WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,451–1,500 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
4.3 Medium Super Static Cache Plugin super-static-cache Cross-Site Request Forgery No login needed ≤ 3.3.5 CVE-2025-30568 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
4.3 Medium Easy 301 Redirects Plugin odihost-easy-redirect-301 Cross-Site Request Forgery No login needed ≤ 1.33 CVE-2025-30557 Patchstack
4.3 Medium Fix Rss Feeds Plugin fix-rss-feed Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-30556 Patchstack
4.3 Medium Yummly Rich Recipes Plugin yummly-rich-recipes Cross-Site Request Forgery No login needed ≤ 4.2 CVE-2025-30549 Patchstack
4.3 Medium Cackle Plugin cackle Cross-Site Request Forgery No login needed ≤ 4.33 CVE-2025-30546 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack
4.3 Medium Simple Optimizer Plugin simple-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-30538 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
4.3 Medium Image Captcha Plugin image-captcha Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-30534 Patchstack
4.3 Medium WP Ride Booking Plugin wp-ride-booking Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-30531 Patchstack
4.3 Medium Auto Load Next Post Plugin auto-load-next-post Cross-Site Request Forgery No login needed ≤ 1.5.14 CVE-2025-30529 Patchstack
4.3 Medium Typekit Plugin typekit Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-30526 Patchstack
4.3 Medium GP Back To Top Plugin gp-back-to-top Cross-Site Request Forgery No login needed ≤ 3.0 CVE-2025-30521 Patchstack
7.6 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.2 CVE-2025-1970 Wordfence
4.3 Medium CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts Plugin cits-support-svg-webp-media-upload Arbitrary File Upload Cross-Site Request Forgery to Font Assignment Deletion No login needed ≤ 4.2 CVE-2024-13768 Wordfence
6.4 Medium Make Builder Plugin make-builder Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via make_builder_ajax_subscribe Function ≤ 1.1.10 CVE-2024-13856 Wordfence
4.3 Medium CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts Plugin cits-support-svg-webp-media-upload Arbitrary File Upload Cross-Site Request Forgery to Settings Update No login needed ≤ 4.2 CVE-2025-0807 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
4.3 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function No login needed ≤ 2.2.5 CVE-2025-1314 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
4.3 Medium Tripetto Plugin tripetto Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Results Deletion No login needed ≤ 8.0.9 CVE-2025-1530 Wordfence
6.1 Medium Zoorum Comments Plugin zoorum-comments Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-2163 Wordfence
8.8 High InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 0.1.0.83 CVE-2024-13913 Wordfence
7.5 High LoginPress Plugin loginpress Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.3.1 CVE-2025-1764 Wordfence
5.3 Medium Resido - Real Estate Theme Broken Access Control Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side Request Forgery and API Key Settings Update No login needed ≤ 3.6 CVE-2025-1285 Wordfence
5.5 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 6.2 CVE-2024-13838 Wordfence
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only