WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 16,951–17,000 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 340 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Gravel Theme gravel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-31418 Patchstack
7.6 High wpForo Forum Plugin wpforo Privilege Escalation ≤ 2.4.2 Fixed in 2.4.4 CVE-2025-31420 Patchstack
5.8 Medium Srbtranslatin Plugin srbtranslatin Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.0 CVE-2025-31421 Patchstack
7.1 High ez Form Calculator Premium Plugin ez-form-calculator-premium Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.14.1.2 CVE-2025-22282 Patchstack
8.8 High Vehica Core Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.97 CVE-2025-3105 Wordfence
8.8 High Woffice Core Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.4.21 CVE-2025-2780 Wordfence
5.4 Medium Woffice Core Plugin Cross-Site Request Forgery Cross-Site Request Forgery to User Registration Approval No login needed ≤ 5.4.21 CVE-2025-2797 Wordfence
5.9 Medium Maps - Google Maps Plugin Cross-Site Scripting Google Maps <= 1.0.6 - Contributor+ Stored XSS ≤ 1.0.6 CVE-2025-2279 WPScan
8.1 High Countdown, Coming Soon, Maintenance – Countdown & Clock Plugin countdown-builder Local File Inclusion Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion No login needed ≤ 2.8.9.1 CVE-2025-2270 Wordfence
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed 4.0.1 – 7.2.4 CVE-2024-13708 Wordfence
6.4 Medium RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 6.0.4.3 CVE-2025-2836 Wordfence
4.4 Medium Simple Banner Plugin simple-banner Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.0.4 CVE-2024-13898 Wordfence
9.8 Critical TagDiv Composer Plugin Information Disclosure Unauthenticated Arbitrary PHP Object Instantiation No login needed ≤ 5.3 CVE-2024-13645 Wordfence
7.5 High Product Filter by WBW Plugin woo-product-filter SQL Injection Unauthenticated SQL Injection via filtersDataBackend Parameter No login needed ≤ 2.7.9 CVE-2025-2317 Wordfence
8.8 High Uncanny Automator Plugin uncanny-automator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 6.3.0.2 Fixed in 7.3.2 CVE-2025-2075 Wordfence
8.1 High Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 4.0.1 – 7.2.4 Fixed in 7.2.5 CVE-2024-13744 Wordfence
9.3 Critical Social Share And Social Locker Plugin social-share-and-social-locker-arsocial SQL Injection No login needed ≤ 1.4.2 CVE-2025-31911 Patchstack
7.5 High Apptivo Business Site CRM Plugin apptivo-business-site Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.3 Fixed in 5.4 CVE-2025-31909 Patchstack
7.1 High Team Builder Plugin team-display Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-31907 Patchstack
7.1 High Team Rosters Plugin team-rosters Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7 Fixed in 4.8 CVE-2025-31905 Patchstack
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-31903 Patchstack
7.1 High Social Share And Social Locker Plugin social-share-and-social-locker-arsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-31902 Patchstack
7.1 High Digihood HTML Sitemap Plugin wedesin-html-sitemap Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.1 CVE-2025-31901 Patchstack
7.1 High Lexicata Plugin lexicata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.16 CVE-2025-31900 Patchstack
7.1 High Awesome Logos Plugin awesome-logos Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-31899 Patchstack
7.1 High MediaView Plugin mediaview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31898 Patchstack
6.5 Medium GetBookingsWP Plugin get-bookings-wp Broken Access Control ≤ 1.1.27 CVE-2025-31896 Patchstack
6.5 Medium Botnet Attack Blocker Plugin botnet-attack-blocker Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 CVE-2025-31893 Patchstack
5.8 Medium Payday Plugin payday Broken Access Control No login needed ≤ 3.3.18 CVE-2025-31876 Patchstack
6.5 Medium Local Magic Plugin local-magic Broken Access Control No login needed ≤ 2.9.0 CVE-2025-31858 Patchstack
6.3 Medium FPW Category Thumbnails Plugin fpw-category-thumbnails Broken Access Control ≤ 1.9.5 CVE-2025-31841 Patchstack
4.9 Medium Fonto Plugin fonto Path Traversal Arbitrary File Download ≤ 1.2.2 CVE-2025-31827 Patchstack
4.9 Medium Category Icon Plugin category-icon Path Traversal Arbitrary File Download ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-31825 Patchstack
6.5 Medium Publitio Plugin publitio Path Traversal Arbitrary File Read ≤ 2.2.0 Fixed in 2.2.2 CVE-2025-31800 Patchstack
6.5 Medium Shopify to WooCommerce Migration Plugin migrate-shopify-to-woocommerce Broken Access Control Settings Change No login needed ≤ 1.3.0 CVE-2025-31795 Patchstack
5.4 Medium WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.0.8 CVE-2025-31794 Patchstack
6.5 Medium TextMe SMS Plugin textme-sms-integration Broken Access Control ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-31789 Patchstack
6.5 Medium Widget Manager Light Plugin widget-manager-light Broken Access Control No login needed ≤ 1.18 CVE-2025-31768 Patchstack
6.5 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.78 CVE-2025-31758 Patchstack
6.4 Medium Clients Plugin clients Broken Access Control ≤ 1.1.4 CVE-2025-31746 Patchstack
6.4 Medium Minimalistic Event Manager Plugin minimalistic-event-manager Broken Access Control ≤ 1.1.1 CVE-2025-31739 Patchstack
6.5 Medium Rich Text Editor Plugin richtexteditor Broken Access Control No login needed ≤ 1.0.1 CVE-2025-31736 Patchstack
6.5 Medium WooTumblog Plugin woo-tumblog Content Injection No login needed ≤ 2.1.4 CVE-2025-31729 Patchstack
7.1 High Support Helpdesk Ticket System Lite Plugin ticket-help-desk-system-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.5.2 Fixed in 5.0.0 CVE-2025-31626 Patchstack
6.5 Medium Advanced Typekit Plugin advanced-typekit Cross-Site Scripting ≤ 1.0.1 CVE-2025-31622 Patchstack
7.1 High Contact Form vCard Generator Plugin contact-form-vcard-generator Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-31582 Patchstack
6.5 Medium WP Video Playlist Plugin wp-video-playlist Broken Access Control Settings Change No login needed ≤ 1.1.2 CVE-2025-31581 Patchstack
7.1 High PeproDev CF7 Database Plugin pepro-cf7-database Cross-Site Scripting No login needed ≤ 2.0.0 CVE-2025-31573 Patchstack
5.8 Medium TailPress Plugin tailpress Information Disclosure Sensitive Data Exposure No login needed ≤ 0.4.4 CVE-2025-31558 Patchstack
5.9 Medium Docxpresso Plugin docxpresso Path Traversal Arbitrary File Download No login needed ≤ 2.6 CVE-2025-31554 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only