WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,301–1,350 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 52
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High TabGarb Pro Plugin tabgarb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6 CVE-2025-28900 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High List of Posts from each Category Plugin list-posts-by-category Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28894 Patchstack
7.1 High FTP Sync Plugin ftp-sync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.6 CVE-2025-28892 Patchstack
7.1 High price-calc Plugin price-calc Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6.3 CVE-2025-28891 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
7.1 High WP Compare Tables Plugin wp-compare-tables Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-28883 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
7.1 High WP jQuery Persian Datepicker Plugin wpjqp-datepicker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0 CVE-2025-28861 Patchstack
7.1 High Google News Editors Picks Feed Generator Plugin google-news-editors-picks-news-feeds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-28860 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack
7.1 High Rankchecker.io Integration Plugin rankchecker-io-integration Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28857 Patchstack
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
4.3 Medium XV Random Quotes Plugin xv-random-quotes Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 1.40 CVE-2024-13580 WPScan
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.1 Medium Contact Us By Lord Linus Plugin Cross-Site Scripting Admin+ Stored XSS via CSRF No login needed ≤ 2.6 CVE-2025-1382 WPScan
4.3 Medium easy-broken-link-checker Plugin Cross-Site Request Forgery Bulk Actions via CSRF ≤ 9.0.2 CVE-2025-1362 WPScan
5.4 Medium Email Keep Plugin Cross-Site Request Forgery Email Deletion via CSRF ≤ 1.1 CVE-2024-13826 WPScan
7.1 High WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.3.1 CVE-2025-25161 Patchstack
5.4 Medium Theme Options Z Plugin theme-options-z Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-25121 Patchstack
7.1 High Curated Search Plugin curated-search Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23502 Patchstack
7.1 High WP SpaceContent Plugin wp-spacecontent Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.4.5 CVE-2025-23446 Patchstack
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
7.1 High 无觅相关文章插件 Plugin wumii-related-posts Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.5.7 CVE-2025-27352 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
7.1 High Smart Maintenance & Countdown Plugin smart-maintenance-countdown Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-27332 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
7.1 High Blightly Explorer Plugin blighty-explorer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.0 CVE-2025-27321 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only