WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 345 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Porto Theme - Functionality Plugin porto-functionality Broken Access Control Functionality plugin < 3.7.3 - Broken Access Control ≤ 3.7.3 Fixed in 3.7.3 CVE-2025-63067 Patchstack
6.5 Medium Porto Theme - Functionality Plugin porto-functionality Cross-Site Scripting Functionality plugin < 3.7.3 - Cross Site Scripting (XSS) ≤ 3.7.3 Fixed in 3.7.3 CVE-2025-63066 Patchstack
5.3 Medium IDonate Plugin idonate Broken Access Control No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-67583 Patchstack
6.5 Medium Donation Thermometer Plugin donation-thermometer Cross-Site Scripting ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-67550 Patchstack
6.1 Medium WP-SOS-Donate Donation Sidebar Plugin wp-sos-donate Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.9.2 CVE-2025-13625 Wordfence
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' ≤ 1.3.7.2 CVE-2025-13109 Wordfence
4.1 Medium Donation Plugin SQL Injection Admin+ SQLi ≤ 1.0 CVE-2025-13001 WPScan
4.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages ≤ 14 CVE-2025-13452 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
5.3 Medium IDonate – Blood Donation, Request And Donor Management System Plugin idonate Broken Access Control Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 2.1.14 CVE-2025-12877 Wordfence
7.2 High GiveWP - Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name' No login needed ≤ 4.13.0 CVE-2025-13206 Wordfence
8.8 High Import any XML, CSV or Excel File to WordPress (WP All Import) Plugin wp-all-import Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Conditional Logic ≤ 3.9.6 CVE-2025-12733 Wordfence
6.4 Medium Simple Donate Plugin simple-donate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11882 Wordfence
6.4 Medium Paypal Donation Shortcode Plugin paypal-donation-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11859 Wordfence
4.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.0.0 CVE-2025-12020 Wordfence
6.4 Medium Nonaki – Drag and Drop Email Template builder and Newsletter Plugin nonaki-email-template-customizer Cross-Site Scripting Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields ≤ 1.0.11 CVE-2025-12644 Wordfence
6.4 Medium Saphali LiqPay for donate Plugin saphali-liqpay-for-donate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.2 CVE-2025-12643 Wordfence
6.5 Medium IDonate Plugin idonate Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function 2.0.0 – 2.1.9 CVE-2025-4522 Wordfence
8.8 High IDonate Plugin idonate Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function 2.1.5 – 2.1.9 CVE-2025-4519 Wordfence
7.1 High Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62057 Patchstack
7.5 High HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter No login needed ≤ 1.3.7.1 CVE-2025-11735 Wordfence
5.4 Medium IDonate Plugin idonate Cross-Site Request Forgery Unauthenticated User Deletion < 2.1.13 Fixed in 2.1.13 CVE-2025-11154 WPScan
6.5 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable SQL Injection Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection ≤ 1.8.8.4 CVE-2025-11893 Wordfence
6.5 Medium Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62058 Patchstack
7.5 High Houzez Theme - Functionality Plugin houzez-theme-functionality Local File Inclusion Functionality plugin <= 4.1.8 - Local File Inclusion ≤ 4.1.8 Fixed in 4.2.0 CVE-2025-62054 Patchstack
6.5 Medium IDonatePro Plugin idonate-pro Information Disclosure Sensitive Data Exposure ≤ 2.1.9 CVE-2025-52752 Patchstack
5.3 Medium Whydonate Plugin wp-whydonate Broken Access Control No login needed ≤ 4.0.15 Fixed in 4.0.16 CVE-2025-49899 Patchstack
7.1 High Terms Dictionary Plugin terms-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-39534 Patchstack
5.3 Medium WhyDonate – FREE Donate button – Crowdfunding – Fundraising Plugin wp-whydonate Broken Access Control FREE Donate button – Crowdfunding – Fundraising <= 4.0.15 - Missing Authorization to Unauthenticated wp_wdplugin_style Rww Deletion No login needed ≤ 4.0.15 CVE-2025-10186 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association No login needed ≤ 4.10.0 CVE-2025-11228 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure No login needed ≤ 4.10.0 CVE-2025-11227 Wordfence
4.3 Medium Professional Contact Form Plugin professional-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Test Email Sending No login needed ≤ 1.0.0 CVE-2025-9944 Wordfence
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High WP Attractive Donations System Plugin wp-attractive-donations-system-easy-stripe-paypal-donations Cross-Site Request Forgery No login needed ≤ 1.29 Fixed in 1.29 CVE-2025-58956 Patchstack
5.9 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-57903 Patchstack
5.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57929 Patchstack
4.3 Medium Double the Donation Plugin double-the-donation Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57930 Patchstack
4.9 Medium Coupon API Plugin couponapi SQL Injection Authenticated (Administrator+) SQL Injection via 'log_duration' ≤ 6.2.12 CVE-2025-8692 Wordfence
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-58985 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting ≤ 1.9.4 Fixed in 1.9.4.1 CVE-2025-58602 Patchstack
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
6.5 Medium Simple Download Monitor Plugin simple-download-monitor SQL Injection Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality ≤ 3.9.33 CVE-2025-8977 Wordfence
5.4 Medium Pronamic Google Maps Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2025-9352 Wordfence
5.9 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-57891 Patchstack
4.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update ≤ 4.5.0 CVE-2025-7221 Wordfence
7.5 High FundEngine Plugin wp-fundraising-donation Local File Inclusion ≤ 1.7.4 Fixed in 1.7.5 CVE-2025-48302 Patchstack
9.9 Critical ReachShip WooCommerce Multi-Carrier & Conditional Shipping Plugin elex-reachship-multi-carrier-conditional-shipping Arbitrary File Upload ≤ 4.3.1 Fixed in 4.3.2 CVE-2025-53213 Patchstack
6.1 Medium Linux Promotional Plugin linux-promotional-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.4 CVE-2025-7668 Wordfence
8.1 High IDonatePro Plugin idonate-pro Local File Inclusion No login needed ≤ 2.1.9 CVE-2025-30635 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only