WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,501–1,550 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
6.1 Medium Appsero Helper Plugin appsero-helper Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2024-13436 Wordfence
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
5.3 Medium Starter Templates by FancyWP Plugin starter-templates Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.0.0 CVE-2024-13924 Wordfence
8.8 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.4.2 CVE-2024-11640 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 CVE-2024-13774 Wordfence
6.1 Medium Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins Plugin related-post Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed 2.0.59 CVE-2024-12634 Wordfence
5.5 Medium WPGet API Plugin wpgetapi Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.2.10 CVE-2024-13857 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence
4.3 Medium Homey Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed ≤ 2.4.3 CVE-2025-0748 Wordfence
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed ≤ 4.2.2 CVE-2025-1383 Wordfence
4.3 Medium Spreadsheet Integration Plugin wpgsi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed ≤ 3.8.2 CVE-2025-1463 Wordfence
6.3 Medium bbPress Plugin bbpress Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed ≤ 2.6.11 CVE-2025-1435 Wordfence
4.3 Medium I Am Gloria Plugin gloria-assistant-by-webtronic-labs Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-0990 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
8.8 High Newscrunch Theme newscrunch Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1306 Wordfence
5.4 Medium Theme Options Z Plugin theme-options-z Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-25121 Patchstack
4.8 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Server-Side Request Forgery Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links No login needed ≤ 2.7.4 CVE-2024-13697 Wordfence
4.3 Medium Simple:Press Plugin simplepress Cross-Site Request Forgery Cross-Site Request Forgery to Unauthorized Post Editing No login needed ≤ 6.10.12 CVE-2024-13518 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
6.4 Medium URL Media Uploader Plugin url-media-uploader Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via DNS Rebinding ≤ 1.0.0 CVE-2025-1662 Wordfence
4.3 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 3.1.0 CVE-2025-1506 Wordfence
4.3 Medium RateMyAgent Official Plugin ratemyagent-official Cross-Site Request Forgery Cross-Site Request Forgery to API Key Update No login needed ≤ 1.4.0 CVE-2025-0801 Wordfence
8.8 High Cardealer Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Update via update_user_profile No login needed ≤ 1.6.4 CVE-2025-1687 Wordfence
4.9 Medium Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Server-Side Request Forgery WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery ≤ 1.16.8 CVE-2024-13907 Wordfence
5.3 Medium OneStore Sites Plugin onestore-sites Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 0.1.1 CVE-2024-13905 Wordfence
4.3 Medium School Management System – SakolaWP Plugin sakolawp-lite Cross-Site Request Forgery SakolaWP <= 1.0.8 - Cross-Site Request Forgery to Exam Setting Manipulation No login needed ≤ 1.0.8 CVE-2024-13647 Wordfence
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
4.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.1.6 CVE-2024-13560 Wordfence
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
6.4 Medium Enfold Theme Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id ≤ 6.0.9 CVE-2024-13695 Wordfence
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Cross-Site Request Forgery in wfu_file_details No login needed ≤ 4.25.2 CVE-2024-13494 Wordfence
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack
4.3 Medium RAYS Grid Plugin rays-grid Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-27317 Patchstack
4.3 Medium JPG, PNG Compression and Optimization Plugin wp-image-compression Cross-Site Request Forgery No login needed ≤ 1.7.35 CVE-2025-27316 Patchstack
4.3 Medium All-In-One Cufon Plugin all-in-one-cufon Cross-Site Request Forgery No login needed ≤ 1.3.0 CVE-2025-27315 Patchstack
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack
4.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Cross-Site Request Forgery Cross-Site Request Forgery to Custom CSS Update No login needed ≤ 3.51 CVE-2024-13883 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only