WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 275 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Peadig’s Google +1 Button Plugin google-1 Cross-Site Scripting ≤ 0.1.2 CVE-2025-46483 Patchstack
7.1 High WP Twitter Button Plugin wp-twitter-button Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-39420 Patchstack
7.1 High WP Sticky Side Buttons Plugin wp-sticky-side-buttons Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-39421 Patchstack
5.9 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting ≤ 9.8.3 Fixed in 9.8.4 CVE-2025-39444 Patchstack
4.8 Medium Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Scripting Admin+ Stored XSS < 6.0.0 Fixed in 6.0.0 CVE-2024-13610 WPScan
4.3 Medium Social Share Buttons & Analytics Plugin – GetSocial.io Plugin wp-share-buttons-analytics-by-getsocial Broken Access Control ≤ 4.5 CVE-2025-32239 Patchstack
5.9 Medium Beam me up Scotty Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) ≤ 1.0.23 CVE-2025-31864 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
6.1 Medium Razorpay Subscription Button Elementor Plugin razorpay-subscription-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed ≤ 1.0.3 CVE-2024-13827 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
6.4 Medium Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Plugin chaty Cross-Site Scripting Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.3.5 CVE-2025-1450 Wordfence
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
6.5 Medium Hover Image Button Plugin hover-image-button Cross-Site Scripting ≤ 1.1.2 CVE-2025-27266 Patchstack
4.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Cross-Site Request Forgery Cross-Site Request Forgery to Custom CSS Update No login needed ≤ 3.51 CVE-2024-13883 Wordfence
6.4 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting Get Paid with PayPal, Square & Stripe <= 3.20.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.0 CVE-2024-11895 Wordfence
5.5 Medium Reaction Buttons Plugin reaction-buttons Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.1.6 CVE-2024-13848 Wordfence
7.1 High Page/Post Specific Social Share Buttons Plugin pagepost-specific-social-share-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26580 Patchstack
7.1 High On Page SEO + Whatsapp Chat Button Plugin ops-robots-txt Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-25138 Patchstack
7.1 High Radio Buttons and Swatches for WooCommerce Plugin variations-radio-buttons-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-24551 Patchstack
4.8 Medium Social Share Buttons Plugin share-button Cross-Site Scripting Admin+ Stored XSS ≤ 2.7 CVE-2024-12807 WPScan
6.5 Medium Social Share Buttons Plugin share-button Path Traversal Unauthenticated Image Upload & Path Traversal No login needed ≤ 2.7 CVE-2024-13117 WPScan
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
7.1 High Sticky Button Plugin sticky-chat-button Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23839 Patchstack
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.1 High Pootle button Plugin pootle-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-23758 Patchstack
6.5 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting ≤ 3.20.0 Fixed in 3.30.0 CVE-2025-22661 Patchstack
6.4 Medium FireCask Like & Share Button Plugin facebook-like-send-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 1.2 CVE-2024-11226 Wordfence
6.4 Medium Payment Button for PayPal Plugin wp-paypal Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3.35 CVE-2024-13401 Wordfence
6.5 Medium Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Scripting ≤ 2.3 CVE-2025-23897 Patchstack
7.1 High Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3 CVE-2025-23898 Patchstack
6.5 Medium Easy Shortcode Buttons Plugin easy-shortcode-buttons Cross-Site Scripting ≤ 1.2 CVE-2025-23825 Patchstack
7.1 High ECT Add to Cart Button Plugin ect-add-to-cart-button Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23471 Patchstack
4.3 Medium Button Block Plugin button-block Broken Access Control ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-22787 Patchstack
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link ≤ 3.4.2 CVE-2024-12304 Wordfence
6.5 Medium Button Block Plugin button-block Cross-Site Scripting ≤ 1.1.9 Fixed in 1.2.0 CVE-2025-22815 Patchstack
4.3 Medium Social Media Share Buttons | MashShare Plugin mashsharer Broken Access Control ≤ 4.0.47 CVE-2025-22319 Patchstack
6.5 Medium mcjh button shortcode Plugin mcjh-button-shortcode Cross-Site Scripting ≤ 1.6.4 CVE-2025-22558 Patchstack
6.5 Medium ICS Button Plugin ics-button Cross-Site Scripting ≤ 0.6 CVE-2025-22574 Patchstack
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
5.3 Medium Floating Action Buttons Plugin floating-action-buttons Broken Access Control No login needed ≤ 0.9.1 Fixed in 1.0.1 CVE-2024-56238 Patchstack
6.5 Medium SvegliaT Buttons Plugin svegliat-buttons Cross-Site Scripting ≤ 1.3.0 CVE-2024-56020 Patchstack
6.4 Medium Spoki – Chat Buttons and WooCommerce Notifications Plugin spoki Cross-Site Scripting Chat Buttons and WooCommerce Notifications <= 2.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.15.15 CVE-2024-11893 Wordfence
4.7 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting Admin+ Stored XSS via Text Color No login needed < 9.8.1 Fixed in 9.8.1 CVE-2024-8968 WPScan
4.8 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting Admin+ Stored XSS via Button Width < 9.8.1 Fixed in 9.8.1 CVE-2024-10555 WPScan
4.3 Medium Button Block – Get fully customizable & multi-functional buttons Plugin button-block Information Disclosure Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication ≤ 1.1.5 CVE-2024-12560 Wordfence
7.1 High Bootstrap Buttons Plugin bootstrap-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49677 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only