WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,301–1,350 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.9.3 Fixed in 4.9.5 CVE-2025-39453 Patchstack
4.3 Medium WooCommerce Social Login Plugin woo-social-login Cross-Site Request Forgery No login needed ≤ 2.8.3 Fixed in 2.8.3 CVE-2025-39472 Patchstack
4.3 Medium Bulk Term Editor Plugin bulk-term-editor Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-39512 Patchstack
4.3 Medium Basic Interactive World Map Plugin basic-interactive-world-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.7 CVE-2025-39517 Patchstack
7.1 High Site Search 360 Plugin site-search-360 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to stored XSS No login needed ≤ 2.1.8 CVE-2025-39530 Patchstack
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Request Forgery No login needed ≤ 6.6.2 Fixed in 6.6.3 CVE-2025-39546 Patchstack
6.5 Medium Conditional Payments for WooCommerce Plugin conditional-payments-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-39563 Patchstack
6.5 Medium Conditional Shipping for WooCommerce Plugin conditional-shipping-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-39564 Patchstack
4.3 Medium Ever Accounting Plugin wp-ever-accounting Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-39593 Patchstack
4.3 Medium Integration for WooCommerce and QuickBooks Plugin wp-woocommerce-quickbooks Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-39600 Patchstack
6.1 Medium Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via saveAsCopy AJAX Action No login needed ≤ 1.7.29 CVE-2024-13452 Wordfence
4.3 Medium InPost Gallery Plugin inpost-gallery Cross-Site Request Forgery No login needed ≤ 2.1.4.3 Fixed in 2.1.4.4 CVE-2025-26903 Patchstack
4.3 Medium WPJobBoard Plugin wpjobboard Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) vulnerabilities No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30965 Patchstack
5.4 Medium Photography Plugin photography Server-Side Request Forgery No login needed ≤ 7.7.6 Fixed in 7.7.6 CVE-2025-30964 Patchstack
4.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Server-Side Request Forgery ≤ 1.7.1006 Fixed in 1.7.1007 CVE-2025-26990 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-27009 Patchstack
5.3 Medium Webcraftic Clearfy – WordPress optimization Plugin clearfy Cross-Site Request Forgery WordPress optimization plugin <= 2.3.1 - Cross-Site Request Forgery to Clear Cache No login needed ≤ 2.3.1 CVE-2024-13338 Wordfence
4.3 Medium Webcraftic Clearfy – WordPress optimization Plugin clearfy Cross-Site Request Forgery WordPress optimization plugin <= 2.3.2 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy' No login needed ≤ 2.3.2 CVE-2024-13337 Wordfence
4.3 Medium WordPress Mega Menu – QuadMenu Plugin quadmenu Cross-Site Request Forgery QuadMenu <= 3.2.0 - Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 3.2.0 CVE-2025-2871 Wordfence
4.3 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Cross-Site Request Forgery No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-32282 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Cross-Site Request Forgery No login needed ≤ 2.6.1 CVE-2025-26902 Patchstack
4.3 Medium Easyfonts Plugin easyfonts Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31005 Patchstack
5.4 Medium IndieBlocks Plugin indieblocks Server-Side Request Forgery No login needed ≤ 0.13.1 Fixed in 0.13.2 CVE-2025-31009 Patchstack
4.3 Medium Customize Login Page Plugin customize-login-page Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1 CVE-2025-31034 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2025-32485 Patchstack
4.9 Medium Waymark Plugin waymark Server-Side Request Forgery ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-32487 Patchstack
4.3 Medium reCAPTCHA Jetpack Plugin recaptcha-jetpack Cross-Site Request Forgery No login needed ≤ 0.2.2 CVE-2025-32494 Patchstack
7.1 High Rentsyst Plugin rentsyst Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.92 Fixed in 2.0.93 CVE-2025-32501 Patchstack
7.1 High REVE Chat Plugin revechat Cross-Site Request Forgery No login needed ≤ 6.4.4 CVE-2025-32559 Patchstack
7.1 High Nimbata Call Tracking Plugin nimbata-call-tracking Cross-Site Request Forgery No login needed ≤ 1.7.4 CVE-2025-32616 Patchstack
7.1 High Epeken All Kurir Plugin epeken-all-kurir Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-32673 Patchstack
7.1 High Mergado Pack Plugin mergado-marketing-pack Cross-Site Request Forgery No login needed ≤ 4.2.1 CVE-2025-32669 Patchstack
6.8 Medium SEO Help Plugin seo-help Server-Side Request Forgery ≤ 6.7.9 CVE-2025-32675 Patchstack
5.4 Medium User Registration Using Contact Form 7 Plugin user-registration-using-contact-form-7 Cross-Site Request Forgery No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32679 Patchstack
4.3 Medium WP Show Stats Plugin wp-show-stats Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-32678 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.12.6 Fixed in 11.12.7 CVE-2025-32691 Patchstack
8.8 High WPFront User Role Editor Plugin wpfront-user-role-editor Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function No login needed ≤ 4.2.1 CVE-2025-3064 Wordfence
7.5 High Read More & Accordion Plugin expand-maker Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 3.4.7 CVE-2025-0810 Wordfence
5.4 Medium Rollbar Plugin rollbar Cross-Site Request Forgery No login needed ≤ 2.7.1 Fixed in 3.0.0 CVE-2025-32250 Patchstack
4.3 Medium WP Project Manager Plugin wedevs-project-manager Cross-Site Request Forgery No login needed ≤ 2.6.25 Fixed in 2.6.25 CVE-2025-32280 Patchstack
4.3 Medium Table Block by RioVizual Plugin riovizual Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-32278 Patchstack
4.3 Medium Administrator Z Plugin administrator-z Cross-Site Request Forgery No login needed ≤ 2026.03.02 CVE-2025-32276 Patchstack
4.3 Medium WP w3all phpBB Plugin wp-w3all-phpbb-integration Cross-Site Request Forgery No login needed ≤ 2.9.8 Fixed in 2.9.9 CVE-2025-32274 Patchstack
4.3 Medium Freetobook Responsive Widget Plugin freetobook-responsive-widget Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.1.1 CVE-2025-32273 Patchstack
4.3 Medium Wishlist Plugin wishlist Cross-Site Request Forgery No login needed ≤ 1.0.46 CVE-2025-32272 Patchstack
4.3 Medium Woocommerce Role Pricing Plugin woocommerce-role-pricing Cross-Site Request Forgery No login needed ≤ 3.5.6 CVE-2025-32271 Patchstack
4.3 Medium Broadstreet Ads Plugin broadstreet Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-32270 Patchstack
4.3 Medium WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32269 Patchstack
4.3 Medium QR Code Tag for WC Plugin qr-code-tag-for-wc-from-goaskle-com Cross-Site Request Forgery No login needed ≤ 1.9.42 CVE-2025-32268 Patchstack
4.3 Medium Post to Social Media – WordPress to Hootsuite Plugin wp-to-hootsuite Cross-Site Request Forgery No login needed ≤ 1.5.8 Fixed in 1.6.0 CVE-2025-32267 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only