WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,351–17,400 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 348 of 594
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Multi Days Events and Multi Events in One Day Calendar Plugin dragon-calendar-free-version Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31572 Patchstack
7.1 High Related Posts Widget with Thumbnails Plugin advanced-css3-related-posts-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-31570 Patchstack
7.1 High wordpress related Posts with thumbnails Plugin related-posts-list-grid-and-slider-all-in-one Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0.1 CVE-2025-31569 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-31567 Patchstack
7.1 High Rio Video Gallery Plugin rio-video-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.6 CVE-2025-31566 Patchstack
6.5 Medium Uptime Robot Plugin uptime-robot-monitor Cross-Site Scripting ≤ 2.3 CVE-2025-31562 Patchstack
6.5 Medium Custom Database Applications by Caspio Plugin custom-database-applications-by-caspio Cross-Site Scripting ≤ 2.1 CVE-2025-31559 Patchstack
6.5 Medium OSM Plugin osm Cross-Site Scripting ≤ 6.1.13 Fixed in 6.1.14 CVE-2025-31557 Patchstack
6.5 Medium IMPress for IDX Broker Plugin idx-broker-platinum Cross-Site Scripting ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-31556 Patchstack
5.4 Medium ContentMX Content Publisher Plugin contentmx-content-publisher Broken Access Control ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-31555 Patchstack
6.5 Medium Fusion Plugin fusion Cross-Site Scripting ≤ 1.6.4 CVE-2025-31549 Patchstack
8.5 High Uptime Robot Plugin uptime-robot-monitor SQL Injection ≤ 2.3 CVE-2025-31547 Patchstack
4.3 Medium Swiss Toolkit For WP Plugin swiss-toolkit-for-wp Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-31546 Patchstack
5.4 Medium Safe Ai Malware Protection for WP Plugin safe-ai-malware-protection-for-wp Broken Access Control ≤ 1.0.20 CVE-2025-31545 Patchstack
4.3 Medium Swiss Toolkit For WP Plugin swiss-toolkit-for-wp Broken Access Control ≤ 1.4.5 CVE-2025-31544 Patchstack
6.5 Medium Twice Commerce Plugin embed-rentle Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-31543 Patchstack
8.5 High My auctions allegro Plugin my-auctions-allegro-free-edition SQL Injection ≤ 3.6.20 Fixed in 3.6.21 CVE-2025-31542 Patchstack
4.3 Medium ACME Divi Modules Plugin acme-divi-modules Broken Access Control ≤ 1.3.5 CVE-2025-31540 Patchstack
6.5 Medium Cryptocurrency Widgets Pack Plugin cryptocurrency-widgets-pack Broken Access Control ≤ 2.0.1 CVE-2025-31539 Patchstack
6.5 Medium Checklist Plugin checklist Cross-Site Scripting ≤ 1.1.9 CVE-2025-31538 Patchstack
6.5 Medium Simple Owl Carousel Plugin simple-owl-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2025-31535 Patchstack
5.3 Medium Salesmate Add-On for Gravity Forms Plugin gf-salesmate-add-on Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-31533 Patchstack
6.5 Medium AtomChat Plugin atomchat Cross-Site Scripting ≤ 1.1.8 CVE-2025-31532 Patchstack
4.3 Medium Google SEO Pressor Snippet Plugin google-seo-author-snippets Broken Access Control ≤ 2.0 CVE-2025-31530 Patchstack
4.3 Medium Slider Path for Elementor Plugin slider-path Broken Access Control ≤ 3.0.0 CVE-2025-31529 Patchstack
4.3 Medium StaticPress Plugin staticpress Broken Access Control ≤ 0.4.5 CVE-2025-31528 Patchstack
6.4 Medium WP Link Preview Plugin wp-link-preview Server-Side Request Forgery ≤ 1.4.1 CVE-2025-31527 Patchstack
8.5 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-31526 Patchstack
7.1 High Tantyyellow Theme tantyyellow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0.5 CVE-2025-23995 Patchstack
6.5 Medium Churel Theme churel Cross-Site Scripting ≤ 1.0.8 CVE-2025-31419 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-30963 Patchstack
4.3 Medium NanoSupport Plugin nanosupport Broken Access Control ≤ 0.6.0 CVE-2025-31376 Patchstack
5.3 Medium Simple:Press Plugin simplepress Broken Access Control No login needed ≤ 6.11.5 Fixed in 6.11.6 CVE-2025-31386 Patchstack
6.5 Medium Trackserver Plugin trackserver Cross-Site Scripting ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-30961 Patchstack
4.3 Medium ELEX WooCommerce Request a Quote Plugin elex-request-a-quote Broken Access Control ≤ 2.3.9 CVE-2025-31406 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.65 Fixed in 3.2.66 CVE-2025-31414 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.1.22 Fixed in 2.1.22.1 CVE-2025-31412 Patchstack
7.5 High InstaWP Connect Plugin instawp-connect Local File Inclusion No login needed ≤ 0.1.0.82 Fixed in 0.1.0.83 CVE-2025-31387 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Local File Inclusion ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-31016 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-30987 Patchstack
7.5 High Ads by WPQuads Plugin quick-adsense-reloaded Broken Access Control No login needed ≤ 2.0.87.1 Fixed in 2.0.88 CVE-2025-30855 Patchstack
7.5 High Accounting for WooCommerce Plugin accounting-for-woocommerce Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-30835 Patchstack
4.3 Medium WP Docs Plugin wp-docs Broken Access Control ≤ 2.2.7 Fixed in 2.2.7 CVE-2025-31417 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.5.7 Fixed in 3.5.7.1 CVE-2025-31043 Patchstack
6.1 Medium Photo Gallery Plugin photo-gallery Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.8.34 Fixed in 1.8.34 CVE-2025-0613 WPScan
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.7 CVE-2024-11180 Wordfence
8.8 High SoJ Soundslides Plugin soj-soundslides Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2.2 CVE-2025-2249 Wordfence
8.8 High Inline Image Upload for BBPress Plugin image-upload-for-bbpress Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.1.19 CVE-2025-2006 Wordfence
6.5 Medium Shortcodes by United Themes Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.1.6 CVE-2024-13557 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only