WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 16,851–16,900 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 338 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium 1-Click Backup & Restore Database Plugin 1-click-backup-restore-database-by-sunbytes Broken Access Control ≤ 1.0.3 CVE-2025-32246 Patchstack
6.5 Medium Official CleverReach Plugin for WooCommerce Plugin cleverreach-wc Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2025-32241 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Information Disclosure Sensitive Data Exposure ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-32238 Patchstack
4.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control ≤ 3.5.28 Fixed in 3.5.29 CVE-2025-32237 Patchstack
4.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar plugin <= 5.9.4 - Broken Access Control ≤ 5.9.4 Fixed in 5.9.5 CVE-2025-32235 Patchstack
4.3 Medium AdMail – Multilingual Back in-Stock Notifier for WooCommerce Plugin admail Broken Access Control ≤ 1.7.0 CVE-2025-32234 Patchstack
4.3 Medium Revive.so Plugin revive-so Broken Access Control ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-32233 Patchstack
4.3 Medium StaffList Plugin stafflist Broken Access Control ≤ 3.2.7 CVE-2025-32232 Patchstack
4.3 Medium Bookingor Plugin bookingor Broken Access Control ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-32231 Patchstack
4.3 Medium Variable Inspector Plugin variable-inspector Broken Access Control ≤ 2.6.3 CVE-2025-32229 Patchstack
4.3 Medium Display product variations dropdown on shop page Plugin display-product-variations-dropdown-on-shop-page Broken Access Control ≤ 1.1.3 CVE-2025-32226 Patchstack
5.3 Medium WP Event Manager Plugin wp-event-manager Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32225 Patchstack
5.4 Medium Salon booking system Plugin salon-booking-system Broken Access Control ≤ 10.31.9 CVE-2025-32220 Patchstack
5.4 Medium eaSYNC Plugin easync-booking Broken Access Control ≤ 1.3.19 Fixed in 1.3.21 CVE-2025-32219 Patchstack
5.4 Medium TableOn Plugin posts-table-filterable Broken Access Control ≤ 1.0.5.1 CVE-2025-32218 Patchstack
5.4 Medium Ai Image Alt Text Generator for WP Plugin ai-image-alt-text-generator-for-wp Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-32217 Patchstack
6.5 Medium Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods Cross-Site Scripting ≤ 3.2.8 Fixed in 3.2.9 CVE-2025-32207 Patchstack
7.6 High Split Test For Elementor Plugin split-test-for-elementor SQL Injection ≤ 1.8.3 Fixed in 1.8.4 CVE-2025-32204 Patchstack
7.6 High Falling things Plugin falling-things SQL Injection ≤ 1.08 Fixed in 1.09 CVE-2025-32203 Patchstack
4.3 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.8.4 Fixed in 1.2.8.5 CVE-2025-32201 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.36 CVE-2025-32197 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2025-32196 Patchstack
6.5 Medium Ecwid Shopping Cart Plugin ecwid-shopping-cart Cross-Site Scripting ≤ 7.0 Fixed in 7.0.1 CVE-2025-32195 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-32194 Patchstack
6.5 Medium Simple WP Events Plugin simple-wp-events Cross-Site Scripting ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32193 Patchstack
6.5 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32192 Patchstack
6.5 Medium News Element Elementor Blog Magazine Plugin news-element Cross-Site Scripting ≤ 1.0.9 CVE-2025-32191 Patchstack
6.5 Medium Musician's Pack For Elementor Plugin music-pack-for-elementor Cross-Site Scripting ≤ 1.8.7 CVE-2025-32190 Patchstack
6.5 Medium BWD Elementor Addons Plugin bwd-elementor-addons Cross-Site Scripting ≤ 4.4.2 CVE-2025-32189 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.15 Fixed in 2.16 CVE-2025-32188 Patchstack
6.5 Medium Administrator Z Plugin administrator-z Cross-Site Scripting ≤ 2026.03.02 CVE-2025-32187 Patchstack
6.5 Medium Turbo Addons Elementor Plugin turbo-addons-elementor Cross-Site Scripting ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-32186 Patchstack
6.5 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.329 Fixed in 1.0.332 CVE-2025-32185 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.5.0 Fixed in 2.6.0 CVE-2025-32184 Patchstack
6.5 Medium Video Playlist For YouTube Plugin video-playlist-for-youtube Cross-Site Scripting ≤ 6.7.1 CVE-2025-32183 Patchstack
6.5 Medium Spider Elements Plugin spider-elements Cross-Site Scripting Addons for Elementor plugin <= 1.6.5 - Cross Site Scripting (XSS) ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-32182 Patchstack
6.5 Medium Search, Filters & Merchandising for WooCommerce Plugin instantsearch-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.58 Fixed in 3.0.59 CVE-2025-32181 Patchstack
6.5 Medium Maps for WP Plugin maps-for-wp Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-32179 Patchstack
6.5 Medium Embed Chessboard Plugin embed-chessboard Cross-Site Scripting ≤ 3.08.00 CVE-2025-32177 Patchstack
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-32176 Patchstack
6.5 Medium VK Filter Search Plugin vk-filter-search Cross-Site Scripting ≤ 2.20.2 CVE-2025-32175 Patchstack
6.5 Medium Tockify Events Calendar Plugin tockify-events-calendar Cross-Site Scripting ≤ 2.2.13 Fixed in 2.3.0 CVE-2025-32174 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-32173 Patchstack
6.5 Medium YaMaps Plugin yamaps Cross-Site Scripting ≤ 0.6.40 Fixed in 0.6.41 CVE-2025-32172 Patchstack
6.5 Medium Table Block by Tableberg Plugin tableberg Cross-Site Scripting ≤ 0.6.10 Fixed in 0.6.12 CVE-2025-32171 Patchstack
6.5 Medium Motors Plugin motors-car-dealership-classified-listings Cross-Site Scripting ≤ 1.4.71 Fixed in 1.4.72 CVE-2025-32170 Patchstack
6.5 Medium Showeblogin Social Plugin showeblogin-facebook-page-like-box Cross-Site Scripting ≤ 7.0 CVE-2025-32169 Patchstack
6.5 Medium Gutenify Plugin gutenify Cross-Site Scripting ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-32168 Patchstack
6.5 Medium SurveyJS Plugin surveyjs Cross-Site Scripting ≤ 1.12.20 Fixed in 1.12.57 CVE-2025-32167 Patchstack
6.5 Medium Emma Plugin emma-emarketing-plugin Cross-Site Scripting ≤ 1.3.3 CVE-2025-32166 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only