WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,401–17,450 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 349 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High So-Called Air Quotes Plugin so-called-air-quotes Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.1 CVE-2025-2803 Wordfence
9.8 Critical Checkout Mestres do WP for WooCommerce Plugin checkout-mestres-wp Broken Access Control Unauthenticated Arbitrary Options Update No login needed 8.6.5 – 8.7.5 CVE-2025-2266 Wordfence
5.3 Medium DAP to Autoresponders Email Syncing Plugin dap-to-autoresponders-daar Information Disclosure Unauthenticated Information Exposure No login needed ≤ 1.0 CVE-2025-2840 Wordfence
4.3 Medium SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Request Forgery CSRF to Multiple Admin Actions ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-31010 Patchstack
7.1 High GlobalPayments WooCommerce Plugin global-payments-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2025-22767 Patchstack
7.1 High SUPER RESPONSIVE SLIDER Plugin super-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22575 Patchstack
7.1 High ULTIMATE VIDEO GALLERY Plugin ultimate-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22566 Patchstack
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack
9.3 Critical Schedule Plugin schedule SQL Injection No login needed ≤ 1.0.0 CVE-2025-22523 Patchstack
7.1 High Improve My City Plugin improve-my-city Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-22501 Patchstack
7.1 High WP Azure offload Plugin wp-azure-offload Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-22360 Patchstack
7.1 High Stencies Plugin stencies Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.58 CVE-2025-22356 Patchstack
8.1 High GetShop ecommerce Plugin getshop-ecommerce Path Traversal No login needed ≤ 1.3 CVE-2024-54362 Patchstack
8.6 High PluginPass Plugin pluginpass-pro-plugintheme-licensing Path Traversal Arbitrary File Download/Delete No login needed ≤ 0.9.10 CVE-2024-54291 Patchstack
7.1 High Já-Já Pagamentos for WooCommerce Plugin wc-ja-ja-pagamentos-multicaixa-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51624 Patchstack
7.5 High Pop-Up Chop Chop Plugin pop-up Local File Inclusion ≤ 2.1.7 CVE-2025-31432 Patchstack
6.5 Medium Magic Embeds Plugin wp-embed-facebook Cross-Site Scripting ≤ 3.1.2 CVE-2025-31433 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
6.5 Medium FormLift for Infusionsoft Web Forms Plugin formlift Cross-Site Scripting ≤ 7.5.19 Fixed in 7.5.20 CVE-2025-31434 Patchstack
4.3 Medium WP Supersized Plugin wp-supersized Cross-Site Request Forgery No login needed ≤ 3.1.6 CVE-2025-31438 Patchstack
5.9 Medium WP-OGP Plugin wp-ogp Cross-Site Scripting ≤ 1.0.5 CVE-2025-31437 Patchstack
5.4 Medium Browser Caching with .htaccess Plugin browser-caching-with-htaccess Cross-Site Request Forgery No login needed 1.2.1 CVE-2025-31439 Patchstack
7.1 High KK I Like It Plugin kk-i-like-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.5.3 CVE-2025-31443 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
5.4 Medium Simple Trackback Disabler Plugin simple-trackback-disabler Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-31448 Patchstack
5.4 Medium NertWorks All in One Social Share Tools Plugin nertworks-all-in-one-social-share-tools Cross-Site Request Forgery No login needed ≤ 1.26 CVE-2025-31447 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
6.5 Medium wBounce Plugin wbounce Cross-Site Scripting ≤ 1.8.1 CVE-2025-31451 Patchstack
6.5 Medium Toggle Box Plugin toggle-box Cross-Site Scripting ≤ 1.6 CVE-2025-31450 Patchstack
6.5 Medium YouTube SimpleGallery Plugin youtube-simplegallery Cross-Site Scripting ≤ 2.0.6 CVE-2025-31453 Patchstack
6.5 Medium WP Ultimate Search Plugin wp-ultimate-search Cross-Site Scripting ≤ 2.0.3 CVE-2025-31452 Patchstack
4.3 Medium Ultimate Security Checker Plugin ultimate-security-checker Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Security Rescan No login needed ≤ 4.2 CVE-2025-31456 Patchstack
7.1 High Video Embedder Plugin video-embedder Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.7.1 Fixed in 1.8 CVE-2025-31458 Patchstack
5.4 Medium LWS SMS Plugin lws-sms Cross-Site Request Forgery No login needed ≤ 2.4.1 CVE-2025-31457 Patchstack
7.1 High Login Alert Plugin login-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.1 CVE-2025-31459 Patchstack
5.9 Medium TGG WP Optimizer Plugin tgg-wp-optimizer Cross-Site Scripting ≤ 1.25 CVE-2025-31463 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
5.9 Medium Text Selection Color Plugin text-selection-color Cross-Site Scripting ≤ 1.6 CVE-2025-31464 Patchstack
8.5 High Duplicate Page and Post Plugin duplicate-post-and-page SQL Injection ≤ 1.0 CVE-2025-31466 Patchstack
6.5 Medium Better Section Navigation Widget Plugin better-section-navigation Cross-Site Scripting ≤ 1.6.1 Fixed in 1.7.0 CVE-2025-31465 Patchstack
5.3 Medium Clear Sucuri Cache Plugin clear-sucuri-cache Broken Access Control No login needed ≤ 1.4 CVE-2025-31469 Patchstack
5.9 Medium Duplicate Page and Post Plugin duplicate-post-and-page Cross-Site Scripting ≤ 1.0 CVE-2025-31471 Patchstack
5.9 Medium Page Takeover Plugin page-takeover Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-31470 Patchstack
5.9 Medium Flatty Plugin flatty-flat-admin-theme Cross-Site Scripting ≤ 2.0.0 CVE-2025-31472 Patchstack
4.3 Medium WP Database Optimizer Plugin wp-database-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.1.3 CVE-2025-31474 Patchstack
5.9 Medium WP Database Optimizer Plugin wp-database-optimizer Cross-Site Scripting ≤ 1.2.1.3 CVE-2025-31473 Patchstack
8.8 High Administrator Z Plugin administrator-z Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 2025.03.24 CVE-2025-2815 Wordfence
6.5 Medium MicroPayments Plugin paid-membership Cross-Site Scripting ≤ 2.9.29 Fixed in 2.9.30 CVE-2025-31075 Patchstack
6.5 Medium Unlimited Plugin unlimited Cross-Site Scripting ≤ 1.45 Fixed in 1.46 CVE-2025-31073 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only