WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,201–17,250 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 345 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Astra Security Suite Plugin getastra Broken Access Control No login needed ≤ 0.2 CVE-2025-31774 Patchstack
5.3 Medium Ship Per Product Plugin ship-per-product Broken Access Control No login needed ≤ 2.1.0 CVE-2025-31773 Patchstack
5.9 Medium WP Modal Popup with Cookie Integration Plugin wp-modal-popup-with-cookie-integration Cross-Site Scripting ≤ 2.4 Fixed in 2.5 CVE-2025-31772 Patchstack
6.5 Medium Team Members for Elementor Page Builder Plugin team-members-for-elementor Cross-Site Scripting ≤ 1.0.4 CVE-2025-31771 Patchstack
6.5 Medium Content Manager Light Plugin content-manager-light Cross-Site Scripting ≤ 3.2 CVE-2025-31770 Patchstack
4.3 Medium CLP – Custom Login Page by NiteoThemes Plugin clp-custom-login-page Cross-Site Request Forgery Custom Login Page by NiteoThemes plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.5.5 CVE-2025-31769 Patchstack
6.5 Medium Post Custom Templates Lite Plugin post-custom-templates-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.14 CVE-2025-31767 Patchstack
6.5 Medium PhotoShelter for Photographers Blog Feed Plugin photoshelter-official-plugin Cross-Site Scripting ≤ 1.5.7 CVE-2025-31766 Patchstack
5.3 Medium GDPR Cookie Notice Plugin gdpr-cookie-notice Broken Access Control No login needed ≤ 1.2.0 CVE-2025-31765 Patchstack
5.9 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Scripting ≤ 5.4.1 CVE-2025-31764 Patchstack
4.3 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Request Forgery No login needed ≤ 5.4.1 CVE-2025-31763 Patchstack
6.5 Medium Sheet2Site Plugin sheet2site Cross-Site Scripting ≤ 1.0.18 CVE-2025-31762 Patchstack
6.5 Medium Hypotext Plugin hypotext Cross-Site Scripting ≤ 1.0.1 CVE-2025-31761 Patchstack
6.5 Medium SnapWidget Social Photo Feed Widget Plugin snapwidget-wp-instagram-widget Cross-Site Scripting ≤ 1.1.0 CVE-2025-31760 Patchstack
6.5 Medium Boo Recipes Plugin boo-recipes Cross-Site Scripting ≤ 2.4.1 CVE-2025-31759 Patchstack
5.4 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control ≤ 1.78 CVE-2025-31757 Patchstack
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
4.3 Medium pCloud Backup Plugin pcloud-backup Broken Access Control ≤ 1.0.1 CVE-2025-31755 Patchstack
6.5 Medium DobsonDev Shortcodes Plugin dobsondev-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.12 CVE-2025-31754 Patchstack
4.3 Medium Bulk Fields Editor Plugin bulk-user-editor Broken Access Control ≤ 1.8.0 CVE-2025-31752 Patchstack
6.5 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.3 CVE-2025-31751 Patchstack
5.9 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Scripting ≤ 1.3 CVE-2025-31750 Patchstack
6.5 Medium HMH Footer Builder For Elementor Plugin hmh-footer-builder-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2025-31749 Patchstack
6.5 Medium Opal Portfolio Plugin opal-portfolios Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-31748 Patchstack
6.5 Medium WP Chrono Plugin wp-chrono Cross-Site Scripting ≤ 1.5.4 CVE-2025-31747 Patchstack
6.5 Medium Subscription Form for Feedblitz Plugin feedblitz-email-subscription Cross-Site Scripting ≤ 1.0.9 CVE-2025-31745 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31744 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31743 Patchstack
5.9 Medium Dima Take Action Plugin dima-take-action Cross-Site Scripting ≤ 1.0.5 CVE-2025-31742 Patchstack
6.5 Medium Easy Magazine Plugin filtr8-magazine Cross-Site Scripting ≤ 2.1.13 CVE-2025-31741 Patchstack
6.5 Medium News, Magazine and Blog Elements Plugin news-magazine-and-blog-elements Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-31740 Patchstack
6.5 Medium LeadQuizzes Plugin leadquizzes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-31738 Patchstack
6.5 Medium Client Showcase Plugin client-showcase Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2025-31737 Patchstack
6.5 Medium Footnotes Plugin footnotes-for-wordpress Cross-Site Scripting ≤ 2016.1230 CVE-2025-31735 Patchstack
6.5 Medium Simple Post Expiration Plugin simple-post-expiration Cross-Site Scripting ≤ 1.0.1 CVE-2025-31734 Patchstack
6.5 Medium WP Sitemap Plugin wpsitemap Cross-Site Scripting ≤ 1.0.0 CVE-2025-31733 Patchstack
4.3 Medium GB Gallery Slideshow Plugin gb-gallery-slideshow Broken Access Control ≤ 1.3 CVE-2025-31732 Patchstack
6.5 Medium Author Bio Shortcode Plugin author-bio-shortcode Cross-Site Scripting ≤ 2.5.3 CVE-2025-31731 Patchstack
6.5 Medium Marketer Addons Plugin marketer-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.1 CVE-2025-31730 Patchstack
4.3 Medium Zoho Flow Plugin zoho-flow Broken Access Control ≤ 2.13.3 Fixed in 2.13.4 CVE-2025-31408 Patchstack
9.8 Critical WP RealEstate Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'process_register' No login needed ≤ 1.6.26 CVE-2025-2237 Wordfence
9.8 Critical SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation No login needed ≤ 3.7.9 CVE-2024-13553 Wordfence
6.4 Medium Contempo Real Estate Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.6.3 CVE-2025-2906 Wordfence
8.8 High WP Pro Real Estate 7 Theme Arbitrary File Upload Authenticated (Custom) Arbitrary File Upload ≤ 3.5.4 CVE-2025-2891 Wordfence
6.4 Medium PowerPack Elementor Addons (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 Fixed in 2.9.1 CVE-2025-1512 Wordfence
5.5 Medium Groundhogg Plugin groundhogg Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter ≤ 3.7.4.1 CVE-2025-1267 Wordfence
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 7.2.4 Fixed in 7.2.5 CVE-2024-12278 Wordfence
4.1 Medium Lana Downloads Manager Plugin lana-downloads-manager Path Traversal Admin+ Arbitrary File Download via Path Traversal < 1.10.0 Fixed in 1.10.0 CVE-2025-2048 WPScan
4.1 Medium Gutentor Plugin gutentor SQL Injection Admin+ SQL Injection < 3.4.7 Fixed in 3.4.7 CVE-2025-1986 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only