WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 101–150 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 7
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High SurveyJS: Drag & Drop Form Builder Plugin surveyjs Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.5.3 CVE-2026-2440 Wordfence
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-53222 Patchstack
7.5 High WowStore – Store Builder & Product Blocks for WooCommerce Plugin product-blocks SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed ≤ 4.4.3 CVE-2026-2579 Wordfence
7.5 High NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id No login needed ≤ 9.1.9 CVE-2026-1947 Wordfence
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
8.8 High Page Builder by SiteOrigin Plugin siteorigin-panels Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 2.33.5 CVE-2026-2448 Wordfence
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
7.1 High Business Template Blocks for WPBakery (Visual Composer) Page Builder Plugin templates-and-addons-for-wpbakery-page-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-69390 Patchstack
8.1 High Portfolio Builder Plugin swp-portfolio Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69375 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69326 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69324 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
8.1 High Extensive VC Addons for WPBakery page builder Plugin extensive-vc-addon Local File Inclusion No login needed ≤ 1.9.1 CVE-2025-60087 Patchstack
7.6 High AIO WP Builder Plugin all-in-one-wp-builder Broken Access Control ≤ 2.0.2 CVE-2025-53217 Patchstack
7.5 High Product Table and List Builder for WooCommerce Lite Plugin wc-product-table-lite SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed ≤ 4.6.2 CVE-2026-2232 Wordfence
8.8 High Custom Block Builder – Lazy Blocks Plugin lazy-blocks Remote Code Execution Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution ≤ 4.2.0 CVE-2026-1560 Wordfence
8.2 High Popup builder with Gamification Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed ≤ 2.2.0 CVE-2025-13192 Wordfence
7.5 High Beaver Builder Plugin beaver-builder-lite-version Remote Code Execution Arbitrary Code Execution ≤ 2.9.4.1 Fixed in 2.9.4.2 CVE-2025-69319 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
7.1 High DASHBOARD BUILDER Plugin dashboard-builder Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed ≤ 1.5.7 CVE-2025-14615 Wordfence
7.1 High Taskbuilder Plugin taskbuilder Cross-Site Scripting No login needed ≤ 4.0.9 Fixed in 5.0.0 CVE-2025-67933 Patchstack
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
8.5 High Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) Plugin azon-addon-js-composer SQL Injection ≤ 1.2 CVE-2025-30628 Patchstack
7.5 High Knowband Mobile App Builder for wooCommerce Plugin Broken Access Control Unauthenticated Arbitrary User Deletion No login needed < 3.0.0 Fixed in 3.0.0 CVE-2025-13029 WPScan
8.1 High Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update ≤ 2.9.4.1 CVE-2025-12934 Wordfence
7.5 High Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode ≤ 2.0.2 CVE-2025-14071 Wordfence
8.8 High PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60084 Patchstack
8.8 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60083 Patchstack
7.5 High PDF for Gravity Forms + Drag And Drop Template Builder Plugin pdf-for-gravity-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60080 Patchstack
8.5 High PopupKit Plugin popup-builder-block SQL Injection ≤ 2.1.5 Fixed in 2.2.0 CVE-2025-14314 Patchstack
7.5 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Broken Access Control The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token No login needed ≤ 3.13.2 CVE-2025-11924 Wordfence
8.1 High Extensive VC Addons for WPBakery page builder Plugin extensive-vc-addon Local File Inclusion Unauthenticated Local File Inclusion via 'shortcode_name' Parameter No login needed ≤ 1.9.1 CVE-2025-14475 Wordfence
7.5 High FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder SQL Injection Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection No login needed ≤ 3.13.1.5 CVE-2025-14169 Wordfence
8.8 High Cost Calculator Builder Plugin cost-calculator-builder Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.6.3 CVE-2025-12529 Wordfence
7.1 High Flo Forms – Easy Drag & Drop Form Builder Plugin flo-forms Cross-Site Scripting Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG Upload No login needed ≤ 1.0.43 CVE-2025-13159 Wordfence
7.1 High Pricing Table builder Plugin wpdevart-pricing-table Cross-Site Request Forgery No login needed ≤ 1.5.3 CVE-2025-62886 Patchstack
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.1.4 CVE-2025-10861 Wordfence
7.2 High 10WebMapBuilder Plugin wd-google-maps Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change No login needed < 1.0.64 Fixed in 1.0.64 CVE-2020-36853 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
7.2 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection ≤ 6.0.6.2 CVE-2025-11204 Wordfence
8.1 High Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Authenticated (Subscriber+) Missing Authorization via get_cc_orders/update_order_status Functions ≤ 3.5.32 CVE-2025-9243 Wordfence
8.8 High TextBuilder Plugin textbuilder Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Account Takeover No login needed 1.0.0 – 1.1.1 CVE-2025-9213 Wordfence
7.7 High BM Content Builder Plugin bm-builder Arbitrary File Deletion ≤ 3.16.3.3 Fixed in 3.16.3.3 CVE-2025-59002 Patchstack
8.0 High User Meta – User Profile Builder and User management Plugin user-meta Arbitrary File Deletion User Profile Builder and User management plugin <= 3.1.2 - Authenticated (Subscriber+) Arbitrary File Deletion ≤ 3.1.2 CVE-2025-9693 Wordfence
8.8 High Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Request Forgery Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Command Injection No login needed ≤ 2.7.6 CVE-2025-7812 Wordfence
8.8 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Request Forgery No login needed ≤ 9.1.3 Fixed in 9.1.4 CVE-2025-49399 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-48154 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg-universal-video-player-addon-visual-composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-48170 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg-universal-video-player-addon-visual-composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-53559 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg_universal_video_player_addon_visual_composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-53562 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only