WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,401–1,450 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 29 of 52
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Fyrebox Quizzes Plugin fyrebox-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.1 CVE-2025-25125 Patchstack
7.1 High Easy Related Posts Plugin easy-related-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.2 CVE-2025-25123 Patchstack
4.3 Medium Indeed API Plugin indeed-api Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.5 CVE-2025-25103 Patchstack
9.6 Critical Munk Sites Plugin munk-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.0.7 CVE-2025-25101 Patchstack
9.6 Critical OneStore Sites Plugin onestore-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 0.1.1 CVE-2025-25107 Patchstack
9.6 Critical Starter Templates by FancyWP Plugin starter-templates Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.0.0 CVE-2025-25106 Patchstack
7.1 High WP Keyword Monitor Plugin wp-keyword-monitor Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-25088 Patchstack
5.4 Medium WP Spell Check Plugin wp-spell-check Cross-Site Request Forgery No login needed ≤ 9.21 Fixed in 9.22 CVE-2025-25111 Patchstack
7.1 High URL-Preview-Box Plugin good-url-preview-box Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.20 CVE-2025-25104 Patchstack
6.1 Medium Child Themes Helper Plugin child-themes-helper Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.2.7 CVE-2025-25093 Patchstack
7.1 High Vignette Ads Plugin vignete-ads Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2 CVE-2025-25071 Patchstack
7.1 High Show notice or message on admin area Plugin show-notice-or-message-on-admin-area Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-25075 Patchstack
7.1 High WP Social Stream Plugin wp-social-stream Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-25074 Patchstack
7.1 High WP Admin Custom Page Plugin wp-admin-custom-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.0 CVE-2025-25072 Patchstack
4.7 Medium LikeBot – Decentralized like-system Plugin Cross-Site Scripting Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF No login needed ≤ 0.85 CVE-2025-0522 WPScan
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 3.0 CVE-2024-13115 WPScan
7.1 High Forge – Front-End Page Builder Plugin forge Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-22703 Patchstack
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
7.1 High DigiTimber cPanel Integration Plugin digitimber-cpanel-integration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.6 Fixed in 1.4.8 CVE-2025-22690 Patchstack
7.1 High Unlimited Page Sidebars Plugin unlimited-page-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.6 Fixed in 0.2.7 CVE-2025-22688 Patchstack
7.1 High Tags to Keywords Plugin tags-to-meta-keywords Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-22685 Patchstack
6.5 Medium Powerful Auto Chat Plugin powers-triggers-of-woo-to-chat Cross-Site Scripting ≤ 1.9.8 CVE-2025-22292 Patchstack
4.6 Medium WP Finance Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.3.6 CVE-2024-13096 WPScan
7.1 High EZPZ SAML SP Single Sign On (SSO) Plugin ezpz-sp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-24749 Patchstack
7.1 High Scroll Styler Plugin scroll-styler Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23990 Patchstack
7.1 High Internal Link Builder Plugin internal-link-builder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23989 Patchstack
5.4 Medium Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23985 Patchstack
7.1 High Full Circle Plugin full-circle Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.5.7.8 CVE-2025-23980 Patchstack
7.1 High FlashCounter Plugin flashcounter Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.8 CVE-2025-23978 Patchstack
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
7.1 High Issuu Panel Plugin issuu-panel Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-23976 Patchstack
5.4 Medium Oshine Modules Plugin oshine-modules Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44055 Patchstack
4.3 Medium Bulk Me Now Plugin Cross-Site Request Forgery Message Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12709 WPScan
7.1 High Fare Calculator Plugin fare-calculator Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-23982 Patchstack
4.3 Medium WP Go Maps Plugin wp-google-maps Cross-Site Request Forgery No login needed ≤ 9.0.40 Fixed in 9.0.41 CVE-2025-24742 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.7.0 Fixed in 6.7.1 CVE-2025-24537 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-13057 WPScan
6.5 Medium Altra Side Menu Plugin Cross-Site Request Forgery Abitrary Menu Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12774 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Bulk Delete via CSRF No login needed ≤ 8.2.4 CVE-2024-12436 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Event Log Deletion via CSRF No login needed ≤ 8.2.4 CVE-2024-12280 WPScan
7.1 High Roi Calculator Plugin roi-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24756 Patchstack
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
4.3 Medium FluentSMTP Plugin fluent-smtp Cross-Site Request Forgery No login needed ≤ 2.2.80 Fixed in 2.2.81 CVE-2025-24739 Patchstack
5.4 Medium Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-24724 Patchstack
5.4 Medium Herd Effects Plugin mwp-herd-effect Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-24716 Patchstack
5.4 Medium Modal Window Plugin modal-window Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.4 Fixed in 6.1.5 CVE-2025-24717 Patchstack
4.4 Medium Comment Edit Core – Simple Comment Editing Plugin simple-comment-editing Server-Side Request Forgery Simple Comment Editing Plugin <= 3.0.33 - Server Side Request Forgery (SSRF) ≤ 3.0.33 Fixed in 3.1.0 CVE-2025-24703 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only