WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,301–17,350 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 347 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High OK Poster Group Plugin ok-poster-group Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-30544 Patchstack
7.1 High Breezing Forms Plugin breezing-forms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8.11 CVE-2025-30520 Patchstack
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.11.14 CVE-2025-1665 Wordfence
7.5 High Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Information Disclosure WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 6.3.1 CVE-2024-13567 Wordfence
8.8 High Import Export Suite for CSV and XML Datafeed Plugin wp-ultimate-csv-importer Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.19, 7.20 CVE-2025-2008 Wordfence
8.1 High Import Export Suite for CSV and XML Datafeed Plugin wp-ultimate-csv-importer Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 7.19, 7.20 CVE-2025-2007 Wordfence
6.5 Medium Infusionsoft Web Form JavaScript Plugin infusionsoft-web-form-javascript Cross-Site Scripting ≤ 1.1.1 CVE-2025-31629 Patchstack
5.9 Medium Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.24 Fixed in 3.25 CVE-2025-31627 Patchstack
7.1 High Useinfluence Plugin useinfluence Cross-Site Request Forgery No login needed ≤ 1.0.8 CVE-2025-31625 Patchstack
6.5 Medium Processing Projects Plugin processing-projects Cross-Site Scripting ≤ 1.0.2 CVE-2025-31624 Patchstack
7.1 High Rich Text Editor Plugin richtexteditor Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-31623 Patchstack
6.5 Medium byBrick Accordion Plugin bybrick-accordion Cross-Site Scripting ≤ 1.0 CVE-2025-31621 Patchstack
6.5 Medium CoverManager Plugin covermanager Cross-Site Scripting ≤ 0.0.1 CVE-2025-31620 Patchstack
5.3 Medium Connector to CiviCRM with CiviMcRestFace Plugin connector-civicrm-mcrestface Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2025-31618 Patchstack
7.1 High PostmarkApp Email Integrator Plugin postmarkapp-email-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 Fixed in 2.5.0 CVE-2025-31617 Patchstack
7.1 High Varnish Plugin varnish-wp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-31616 Patchstack
7.1 High Simple Contact Forms Plugin simple-contact-forms Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.4 CVE-2025-31615 Patchstack
6.5 Medium Terms Before Download Plugin terms-before-download Cross-Site Scripting ≤ 1.0.5 CVE-2025-31614 Patchstack
7.1 High AB Google Map Travel Plugin ab-google-map-travel Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.6 CVE-2025-31613 Patchstack
4.3 Medium Auto Post After Image Upload Plugin auto-post-after-image-upload Broken Access Control ≤ 1.6 CVE-2025-31611 Patchstack
5.9 Medium Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any Plugin gp-notification-bar Cross-Site Scripting ≤ 1.1 CVE-2025-31610 Patchstack
4.3 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Insecure Direct Object References (IDOR) ≤ 8.0.2 CVE-2025-31609 Patchstack
6.5 Medium CookieHint WP Plugin cookiehint-wp Cross-Site Scripting ≤ 1.0.0 CVE-2025-31608 Patchstack
6.5 Medium Simple-Audioplayer Plugin simple-audioplayer Cross-Site Scripting ≤ 1.1 CVE-2025-31607 Patchstack
4.8 Medium SP Blog Designer Plugin sp-blog-designer Arbitrary Shortcode Execution No login needed ≤ 1.0.0 CVE-2025-31606 Patchstack
5.9 Medium Welcome Popup Plugin welcome-popup Cross-Site Scripting ≤ 1.0.10 CVE-2025-31605 Patchstack
6.5 Medium Cal.com Plugin cal-com Cross-Site Scripting ≤ 1.0.0 Fixed in 2.0.0 CVE-2025-31604 Patchstack
5.4 Medium CF7 Spreadsheets Plugin cf7-spreadsheets Broken Access Control Settings Change ≤ 2.3.2 CVE-2025-31603 Patchstack
4.3 Medium Apimo Connector Plugin apimo Cross-Site Request Forgery No login needed ≤ 2.6.5.1 CVE-2025-31602 Patchstack
6.5 Medium Appointy Appointment Scheduler Plugin appointy-appointment-scheduler Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 4.2.1 CVE-2025-31601 Patchstack
4.3 Medium DesignO Plugin designo Cross-Site Request Forgery No login needed ≤ 2.6.0 CVE-2025-31600 Patchstack
6.5 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-31598 Patchstack
6.5 Medium Ultimate Live Cricket WordPress Lite Plugin ultimate-live-cricket-lite Cross-Site Scripting ≤ 1.4.2 CVE-2025-31597 Patchstack
4.3 Medium Chat by Chatwee Plugin chatwee Broken Access Control ≤ 2.1.3 CVE-2025-31596 Patchstack
6.5 Medium Timeline Event History Plugin timeline-event-history Cross-Site Scripting ≤ 3.2 CVE-2025-31595 Patchstack
6.5 Medium OpenMenu Plugin open-menu Cross-Site Scripting ≤ 3.5 CVE-2025-31593 Patchstack
6.5 Medium Send E-mail Plugin send-e-mail Cross-Site Scripting ≤ 1.3 CVE-2025-31592 Patchstack
5.9 Medium Exit Popup Free Plugin exit-popup-free Cross-Site Scripting ≤ 1.0 CVE-2025-31591 Patchstack
6.5 Medium WP Date and Time Shortcode Plugin wp-date-and-time-shortcode Cross-Site Scripting ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-31590 Patchstack
6.5 Medium Ethiopian Calendar Plugin ethiopian-calendar Cross-Site Scripting ≤ 1.1.1 CVE-2025-31589 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
5.9 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Scripting ≤ 1.0.1 CVE-2025-31587 Patchstack
6.5 Medium Gallery – Photo Albums Plugin easy-media-gallery Cross-Site Scripting Photo Albums Plugin plugin <= 1.3.170 - Stored Cross Site Scripting (XSS) ≤ 1.3.170 CVE-2025-31586 Patchstack
7.1 High Leadfox Plugin leadfox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-31585 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Broken Access Control ≤ 1.0.1 CVE-2025-31584 Patchstack
7.1 High WP Copy Media URL Plugin wp-copy-media-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-31583 Patchstack
6.6 Medium Appointify Plugin appointify Arbitrary File Upload ≤ 1.0.8 CVE-2025-31577 Patchstack
4.3 Medium PostmarkApp Email Integrator Plugin postmarkapp-email-integrator Broken Access Control ≤ 2.4 Fixed in 2.5.0 CVE-2025-31576 Patchstack
5.9 Medium Flag Icons Plugin language-icons-flags-switcher Cross-Site Scripting ≤ 2.2 CVE-2025-31575 Patchstack
6.5 Medium Custom Content Scrollbar Plugin custom-content-scrollbar Cross-Site Scripting ≤ 1.3 CVE-2025-31574 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only