WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 16,751–16,800 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 336 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Czater.pl – live chat i telefon Plugin czater Cross-Site Request Forgery live chat i telefon plugin <= 1.0.5 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2025-32624 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
5.9 Medium Ally Plugin pojo-accessibility Cross-Site Scripting ≤ 3.1.0 Fixed in 3.2.0 CVE-2025-32640 Patchstack
9.6 Critical Vite Coupon Plugin vite-coupon Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-32642 Patchstack
7.1 High Custom Posts Order Plugin custom-posts-order Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.4 CVE-2025-32645 Patchstack
7.1 High IP2Location World Clock Plugin ip2location-world-clock Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.9 Fixed in 1.1.10 CVE-2025-32644 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
7.1 High Nepali Date Utilities Plugin nepali-date-utilities Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.15 CVE-2025-32664 Patchstack
7.1 High Interactive US Map Plugin interactive-us-map Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.7 CVE-2025-32661 Patchstack
7.1 High Doppler Forms Plugin doppler-form Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 Fixed in 2.6.0 CVE-2025-32667 Patchstack
7.1 High Epeken All Kurir Plugin epeken-all-kurir Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-32673 Patchstack
7.1 High Mergado Pack Plugin mergado-marketing-pack Cross-Site Request Forgery No login needed ≤ 4.2.1 CVE-2025-32669 Patchstack
6.8 Medium SEO Help Plugin seo-help Server-Side Request Forgery ≤ 6.7.9 CVE-2025-32675 Patchstack
7.6 High WP Social Stream Designer Plugin social-stream-design SQL Injection ≤ 1.3 CVE-2025-32677 Patchstack
7.6 High Verowa Connect Plugin verowa-connect SQL Injection ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-32676 Patchstack
5.4 Medium User Registration Using Contact Form 7 Plugin user-registration-using-contact-form-7 Cross-Site Request Forgery No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32679 Patchstack
4.3 Medium WP Show Stats Plugin wp-show-stats Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-32678 Patchstack
5.9 Medium Review Stream Plugin review-stream Cross-Site Scripting ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-32680 Patchstack
6.5 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting ≤ 8.6.6 Fixed in 8.6.7 CVE-2025-32683 Patchstack
5.0 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Broken Access Control ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32684 Patchstack
6.5 Medium PowerPress Podcasting Plugin powerpress Cross-Site Scripting ≤ 11.12.5 Fixed in 11.12.6 CVE-2025-32690 Patchstack
7.6 High WP Inquiries Plugin wp-inquiries SQL Injection ≤ 0.2.1 CVE-2025-32685 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.12.6 Fixed in 11.12.7 CVE-2025-32691 Patchstack
4.7 Medium WebinarPress Plugin wp-webinarsystem Open Redirect No login needed ≤ 1.33.28 CVE-2025-32693 Patchstack
7.5 High WP Subscription Forms Plugin wp-subscription-forms Local File Inclusion ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-32692 Patchstack
4.7 Medium Ultimate WP Mail Plugin ultimate-wp-mail Open Redirect No login needed ≤ 1.3.10 CVE-2025-32694 Patchstack
6.3 Medium Plugin Upgrade Time Out Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-8243 WPScan
4.3 Medium WP MultiTasking Plugin Cross-Site Request Forgery Permalink Suffix Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6860 WPScan
4.3 Medium WP MultiTasking Plugin Cross-Site Request Forgery Header/Footer/Body Script Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6857 WPScan
6.4 Medium WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts Plugin wedevs-project-manager Cross-Site Scripting Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.6.22 Fixed in 2.6.23 CVE-2025-3100 Wordfence
4.3 Medium Live Forms Plugin liveforms Broken Access Control No login needed ≤ 4.8.5 CVE-2025-32279 Patchstack
6.5 Medium Broadstreet Ads Plugin broadstreet Cross-Site Scripting ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-32211 Patchstack
6.5 Medium m1.DownloadList Plugin m1downloadlist Information Disclosure Sensitive Data Exposure ≤ 0.24 CVE-2025-32164 Patchstack
7.1 High Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2025-32117 Patchstack
5.3 Medium MelaPress Login Security and MelaPress Login Security Premium Plugin melapress-login-security Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion No login needed 2.1.0 CVE-2025-2876 Wordfence
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence
5.3 Medium Accept SagePay Payments Using Contact Form 7 Plugin accept-sagepay-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.0 CVE-2025-2883 Wordfence
4.3 Medium Motors – Car Dealership & Classified Listings Plugin Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.66 - Missing Authorization to Authenticated (Subscriber+) Wizard Set-up ≤ 1.4.66 CVE-2025-3437 Wordfence
5.4 Medium Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Cross-Site Scripting Car Dealership & Classified Listings Plugin <= 1.4.63 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.4.63 Fixed in 1.4.64 CVE-2025-2808 Wordfence
8.8 High Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.4.64 Fixed in 1.4.65 CVE-2025-2807 Wordfence
6.5 Medium coreActivity: Activity Logging Plugin coreactivity SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.7 Fixed in 2.7.1 CVE-2025-3436 Wordfence
8.8 High WPFront User Role Editor Plugin wpfront-user-role-editor Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function No login needed ≤ 4.2.1 CVE-2025-3064 Wordfence
6.1 Medium Advanced Advertising System Plugin advanced-advertising-system Open Redirect No login needed ≤ 1.3.1 CVE-2025-3433 Wordfence
6.4 Medium AAWEP Obfuscator Plugin aawp-obfuscator Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-3432 Wordfence
5.3 Medium GreenPay(tm) by Green.Money Plugin green-money-payment-gateway Information Disclosure Unauthenticated Information Exposure No login needed 3.0.0 – 3.0.9 CVE-2025-2882 Wordfence
7.5 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin Path Traversal WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download No login needed ≤ 6.91 CVE-2025-3431 Wordfence
4.9 Medium 3DPrint Lite Plugin 3dprint-lite SQL Injection Authenticated (Admin+) SQL Injection via 'coating_text' ≤ 2.1.3.6 CVE-2025-3428 Wordfence
4.9 Medium Team Circle Image Slider With Lightbox Plugin circle-image-slider-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 Fixed in 1.0.5 CVE-2019-25223 Wordfence
4.9 Medium 3DPrint Lite Plugin 3dprint-lite SQL Injection Authenticated (Admin+) SQL Injection via 'printer_text' ≤ 2.1.3.6 CVE-2025-3430 Wordfence
4.9 Medium 3DPrint Lite Plugin 3dprint-lite SQL Injection Authenticated (Admin+) SQL Injection via 'material_text' ≤ 2.1.3.6 CVE-2025-3429 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only