WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 404 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Kayon Theme kayon Local File Inclusion No login needed ≤ 1.3 CVE-2026-28027 Patchstack
8.1 High Yottis Theme yottis Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-28011 Patchstack
7.1 High PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) No login needed ≤ 11.2.0.1 Fixed in 11.2.0.2 CVE-2026-27072 Patchstack
8.1 High Yokoo Theme yokoo Local File Inclusion No login needed ≤ 1.1.11 CVE-2025-69400 Patchstack
7.5 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2025-68048 Patchstack
6.5 Medium Travelpayouts Plugin travelpayouts Broken Access Control ≤ 1.2.2 CVE-2025-68042 Patchstack
4.3 Medium Serious Slider Plugin cryout-serious-slider Broken Access Control ≤ 1.2.7 Fixed in 1.3.0 CVE-2026-25399 Patchstack
6.4 Medium Ravelry Designs Widget Plugin ravelry-designs-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sb_ravelry_designs' Shortcode 'layout' Attribute ≤ 1.0.0 CVE-2026-1903 Wordfence
7.2 High PixelYourSite Plugin pixelyoursite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 11.2.0 CVE-2026-1841 Wordfence
7.2 High PixelYourSite PRO Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 12.4.0.2 CVE-2026-1844 Wordfence
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute ≤ 26.8 CVE-2026-1293 Wordfence
4.3 Medium WP Youtube Video Gallery Plugin wp-youtube-video-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0 CVE-2025-14906 Wordfence
5.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2026-24599 Patchstack
6.5 Medium Turn Yoast SEO FAQ Block to Accordion Plugin faq-schema-block-to-accordion Cross-Site Scripting ≤ 1.0.6 CVE-2026-24591 Patchstack
8.1 High Yolox Theme yolox Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-69075 Patchstack
8.1 High Hyori Plugin hyori Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69038 Patchstack
8.1 High Myour Plugin myour Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-67615 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
5.3 Medium Custom Fonts – Host Your Fonts Locally Plugin custom-fonts Broken Access Control Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion No login needed ≤ 2.1.16 CVE-2025-14351 Wordfence
5.9 Medium Feeds for YouTube Pro Plugin feeds-for-youtube Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed ≤ 2.6.0 CVE-2025-12002 Wordfence
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
7.5 High Yoco Payments Plugin yoco-payment-gateway Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 3.9.0 CVE-2025-13801 Wordfence
7.1 High Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin yournewsapp Cross-Site Scripting Your native, mobile iPhone App and Android App Plugin <= 0.8.8.8 - Cross Site Scripting (XSS) No login needed ≤ 0.8.8.8 CVE-2025-50053 Patchstack
4.9 Medium Youzify Plugin youzify Server-Side Request Forgery ≤ 1.3.7 CVE-2025-69014 Patchstack
5.3 Medium PixelYourSite Plugin pixelyoursite Information Disclosure Sensitive Information Exposure via Log File No login needed ≤ 11.1.5 CVE-2025-14280 Wordfence
6.5 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.4 CVE-2025-68599 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
7.5 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Broken Access Control The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token No login needed ≤ 3.13.2 CVE-2025-11924 Wordfence
6.5 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Broken Access Control Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification No login needed ≤ 4.0.1 CVE-2025-13880 Wordfence
5.3 Medium Feeds for YouTube Plugin feeds-for-youtube Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.6.1 CVE-2025-64635 Patchstack
6.4 Medium Kingcabs Theme kingcabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.1.9 CVE-2025-7058 Wordfence
6.4 Medium Ayo Shortcodes Plugin ayo-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute ≤ 0.2 CVE-2025-14143 Wordfence
5.8 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 5.1.1 CVE-2025-11467 Wordfence
4.3 Medium Custom Layouts – Post + Product grids made easy Plugin custom-layouts Broken Access Control Post + Product grids made easy plugin <= 1.4.12 - Broken Access Control ≤ 1.4.12 Fixed in 1.5.0 CVE-2025-62996 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Backup, Restore and Migrate your sites with XCloner Plugin xcloner-backup-and-restore Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed ≤ 4.8.2 CVE-2025-11759 Wordfence
6.1 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Cross-Site Scripting Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import No login needed ≤ 3.20.3 CVE-2025-13007 Wordfence
4.4 Medium YouTube Subscribe Plugin easy-youtube-subscribe Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Title and Channel ID ≤ 3.0.0 CVE-2025-12025 Wordfence
3.4 Low WP YouTube Lyte Plugin wp-youtube-lyte Open Redirect No login needed ≤ 1.7.28 Fixed in 1.7.29 CVE-2025-66062 Patchstack
6.5 Medium ACF Flexible Layouts Manager Plugin acf-flexible-layouts-manager Broken Access Control Missing Authorization to Unauthenticated Custom Field Update No login needed ≤ 1.1.6 CVE-2025-12937 Wordfence
5.3 Medium YOP Poll Plugin yop-poll Broken Access Control No login needed ≤ 6.5.38 Fixed in 6.5.39 CVE-2025-64370 Patchstack
4.3 Medium Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed Plugin quicq Broken Access Control Missing Authorization to Authenticated (Subscriber+) Afosto Disconnect ≤ 2.0.0 CVE-2025-12015 Wordfence
7.1 High YOP Poll Plugin yop-poll Cross-Site Scripting No login needed ≤ 6.5.37 Fixed in 6.5.38 CVE-2025-62040 Patchstack
8.8 High Yogi - Health Beauty & Yoga Plugin noo-yogi PHP Object Injection Health Beauty & Yoga Theme <= 2.9.2 - Deserialization of untrusted data ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-54719 Patchstack
7.1 High Yogi - Health Beauty & Yoga Plugin noo-yogi Cross-Site Scripting Health Beauty & Yoga theme <= 2.9.2 - Cross Site Scripting (XSS) No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-54718 Patchstack
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Broken Access Control Unauthenticated Price Alteration No login needed ≤ 2.1.9 CVE-2025-12115 Wordfence
6.5 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting ≤ 2.23.0 Fixed in 2.24.0 CVE-2025-62969 Patchstack
2.7 Low PixelYourSite Plugin pixelyoursite Local File Inclusion Admin+ LFI < 11.1.2 Fixed in 11.1.2 CVE-2025-10723 WPScan
7.1 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting No login needed ≤ 2.24.0 CVE-2025-52735 Patchstack
6.4 Medium Simple Youtube Shortcode Plugin simple-youtube-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.3 CVE-2025-11811 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only