WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 242 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Plugin aio-time-clock-lite Broken Access Control Tracking Employee Time Has Never Been Easier <= 2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/Out ≤ 2.0 CVE-2025-6833 Wordfence
4.9 Medium Email Tracker Plugin email-tracker SQL Injection Authenticated (Admin+) SQL Injection ≤ 5.3.15 CVE-2025-10047 Wordfence
5.5 Medium Interactive Medical Drawing of Human Body Plugin interactive-medical-drawing-of-human-body Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.6 CVE-2025-9332 Wordfence
7.1 High WP Attractive Donations System Plugin wp-attractive-donations-system-easy-stripe-paypal-donations Cross-Site Request Forgery No login needed ≤ 1.29 Fixed in 1.29 CVE-2025-58956 Patchstack
4.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Other Race Condition ≤ 3.6.20 Fixed in 3.6.21 CVE-2025-59577 Patchstack
5.9 Medium Goracash Plugin goracash Cross-Site Scripting ≤ 1.1 CVE-2025-53458 Patchstack
6.5 Medium Adverts Plugin adverts-click-tracker Cross-Site Scripting ≤ 1.4 CVE-2025-57911 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure No login needed ≤ 1.16.16 Fixed in 1.16.17 CVE-2025-58226 Patchstack
4.3 Medium Interact: Embed A Quiz On Your Site Plugin interact-quiz-embed Cross-Site Request Forgery No login needed ≤ 3.1 Fixed in 3.2 CVE-2025-58675 Patchstack
8.8 High Time Tracker Plugin time-tracker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Limited Data Deletion ≤ 3.1.0 CVE-2025-9018 Wordfence
9.3 Critical Miraculous Plugin miraculous SQL Injection No login needed ≤ 2.0.9 CVE-2025-58628 Patchstack
5.9 Medium Simple Matomo Tracking Code Plugin simple-matomo-tracking-code Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-58630 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Privilege Escalation No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-49388 Patchstack
5.9 Medium Goal Tracker for Patreon Plugin goal-tracker-for-patreon Cross-Site Scripting ≤ 0.4.6 CVE-2025-48305 Patchstack
5.3 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Broken Access Control No login needed ≤ 1.17.17 Fixed in 1.17.18 CVE-2025-58201 Patchstack
5.3 Medium myCred Plugin mycred Other Race Condition No login needed ≤ 2.9.4.3 Fixed in 2.9.4.4 CVE-2025-54667 Patchstack
6.1 Medium All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Plugin aio-time-clock-lite Cross-Site Scripting Tracking Employee Time Has Never Been Easier <= 2.0 - Reflected Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-6832 Wordfence
4.3 Medium Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship Plugin biteship Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details ≤ 3.2.0 CVE-2025-5816 Wordfence
7.1 High Track Everything Plugin track-everything Cross-Site Request Forgery No login needed ≤ 2.0.1 CVE-2025-53332 Patchstack
6.4 Medium FL3R Accessibility Suite Plugin fl3r-accessibility-suite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fl3raccessibilitysuite Shortcode ≤ 1.4 CVE-2025-6689 Wordfence
6.4 Medium WP SoundSystem Plugin wp-soundsystem Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpsstm-track Shortcode ≤ 3.4.2 CVE-2025-6258 Wordfence
6.4 Medium Tournament Bracket Generator Plugin tournament-bracket-generator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bracket Shortcode ≤ 1.0.0 CVE-2025-6290 Wordfence
6.4 Medium 3D FlipBook - Lite Edition Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting Lite Edition <= 1.16.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via style and mode Parameters ≤ 1.16.15 CVE-2025-5289 Wordfence
6.4 Medium Pixel Manager for WooCommerce (PRO) Plugin woocommerce-google-adwords-conversion-tracking-tag Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Shortcode ≤ 1.49.0 CVE-2025-6201 Wordfence
7.1 High Track, Analyze & Optimize by WP Tao Plugin wp-tao Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-48145 Patchstack
5.3 Medium Interactive Regional Map of Florida Plugin interactive-map-of-florida Broken Access Control No login needed ≤ 1.0 CVE-2025-49441 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
6.1 Medium Affiliate Sales in Google Analytics and other tools Plugin wecantrack Open Redirect No login needed ≤ 2.0.0 CVE-2024-12561 Wordfence
5.3 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary Shortcode Execution No login needed ≤ 8.6.9 Fixed in 8.6.10 CVE-2025-48120 Patchstack
5.3 Medium User Activity Tracking and Log Plugin user-activity-tracking-and-log Authentication Bypass IP Spoofing No login needed < 4.1.4 Fixed in 4.1.4 CVE-2024-0970 WPScan
4.8 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting Tracking Code Manager < 2.3.0- Admin+ Stored Cross-Site Scripting < 2.3.0 Fixed in 2.3.0 CVE-2024-6335 WPScan
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Privilege Escalation WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function ≤ 3.8.1 CVE-2025-3876 Wordfence
6.5 Medium Spiraclethemes Site Library Plugin spiraclethemes-site-library Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-47656 Patchstack
4.3 Medium Awin – Advertiser Tracking for WooCommerce Plugin awin-advertiser-tracking Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-47633 Patchstack
5.9 Medium Submission DOM tracking for Contact Form 7 Plugin cf7-submission-dom-tracking Cross-Site Scripting ≤ 2.1 Fixed in 2.2 CVE-2025-47626 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Other Race Condition No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2025-47545 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High TrackShip for WooCommerce Plugin trackship-for-woocommerce SQL Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47460 Patchstack
7.2 High boot-store Theme boot-store Cross-Site Scripting The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. No login needed 1.6.4 CVE-2015-4582 mitre
8.8 High Integração entre Eduzz e Woocommerce Plugin integracao-entre-eduzz-e-wc-powers Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.7.5 CVE-2025-3906 Wordfence
7.5 High Grace Mag Plugin grace-mag Local File Inclusion No login needed ≤ 1.1.5 CVE-2025-39360 Patchstack
7.1 High Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.23 Fixed in 1.4.23.1 CVE-2025-24586 Patchstack
7.1 High Shipmozo Courier Tracking Plugin webparex Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-27293 Patchstack
7.1 High 17TRACK for WooCommerce Plugin 17track Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 CVE-2025-27324 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32682 Patchstack
7.1 High Simple Maps Plugin interactive-maps Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.98 Fixed in 0.99 CVE-2025-39424 Patchstack
4.3 Medium Basic Interactive World Map Plugin basic-interactive-world-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.7 CVE-2025-39517 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.24 Fixed in 1.6.25 CVE-2025-32525 Patchstack
9.3 Critical WPSmartContracts Plugin wp-smart-contracts SQL Injection No login needed ≤ 2.0.12 CVE-2025-31565 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only