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files Plugin embed-any-document Server-Side Request Forgery Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode ≤ 2.7.5 CVE-2025-1043 Wordfence
6.1 Medium DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 5.8.0 CVE-2024-13339 Wordfence
4.3 Medium Disable Auto Updates Plugin disable-auto-updates Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed ≤ 1.4 CVE-2024-13336 Wordfence
4.3 Medium Apptivo Business Site CRM Plugin apptivo-business-site Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed ≤ 5.3 CVE-2024-13405 Wordfence
6.5 Medium WP Media Category Management Plugin wp-media-category-management Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 2.0 – 2.3.3 CVE-2025-0865 Wordfence
6.1 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.7.1007 CVE-2025-1441 Wordfence
4.3 Medium Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later Plugin flexible-wishlist Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed ≤ 1.2.26 CVE-2024-13718 Wordfence
4.3 Medium Ecwid by Lightspeed Ecommerce Shopping Cart Plugin ecwid-shopping-cart Cross-Site Request Forgery Cross-Site Request Forgery to Send Deactivation Message No login needed ≤ 6.12.27 CVE-2024-13795 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only