WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,551–1,600 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 32 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files Plugin embed-any-document Server-Side Request Forgery Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode ≤ 2.7.5 CVE-2025-1043 Wordfence
8.1 High Ultimate Classified Listings Plugin ultimate-classified-listings Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover No login needed ≤ 1.5 CVE-2024-13753 Wordfence
6.1 Medium DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 5.8.0 CVE-2024-13339 Wordfence
4.3 Medium Disable Auto Updates Plugin disable-auto-updates Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed ≤ 1.4 CVE-2024-13336 Wordfence
4.3 Medium Apptivo Business Site CRM Plugin apptivo-business-site Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed ≤ 5.3 CVE-2024-13405 Wordfence
6.5 Medium WP Media Category Management Plugin wp-media-category-management Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 2.0 – 2.3.3 CVE-2025-0865 Wordfence
6.1 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.7.1007 CVE-2025-1441 Wordfence
4.3 Medium Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later Plugin flexible-wishlist Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed ≤ 1.2.26 CVE-2024-13718 Wordfence
4.3 Medium Ecwid by Lightspeed Ecommerce Shopping Cart Plugin ecwid-shopping-cart Cross-Site Request Forgery Cross-Site Request Forgery to Send Deactivation Message No login needed ≤ 6.12.27 CVE-2024-13795 Wordfence
6.1 Medium MemorialDay Plugin memorialday Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2024-13523 Wordfence
8.8 High Shopwarden – Automated WooCommerce monitoring & testing Plugin shopwarden Cross-Site Request Forgery Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0.11 CVE-2024-13315 Wordfence
4.3 Medium SpeedSize Image & Video AI-Optimizer Plugin speedsize-ai-image-optimizer Cross-Site Request Forgery Cross-Site Request Forgery to Clear Cache No login needed ≤ 1.5.1 CVE-2024-13438 Wordfence
5.3 Medium 1 Click WordPress Migration Plugin – 100% FREE for a limited time Plugin 1-click-migration Cross-Site Request Forgery Cross-Site Request Forgery to Backup Process Cancellation No login needed ≤ 2.2 CVE-2024-13555 Wordfence
8.8 High Option Editor Plugin option-editor Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0 CVE-2024-13852 Wordfence
4.3 Medium Mortgage Lead Capture System Plugin wprequal Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 8.2.11 CVE-2025-0796 Wordfence
8.1 High Reset Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Database Reset No login needed ≤ 1.6 CVE-2024-13684 Wordfence
6.1 Medium magayo Lottery Results Plugin magayo-lottery-results Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0.12 CVE-2024-13522 Wordfence
5.4 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 5.9.4.2 CVE-2024-13741 Wordfence
5.5 Medium Stream Plugin stream Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery ≤ 4.0.2 CVE-2024-13879 Wordfence
5.4 Medium Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Plugin responsive-add-ons Server-Side Request Forgery Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_request ≤ 3.1.4 CVE-2024-13834 Wordfence
4.3 Medium DirectoryPress Frontend Plugin directorypress-frontend Cross-Site Request Forgery Cross-Site Request Forgery to Listing Status Update No login needed ≤ 2.7.9 CVE-2024-10581 Wordfence
8.1 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Account Deletion No login needed ≤ 2.7.3 CVE-2024-12386 Wordfence
4.3 Medium Book a Room Plugin book-a-room Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.9 CVE-2024-13437 Wordfence
6.1 Medium StaffList Plugin stafflist Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 3.2.3 CVE-2024-13749 Wordfence
4.3 Medium Houzez Property Feed Plugin houzez-property-feed Cross-Site Request Forgery Cross-Site Request Forgery to Property Feed Export Deletion No login needed ≤ 2.4.21 CVE-2025-0808 Wordfence
4.3 Medium WP All Import Pro Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Imported Content Deletion No login needed ≤ 4.9.7 CVE-2024-9661 Wordfence
5.4 Medium Infusionsoft Analytics Plugin infusionsoft-web-tracker Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-25145 Patchstack
4.3 Medium Songkick Concerts and Festivals Plugin songkick-concerts-and-festivals Cross-Site Request Forgery No login needed ≤ 0.9.7 Fixed in 0.10.0 CVE-2025-25146 Patchstack
5.4 Medium WP Spell Check Plugin wp-spell-check Cross-Site Request Forgery No login needed ≤ 9.21 Fixed in 9.22 CVE-2025-25111 Patchstack
6.1 Medium ShopSite Plugin shopsite-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.10 CVE-2024-13510 Wordfence
6.5 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion No login needed ≤ 4.6 CVE-2024-13356 Wordfence
4.3 Medium Activity Log WinterLock Plugin winterlock Cross-Site Request Forgery Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted. No login needed prior to 1.2.5 CVE-2025-24982 jpcert
7.1 High Forge – Front-End Page Builder Plugin forge Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-22703 Patchstack
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
5.4 Medium Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23985 Patchstack
5.4 Medium Oshine Modules Plugin oshine-modules Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44055 Patchstack
8.8 High WP Image Uploader Plugin wp-image-uploader Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.0.1 CVE-2024-13707 Wordfence
6.1 Medium Wonder FontAwesome Plugin wonder-fontawesome Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.8 CVE-2024-13512 Wordfence
6.5 Medium CP Contact Form with PayPal Plugin cp-contact-form-with-paypal Cross-Site Request Forgery No login needed ≤ 1.3.52 CVE-2024-13758 Wordfence
6.1 Medium MailUp Auto Subscription Plugin mailup-auto-subscribtion Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2024-13521 Wordfence
4.3 Medium WP Go Maps Plugin wp-google-maps Cross-Site Request Forgery No login needed ≤ 9.0.40 Fixed in 9.0.41 CVE-2025-24742 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.7.0 Fixed in 6.7.1 CVE-2025-24537 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
8.8 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.7.2 CVE-2024-11641 Wordfence
5.4 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Server-Side Request Forgery MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl ≤ 4.0.5 CVE-2024-10705 Wordfence
3.8 Low Contact Form by Bit Form Plugin bit-form Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.17.4 CVE-2024-13450 Wordfence
6.1 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.8.3 CVE-2024-12076 Wordfence
4.3 Medium Linear Plugin linear Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset No login needed ≤ 2.8.1 CVE-2024-13709 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only