WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,201–1,250 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 52
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
4.3 Medium Product Author for WooCommerce Plugin wc-product-author Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-30872 Patchstack
4.3 Medium 3DPrint Lite Plugin 3dprint-lite Cross-Site Request Forgery No login needed ≤ 2.1.3.5 Fixed in 2.1.3.6 CVE-2025-30865 Patchstack
4.3 Medium Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-30863 Patchstack
4.3 Medium reCAPTCHA for all Plugin recaptcha-for-all Cross-Site Request Forgery No login needed ≤ 2.22 Fixed in 2.23 CVE-2025-30862 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
4.3 Medium Custom Field For WP Job Manager Plugin custom-field-for-wp-job-manager Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-30856 Patchstack
4.3 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-30854 Patchstack
4.3 Medium Christmas Panda Plugin christmas-panda Cross-Site Request Forgery No login needed ≤ 1.0.4 Fixed in 1.1.0 CVE-2025-30842 Patchstack
4.3 Medium Verge3D Plugin verge3d Cross-Site Request Forgery No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-30833 Patchstack
4.3 Medium Anthologize Plugin anthologize Cross-Site Request Forgery No login needed ≤ 0.8.2 Fixed in 0.8.3 CVE-2025-30823 Patchstack
4.3 Medium Custom Login Logo Plugin ideal-wp-login-logo-changer Cross-Site Request Forgery No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30822 Patchstack
4.3 Medium publish post email notification Plugin publish-post-email-notification Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.2.3 Fixed in 1.0.2.4 CVE-2025-30816 Patchstack
4.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2025-30815 Patchstack
4.3 Medium ValidateCertify Plugin validar-certificados-de-cursos Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-30811 Patchstack
4.3 Medium Flexible Cookies Plugin flexible-cookies Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-30805 Patchstack
4.3 Medium wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-30804 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
4.3 Medium Football Pool Plugin football-pool Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2025-30764 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.1 High Cookies Pro Plugin cookies-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-26546 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
8.8 High Booknetic Plugin Cross-Site Request Forgery Staff Creation via CSRF No login needed < 4.1.5 Fixed in 4.1.5 CVE-2024-13146 WPScan
7.2 High Downloable by American Osteopathic Association Plugin Server-Side Request Forgery Unauthenticated SSRF No login needed ≤ 0.1.0 CVE-2024-13618 WPScan
4.3 Medium IP Based Login Plugin ip-based-login Cross-Site Request Forgery Log Deletion via CSRF No login needed < 2.4.1 Fixed in 2.4.1 CVE-2024-13118 WPScan
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack
4.3 Medium Flipdish Ordering System Plugin flipdish-ordering-system Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.5.2 CVE-2025-30601 Patchstack
4.3 Medium OSS Upload Plugin oss-upload Cross-Site Request Forgery WordPress OSS Upload plugin <= 4.8.9 Cross Site Request Forgery (CSRF) No login needed ≤ 4.8.9 CVE-2025-30598 Patchstack
7.1 High Map Contact Plugin map-contact Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.4 CVE-2025-30588 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High cTabs Plugin ctabs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-30586 Patchstack
4.3 Medium Generate Post Thumbnails Plugin generate-post-thumbnails Cross-Site Request Forgery No login needed ≤ 0.8 CVE-2025-30585 Patchstack
7.1 High AlphaOmega Captcha & Anti-Spam Filter Plugin alphaomega-captcha-anti-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3 CVE-2025-30584 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only