WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,051–17,100 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 342 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.8 Medium WP-LESS Plugin wp-less Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-31550 Patchstack
7.1 High Ultimate Push Notifications Plugin ultimate-push-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-31548 Patchstack
7.1 High Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16 Fixed in 2.20 CVE-2025-31537 Patchstack
9.3 Critical Shopper Plugin shopper SQL Injection No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-31534 Patchstack
9.3 Critical History Log by click5 Plugin history-log-by-click5 SQL Injection No login needed ≤ 1.0.13 CVE-2025-31531 Patchstack
4.3 Medium WP Mobile Bottom Menu Plugin mobile-bottom-menu-for-wp Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-31525 Patchstack
7.1 High CGM Event Calendar Plugin cgm-event-calendar Cross-Site Scripting No login needed ≤ 0.8.5 CVE-2025-31462 Patchstack
7.1 High NanoSupport Plugin nanosupport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.0 CVE-2025-31461 Patchstack
7.1 High Limit Max IPs Per User Plugin limit-max-ips-per-user Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-31455 Patchstack
7.1 High Delete Post Revision Plugin delete-post-revision Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31454 Patchstack
7.1 High WP Cleaner Plugin wpcleaner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-31446 Patchstack
7.1 High Pages Order Plugin pages-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-31445 Patchstack
7.1 High WordPress Galleria Plugin wp-galleria Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-31441 Patchstack
7.1 High WP Bookmarks Plugin wp-bookmarks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31431 Patchstack
8.1 High Material Dashboard Plugin material-dashboard Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31097 Patchstack
8.5 High Order Splitter for WooCommerce Plugin woo-order-splitter SQL Injection ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-31089 Patchstack
7.1 High Product Table by WBW Plugin woo-product-tables Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-31086 Patchstack
7.1 High xili-language Plugin xili-language Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.21.2 Fixed in 2.21.3 CVE-2025-31085 Patchstack
8.1 High News & Blog Designer Pack Plugin blog-designer-pack Local File Inclusion No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2025-31082 Patchstack
7.1 High Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.5 Fixed in 4.1.6 CVE-2025-31081 Patchstack
7.1 High HTML Forms Plugin html-forms Cross-Site Scripting No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-31080 Patchstack
7.1 High Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition Cross-Site Scripting Worldwide Express Edition plugin <= 5.2.18 - Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-31078 Patchstack
7.1 High Access Areas Plugin wp-access-areas Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.19 Fixed in 1.5.20 CVE-2025-30913 Patchstack
7.1 High Plugin Oficial – Getnet para WooCommerce Plugin wc-checkout-getnet Cross-Site Scripting Getnet para WooCommerce plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.8.0 CVE-2025-30906 Patchstack
7.1 High Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.4.5 CVE-2025-30905 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager PHP Object Injection ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30892 Patchstack
5.4 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Authentication Bypass Broken Authentication ≤ 3.10.0 Fixed in 3.10.1 CVE-2025-30853 Patchstack
7.1 High Oracle Cards Lite Plugin oracle-cards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-30852 Patchstack
7.1 High Watu Quiz Plugin watu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-30844 Patchstack
9.9 Critical Countdown & Clock Plugin countdown-builder Remote Code Execution ≤ 2.8.8 Fixed in 2.8.9 CVE-2025-30841 Patchstack
8.8 High WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce Plugin wpc-smart-linked-products Privilege Escalation ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-30825 Patchstack
9.3 Critical Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-30807 Patchstack
7.1 High VPSUForm Plugin v-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.9 Fixed in 3.1.10 CVE-2025-30778 Patchstack
10.0 Critical DigiWidgets Image Editor Plugin digiwidgets-image-editor Remote Code Execution No login needed ≤ 1.10 CVE-2025-30580 Patchstack
7.1 High Frizzly Plugin frizzly Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-30554 Patchstack
4.3 Medium Advanced Speed Increaser Plugin advanced-speed-increaser Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-31753 Patchstack
7.6 High BookingPress Plugin bookingpress-appointment-booking SQL Injection ≤ 1.1.28 Fixed in 1.1.38 CVE-2025-31910 Patchstack
7.1 High JSON Structuring Markup Plugin json-structuring-markup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-31908 Patchstack
7.1 High WP Profitshare Plugin wp-profitshare Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.9 CVE-2025-31906 Patchstack
7.1 High Ebook Downloader Plugin ebook-downloader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31904 Patchstack
6.5 Medium Arrow Custom Feed for Twitter Plugin arrow-twitter-feed Cross-Site Scripting ≤ 1.5.3 CVE-2025-31897 Patchstack
6.5 Medium ABC Notation Plugin abc-notation Cross-Site Scripting ≤ 6.1.3 CVE-2025-31895 Patchstack
6.5 Medium Ebook Downloader Plugin ebook-downloader Cross-Site Scripting ≤ 1.0 CVE-2025-31894 Patchstack
6.5 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-31892 Patchstack
6.5 Medium Gosign – Posts Slider Block Plugin gosign-posts-slider-block Cross-Site Scripting Posts Slider Block plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-31891 Patchstack
6.5 Medium Simple Map No Api Plugin simple-map-no-api Cross-Site Scripting ≤ 1.9 CVE-2025-31890 Patchstack
4.3 Medium WP Multistore Locator Plugin wp-multi-store-locator Cross-Site Request Forgery No login needed ≤ 2.5.2 CVE-2025-31888 Patchstack
4.3 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Broken Access Control ≤ 1.0.8 CVE-2025-31887 Patchstack
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.21 Fixed in 5.22 CVE-2025-31886 Patchstack
6.5 Medium Hyperlink Group Block Plugin hyperlink-group-block Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-31885 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only