WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 1,151–1,200 of 2,555 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 52
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium CLP – Custom Login Page by NiteoThemes Plugin clp-custom-login-page Cross-Site Request Forgery Custom Login Page by NiteoThemes plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.5.5 CVE-2025-31769 Patchstack
4.3 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Request Forgery No login needed ≤ 5.4.1 CVE-2025-31763 Patchstack
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
6.5 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.3 CVE-2025-31751 Patchstack
7.1 High Useinfluence Plugin useinfluence Cross-Site Request Forgery No login needed ≤ 1.0.8 CVE-2025-31625 Patchstack
7.1 High Rich Text Editor Plugin richtexteditor Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-31623 Patchstack
7.1 High PostmarkApp Email Integrator Plugin postmarkapp-email-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 Fixed in 2.5.0 CVE-2025-31617 Patchstack
7.1 High Varnish Plugin varnish-wp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-31616 Patchstack
7.1 High Simple Contact Forms Plugin simple-contact-forms Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.4 CVE-2025-31615 Patchstack
7.1 High AB Google Map Travel Plugin ab-google-map-travel Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.6 CVE-2025-31613 Patchstack
4.3 Medium Apimo Connector Plugin apimo Cross-Site Request Forgery No login needed ≤ 2.6.5.1 CVE-2025-31602 Patchstack
6.5 Medium Appointy Appointment Scheduler Plugin appointy-appointment-scheduler Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 4.2.1 CVE-2025-31601 Patchstack
4.3 Medium DesignO Plugin designo Cross-Site Request Forgery No login needed ≤ 2.6.0 CVE-2025-31600 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
7.1 High Leadfox Plugin leadfox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-31585 Patchstack
7.1 High WP Copy Media URL Plugin wp-copy-media-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-31583 Patchstack
4.3 Medium Multi Days Events and Multi Events in One Day Calendar Plugin dragon-calendar-free-version Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31572 Patchstack
7.1 High Related Posts Widget with Thumbnails Plugin advanced-css3-related-posts-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-31570 Patchstack
7.1 High wordpress related Posts with thumbnails Plugin related-posts-list-grid-and-slider-all-in-one Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0.1 CVE-2025-31569 Patchstack
7.1 High Rio Video Gallery Plugin rio-video-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.6 CVE-2025-31566 Patchstack
6.4 Medium WP Link Preview Plugin wp-link-preview Server-Side Request Forgery ≤ 1.4.1 CVE-2025-31527 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
4.3 Medium SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Request Forgery CSRF to Multiple Admin Actions ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-31010 Patchstack
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
4.3 Medium WP Supersized Plugin wp-supersized Cross-Site Request Forgery No login needed ≤ 3.1.6 CVE-2025-31438 Patchstack
5.4 Medium Browser Caching with .htaccess Plugin browser-caching-with-htaccess Cross-Site Request Forgery No login needed 1.2.1 CVE-2025-31439 Patchstack
7.1 High KK I Like It Plugin kk-i-like-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.5.3 CVE-2025-31443 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
5.4 Medium Simple Trackback Disabler Plugin simple-trackback-disabler Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-31448 Patchstack
5.4 Medium NertWorks All in One Social Share Tools Plugin nertworks-all-in-one-social-share-tools Cross-Site Request Forgery No login needed ≤ 1.26 CVE-2025-31447 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
4.3 Medium Ultimate Security Checker Plugin ultimate-security-checker Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Security Rescan No login needed ≤ 4.2 CVE-2025-31456 Patchstack
7.1 High Video Embedder Plugin video-embedder Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.7.1 Fixed in 1.8 CVE-2025-31458 Patchstack
5.4 Medium LWS SMS Plugin lws-sms Cross-Site Request Forgery No login needed ≤ 2.4.1 CVE-2025-31457 Patchstack
7.1 High Login Alert Plugin login-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.1 CVE-2025-31459 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
4.3 Medium WP Database Optimizer Plugin wp-database-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.1.3 CVE-2025-31474 Patchstack
4.9 Medium WP Compress for MainWP Plugin wp-compress-mainwp Server-Side Request Forgery ≤ 6.30.03 Fixed in 6.30.06 CVE-2025-31076 Patchstack
4.3 Medium Usermaven Plugin usermaven Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-31079 Patchstack
4.3 Medium Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Cross-Site Request Forgery Arbitrary Tickets Deletion via CSRF No login needed < 2.5.4 Fixed in 2.5.4 CVE-2025-1762 WPScan
7.1 High Filled In Plugin filled-in Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-22628 Patchstack
5.4 Medium Easy Booked – Appointment Booking and Scheduling Management System Plugin easy-booked Cross-Site Request Forgery No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-22634 Patchstack
4.3 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22637 Patchstack
4.3 Medium AIO Performance Profiler, Monitor, Optimize, Compress & Debug Plugin all-in-one-performance-accelerator Broken Access Control ≤ 1.2 Fixed in 1.3 CVE-2025-22647 Patchstack
7.1 High Listings for Appfolio Plugin listings-for-appfolio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22658 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
6.5 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-22670 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only