WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,251–1,300 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 52
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Pro Rank Tracker Plugin proranktracker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30583 Patchstack
7.1 High AdSense Privacy Policy Plugin adsense-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30578 Patchstack
7.1 High Browser Address Bar Color Plugin browser-address-bar-color Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3 Fixed in 3.4 CVE-2025-30577 Patchstack
4.3 Medium Hacklog Remote Image Autosave Plugin hacklog-remote-image-autosave Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-30576 Patchstack
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
4.3 Medium Super Static Cache Plugin super-static-cache Cross-Site Request Forgery No login needed ≤ 3.3.5 CVE-2025-30568 Patchstack
7.1 High banner-manager Plugin banner-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 16.04.19 CVE-2025-30565 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
7.1 High CAS Maestro Plugin cas-maestro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 CVE-2025-30561 Patchstack
7.1 High jQuery Dropdown Menu Plugin jquery-drop-down-menu-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 CVE-2025-30560 Patchstack
7.1 High ANAC XML Render Plugin anac-xml-render Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.7 CVE-2025-30558 Patchstack
4.3 Medium Easy 301 Redirects Plugin odihost-easy-redirect-301 Cross-Site Request Forgery No login needed ≤ 1.33 CVE-2025-30557 Patchstack
4.3 Medium Fix Rss Feeds Plugin fix-rss-feed Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-30556 Patchstack
7.1 High WordPres 同步微博 Plugin wp2wb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30555 Patchstack
7.1 High WordPress Admin Bar Improved Plugin wordpress-admin-bar-improved Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.5 CVE-2025-30552 Patchstack
7.1 High CallPhone'r Plugin callphoner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30550 Patchstack
4.3 Medium Yummly Rich Recipes Plugin yummly-rich-recipes Cross-Site Request Forgery No login needed ≤ 4.2 CVE-2025-30549 Patchstack
4.3 Medium Cackle Plugin cackle Cross-Site Request Forgery No login needed ≤ 4.33 CVE-2025-30546 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack
4.3 Medium Simple Optimizer Plugin simple-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-30538 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
4.3 Medium Image Captcha Plugin image-captcha Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-30534 Patchstack
4.3 Medium WP Ride Booking Plugin wp-ride-booking Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-30531 Patchstack
4.3 Medium Auto Load Next Post Plugin auto-load-next-post Cross-Site Request Forgery No login needed ≤ 1.5.14 CVE-2025-30529 Patchstack
9.3 Critical Awesome Logos Plugin awesome-logos Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.2 CVE-2025-30528 Patchstack
4.3 Medium Typekit Plugin typekit Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-30526 Patchstack
7.1 High Contact Form 7 Material Design Plugin cf7-material-design Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30522 Patchstack
4.3 Medium GP Back To Top Plugin gp-back-to-top Cross-Site Request Forgery No login needed ≤ 3.0 CVE-2025-30521 Patchstack
7.5 High NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.9.179 CVE-2024-13558 Wordfence
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
7.1 High Limit Bio Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2025-1436 WPScan
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-28938 Patchstack
7.1 High MaxA/B Plugin maxab Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-28933 Patchstack
7.1 High Insert Code Plugin insert-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 CVE-2025-28932 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
7.1 High WATI Chat and Notification Plugin wati-chat-and-notification Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.5 CVE-2025-28925 Patchstack
7.1 High No Disposable Email Plugin no-disposable-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-28923 Patchstack
7.1 High Go To Top Plugin go-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.8 CVE-2025-28922 Patchstack
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only