WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 269 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Cross-Site Scripting LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) ≤ 1.18.3 Fixed in 1.18.4 CVE-2025-54699 Patchstack
6.5 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30993 Patchstack
6.4 Medium Appzend Theme appzend Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.2.6 CVE-2025-5587 Wordfence
6.4 Medium YouTube Embed Plugin youram-youtube-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via instance Parameter ≤ 10.3 CVE-2025-6692 Wordfence
6.4 Medium StreamWeasels YouTube Integration Plugin streamweasels-youtube-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.0 CVE-2025-7811 Wordfence
6.4 Medium Get Youtube Subs Plugin get-youtube-subs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via subscribe_link_att Function ≤ 3.5 CVE-2025-7966 Wordfence
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
6.5 Medium Profiler - What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed ≤ 1.0.0 CVE-2025-48339 Patchstack
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
4.3 Medium WP YouTube Live Plugin wp-youtube-live Cross-Site Request Forgery No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-53261 Patchstack
6.4 Medium kk Youtube Video Plugin kk-youtube-video Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2 CVE-2025-6061 Wordfence
4.3 Medium Yougler Blogger Profile Page Plugin yougler-blogger-profile-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ v1.01 CVE-2025-6062 Wordfence
5.3 Medium Profiler – What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Missing Authentication to Unauthenticated Arbitrary Plugin Reactivation via State Restoration No login needed ≤ 1.0.0 CVE-2025-5814 Wordfence
6.5 Medium YouTube Simple Gallery Plugin youtube-simple-gallery Cross-Site Scripting ≤ 2.2.0 CVE-2025-29011 Patchstack
4.3 Medium Layouts for Elementor Plugin layouts-for-elementor Cross-Site Request Forgery No login needed ≤ 1.11 CVE-2025-30948 Patchstack
6.4 Medium WP YouTube Video Optimizer Plugin wp-youtube-video-optimizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2025-4217 Wordfence
5.3 Medium Masteriyo - LMS Plugin learning-management-system Authentication Bypass Broken Authentication No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-33939 Patchstack
4.8 Medium Travelpayouts Plugin travelpayouts Cross-Site Scripting Reflected XSS < 1.1.14 Fixed in 1.1.14 CVE-2023-5932 WPScan
5.9 Medium Color Your Bar Plugin color-your-bar Cross-Site Scripting ≤ 2.0 CVE-2025-47595 Patchstack
5.9 Medium COVID-19 (Coronavirus) Update Your Customers Plugin covid-19-alert Cross-Site Scripting ≤ 1.5.1 CVE-2025-46523 Patchstack
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
6.5 Medium DSGVO Youtube Plugin dsgvo-youtube Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-26982 Patchstack
5.9 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4 CVE-2025-31008 Patchstack
5.3 Medium WP Genealogy – Your Family History Website Plugin wpgenealogy Broken Access Control No login needed ≤ 0.1.9 CVE-2025-32252 Patchstack
6.5 Medium Video Playlist For YouTube Plugin video-playlist-for-youtube Cross-Site Scripting ≤ 6.7.1 CVE-2025-32183 Patchstack
6.5 Medium Planyo online reservation system Plugin planyo-online-reservation-system Cross-Site Scripting ≤ 3.1 CVE-2025-31811 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31744 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31743 Patchstack
6.5 Medium YouTube SimpleGallery Plugin youtube-simplegallery Cross-Site Scripting ≤ 2.0.6 CVE-2025-31453 Patchstack
6.4 Medium Your Simple SVG Support Plugin your-simple-svg-support Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.1 CVE-2025-2542 Wordfence
4.7 Medium CryoKey Plugin cryokey Cross-Site Scripting Reflected Cross-Site Scripting via 'ckemail' Parameter No login needed ≤ 2.4 CVE-2025-2477 Wordfence
5.3 Medium VidoRev Extensions Plugin Broken Access Control Missing Authorization to Unauthenticated Youtube Video Import No login needed ≤ 2.9.9.9.9.9.5 CVE-2025-0955 Wordfence
4.4 Medium Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site Plugin counter-box Cross-Site Scripting Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-13901 Wordfence
6.3 Medium PixelYourSite Plugin pixelyoursite PHP Object Injection Insecure deserialization No login needed 10.1.1.1 CVE-2025-0769 Fluid Attacks
4.3 Medium NextMove Lite – Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission ≤ 2.19.0 CVE-2024-10860 Wordfence
6.4 Medium YouTube Playlists with Schema Plugin jma-youtube-playlists-with-schema Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13589 Wordfence
6.4 Medium Web Stories Enhancer – Level Up Your Web Stories Plugin web-stories-enhancer Cross-Site Scripting Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13575 Wordfence
6.1 Medium magayo Lottery Results Plugin magayo-lottery-results Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0.12 CVE-2024-13522 Wordfence
5.9 Medium Elfsight Yottie Lite Plugin yottie-lite Cross-Site Scripting ≤ 1.3.3 CVE-2025-26561 Patchstack
4.3 Medium Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time Plugin builder-shortcode-extras Information Disclosure WordPress Shortcodes Collection to Save You Time <= 1.0.0 - Authenticated (Contributor+) Post Disclosure ≤ 1.0.0 CVE-2024-13841 Wordfence
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
6.5 Medium Demo User DZS Plugin demo-user-dzs-showcase-your-admin-safely Cross-Site Scripting ≤ 1.1.0 CVE-2025-23581 Patchstack
6.4 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.8.24 CVE-2024-13470 Wordfence
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only