WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,451–1,500 of 2,553 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 52
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Counter Box Plugin counter-box Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-24715 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
5.4 Medium Radius Blocks Plugin radius-blocks Cross-Site Request Forgery WordPress Gutenberg Blocks Plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.1.2 Fixed in 2.2.0 CVE-2025-24712 Patchstack
5.4 Medium Popup Box Plugin popup-box Cross-Site Request Forgery No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-24711 Patchstack
4.3 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Request Forgery No login needed ≤ 5.1.8 Fixed in 5.1.9 CVE-2025-24698 Patchstack
5.4 Medium Bubble Menu – circle floating menu Plugin bubble-menu Cross-Site Request Forgery No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2025-24714 Patchstack
4.4 Medium Chained Quiz Plugin chained-quiz Server-Side Request Forgery ≤ 1.3.2.9 Fixed in 1.3.3 CVE-2025-24701 Patchstack
4.4 Medium Extensions For CF7 Plugin extensions-for-cf7 Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-24695 Patchstack
9.1 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.15.3 Fixed in 2.15.4 CVE-2025-24650 Patchstack
5.4 Medium WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Cross-Site Request Forgery No login needed ≤ 1.0.35 Fixed in 1.0.36 CVE-2025-24647 Patchstack
4.3 Medium Taxonomy/Term and Role based Discounts for WooCommerce Plugin taxonomy-discounts-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.1 Fixed in 5.2 CVE-2025-24625 Patchstack
4.3 Medium Really Simple SSL Plugin really-simple-ssl Cross-Site Request Forgery No login needed ≤ 9.1.4 Fixed in 9.2.0 CVE-2025-24623 Patchstack
5.4 Medium Job Board Manager Plugin job-board-manager Cross-Site Request Forgery No login needed ≤ 2.1.59 Fixed in 2.1.60 CVE-2025-24622 Patchstack
7.1 High MachForm Shortcode Plugin machform-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-24636 Patchstack
6.5 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Cross-Site Request Forgery CSRF to Broken Access Control No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-24594 Patchstack
7.1 High KBucket Plugin kbucket Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 4.1.6 Fixed in 4.2.2 CVE-2025-24562 Patchstack
6.5 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.78.258 Fixed in 1.79.262 CVE-2025-24572 Patchstack
4.3 Medium Ultimate Coming Soon & Maintenance Plugin ultimate-coming-soon Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-24543 Patchstack
5.4 Medium Ultimate Coming Soon & Maintenance Plugin ultimate-coming-soon Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-24546 Patchstack
7.1 High ReviewsTap Plugin reviewstap Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-24561 Patchstack
4.3 Medium Starter Templates Plugin astra-sites Cross-Site Request Forgery No login needed ≤ 4.4.9 Fixed in 4.4.10 CVE-2025-24568 Patchstack
7.1 High Subscription DNA Plugin subscriptiondna Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-24555 Patchstack
7.1 High Rocket Media Library Mime Type Plugin rocket-media-library-mime-type Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-22768 Patchstack
7.1 High Ultimate Subscribe Plugin ultimate-subscribe Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23806 Patchstack
7.1 High Snippy Plugin snippy Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23803 Patchstack
4.3 Medium AnyRoad Plugin anyguide Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-23996 Patchstack
7.1 High Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings plugin <= 5.5.0 - CSRF to Settings Update & Stored XSS No login needed ≤ 5.5.0 CVE-2025-23994 Patchstack
7.1 High PPO Call To Actions Plugin ppo-call-to-actions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.3 CVE-2025-24001 Patchstack
7.1 High VikAppointments Services Booking Calendar Plugin vikappointments Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-22719 Patchstack
7.1 High root Cookie Plugin root-cookie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6 CVE-2025-23815 Patchstack
7.1 High Auto FTP Plugin auto-ftp Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23793 Patchstack
7.1 High Chatter Plugin chatter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23760 Patchstack
10.0 Critical iSpring Embedder Plugin embed-ispring Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.0 CVE-2025-23922 Patchstack
7.1 High GravatarLocalCache Plugin gravatarlocalcache Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.2 CVE-2025-23901 Patchstack
7.1 High Genki Announcement Plugin genki-announcement Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23900 Patchstack
7.1 High Error Notification Plugin error-notification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.7 CVE-2025-23902 Patchstack
7.1 High Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3 CVE-2025-23898 Patchstack
7.1 High Annie Plugin annie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 CVE-2025-23884 Patchstack
7.1 High Add RSS Plugin add-rss Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-23895 Patchstack
7.1 High Better Protected Pages Plugin better-protected-pages Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-23875 Patchstack
7.1 High amr personalise Plugin amr-personalise Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.10 CVE-2025-23880 Patchstack
7.1 High PayForm Plugin payform Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-23872 Patchstack
7.1 High LSD Google Maps Embedder Plugin lsd-google-maps-embedder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23871 Patchstack
7.1 High Copyright Safeguard Footer Notice Plugin copyright-safeguard-footer-notice Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 3.0 CVE-2025-23870 Patchstack
7.1 High CJ Custom Content Plugin cj-custom-content Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-23869 Patchstack
7.1 High Debt Calculator Plugin debt-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23861 Patchstack
7.1 High Hotspots Analytics Plugin hotspots Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.12 CVE-2025-23848 Patchstack
7.1 High Gallery Plugin wordpress-gallery-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23842 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only