WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,251–17,300 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 346 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Bridge Core Plugin bridge-core Cross-Site Scripting < 3.3.1 Fixed in 3.3.1 CVE-2025-31409 Patchstack
8.5 High RJ Quickcharts Plugin rj-quickcharts SQL Injection ≤ 0.6.1 CVE-2025-31024 Patchstack
7.5 High GTM Kit Plugin gtm-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-31001 Patchstack
9.3 Critical XV Random Quotes Plugin xv-random-quotes SQL Injection No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-30971 Patchstack
8.8 High Vitepos Plugin vitepos-lite Authentication Bypass Broken Authentication ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-22277 Patchstack
7.6 High YayExtra Plugin yayextra Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-31415 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31095 Patchstack
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
9.8 Critical Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection No login needed ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-31084 Patchstack
8.8 High Mobile DJ Manager Plugin mobile-dj-manager PHP Object Injection ≤ 1.7.5.2 Fixed in 1.7.5.3 CVE-2025-31074 Patchstack
4.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control ≤ 24.12.58 Fixed in 24.12.59 CVE-2025-30926 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.4 Fixed in 4.2.4 CVE-2025-30924 Patchstack
7.1 High SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30917 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
8.6 High CM Download Manager Plugin cm-download-manager Arbitrary File Deletion No login needed ≤ 2.9.6 Fixed in 3.0.0 CVE-2025-30910 Patchstack
7.1 High AEC Kiosque Plugin aec-kiosque Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.3 Fixed in 1.9.4 CVE-2025-30902 Patchstack
8.1 High JS Help Desk Plugin js-support-ticket Local File Inclusion No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30901 Patchstack
9.3 Critical JS Help Desk Plugin js-support-ticket SQL Injection No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30886 Patchstack
7.5 High JS Help Desk Plugin js-support-ticket Path Traversal Arbitrary File Download No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-30882 Patchstack
7.5 High JS Help Desk Plugin js-support-ticket Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30880 Patchstack
8.6 High JS Help Desk Plugin js-support-ticket Arbitrary File Deletion No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30878 Patchstack
9.3 Critical Ads by WPQuads Plugin quick-adsense-reloaded SQL Injection No login needed ≤ 2.0.87.1 Fixed in 2.0.88 CVE-2025-30876 Patchstack
8.1 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion No login needed ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-30870 Patchstack
7.1 High Image Wall Plugin image-wall Cross-Site Scripting No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-30869 Patchstack
8.1 High Essential Real Estate Plugin essential-real-estate Local File Inclusion No login needed ≤ 5.2.0 Fixed in 5.2.1 CVE-2025-30849 Patchstack
7.1 High Hostel Plugin hostel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 Fixed in 1.1.5.5 CVE-2025-30848 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.5 Fixed in 2.12.5.1 CVE-2025-30840 Patchstack
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.5 High Bit Assist Plugin bit-assist Path Traversal No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30834 Patchstack
7.1 High WP2LEADS Plugin wp2leads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.5 Fixed in 3.4.7 CVE-2025-30827 Patchstack
7.1 High About Author Plugin about-author Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30808 Patchstack
4.3 Medium Our Team Members Plugin our-team-members Information Disclosure Sensitive Data Exposure ≤ 2.2 Fixed in 2.3 CVE-2025-30802 Patchstack
7.1 High Better WishList API Plugin better-wlm-api Cross-Site Scripting No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-30798 Patchstack
7.5 High Greek Multi Tool – Fix peralinks, accents, auto create menus and more Plugin greek-multi-tool Broken Access Control Fix peralinks, accents, auto create menus and more plugin <= 2.3.1 - Broken Access Control No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-30797 Patchstack
7.1 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended plugin <= 3.0.14 - Cross Site Scripting (XSS) No login needed ≤ 3.0.14 Fixed in 3.0.15 CVE-2025-30796 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.20.0 Fixed in 5.20.1 CVE-2025-30794 Patchstack
7.5 High Houzez Property Feed Plugin houzez-property-feed Path Traversal Arbitrary File Download No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-30793 Patchstack
7.5 High Subscribe to Download Lite Plugin subscribe-to-download-lite Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-30782 Patchstack
8.2 High Quiz Maker Plugin quiz-maker SQL Injection No login needed ≤ 6.6.8.7 Fixed in 6.6.8.8 CVE-2025-30774 Patchstack
9.3 Critical PostMash Plugin postmash-custom SQL Injection No login needed ≤ 1.0.3 CVE-2025-30622 Patchstack
7.1 High Google Font Fix Plugin google-font-fix Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.1 CVE-2025-30614 Patchstack
6.5 Medium Nmedia MailChimp Plugin nmedia-mailchimp-widget Cross-Site Scripting ≤ 5.4 CVE-2025-30613 Patchstack
7.1 High Quick Localization Plugin quick-localization Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.0 CVE-2025-30607 Patchstack
6.5 Medium Include URL Plugin include-url Path Traversal WordPress Include URL plugin <= 0.3.5 Arbitrary File Download ≤ 0.3.5 CVE-2025-30594 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30589 Patchstack
7.1 High Pesapal Gateway for Woocommerce Plugin pesapal-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-30579 Patchstack
7.1 High Tidekey Plugin tidekey Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-30563 Patchstack
7.1 High Kento WordPress Stats Plugin kento-wp-stats Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-30559 Patchstack
7.1 High Advanced Post Search Plugin advanced-post-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-30548 Patchstack
7.1 High WP Cards Plugin wp-cards Cross-Site Scripting No login needed ≤ 1.5.1 CVE-2025-30547 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only