WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,701–1,750 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
6.5 Medium Slider Templates Plugin slider-templates Broken Access Control No login needed ≤ 1.0.3 CVE-2025-68009 Patchstack
6.5 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Settings Change No login needed ≤ 5.0.37.decaf Fixed in 5.0.53.decaf CVE-2025-68007 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
6.5 Medium Shown Connector Plugin shown-connector Broken Access Control Settings Change No login needed ≤ 1.2.10 CVE-2025-68003 Patchstack
6.4 Medium WPO365 Plugin wpo365-login Server-Side Request Forgery ≤ 40.0 Fixed in 40.1 CVE-2025-67961 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2025-67942 Patchstack
6.5 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.2 Fixed in 3.5.6.3 CVE-2025-67939 Patchstack
4.3 Medium WP SEO Search Plugin wp-seo-search Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-67626 Patchstack
5.4 Medium Crumber Plugin crumber-elementor Broken Access Control ≤ 1.0.10 CVE-2025-66143 Patchstack
5.4 Medium Comparimager for Elementor Plugin comparimager-elementor Broken Access Control ≤ 1.0.1 CVE-2025-66142 Patchstack
5.4 Medium Scroller Plugin scroller Broken Access Control ≤ 2.0.2 CVE-2025-66141 Patchstack
5.4 Medium Uper for Elementor Plugin uper-elementor Broken Access Control ≤ 1.0.5 CVE-2025-66140 Patchstack
5.4 Medium Audier For Elementor Plugin audier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66139 Patchstack
5.4 Medium Motionger for Elementor Plugin motionger-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66138 Patchstack
5.4 Medium Searcher for Elementor Plugin searcher-elementor Broken Access Control ≤ 1.0.3 CVE-2025-66137 Patchstack
5.4 Medium Carter for Elementor Plugin carter-elementor Broken Access Control ≤ 1.0.2 CVE-2025-66136 Patchstack
5.4 Medium Imager for Elementor Plugin imager-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66135 Patchstack
4.9 Medium ANAC XML Viewer Plugin anac-xml-viewer Server-Side Request Forgery ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-64252 Patchstack
4.3 Medium REHub Framework Plugin rehub-framework Information Disclosure Sensitive Data Exposure ≤ 19.9.9.4 Fixed in 19.9.9.4 CVE-2025-63051 Patchstack
6.5 Medium Grand Restaurant Theme Elements for Elementor Plugin grandrestaurant-elementor Cross-Site Scripting ≤ 2.1.1 CVE-2025-63026 Patchstack
5.3 Medium Cookies and Content Security Policy Plugin cookies-and-content-security-policy Information Disclosure Sensitive Data Exposure No login needed ≤ 2.34 Fixed in 2.35 CVE-2025-63019 Patchstack
4.3 Medium Bard Plugin bard Broken Access Control ≤ 2.229 CVE-2025-63018 Patchstack
5.3 Medium Payment Gateway bKash for WC Plugin woo-payment-bkash Broken Access Control No login needed ≤ 3.1.0 CVE-2025-62754 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack
5.4 Medium WP-CRM System Plugin wp-crm-system Broken Access Control ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-62106 Patchstack
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
6.5 Medium Electron Plugin electron Broken Access Control ≤ 1.8.2 CVE-2025-5805 Patchstack
6.5 Medium xSmart Plugin xsmart Broken Access Control ≤ 1.2.9.4 CVE-2025-54002 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50005 Patchstack
5.4 Medium HomeLancer Plugin homelancer Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-49375 Patchstack
5.9 Medium Pondol BBS Plugin pondol-bbs Cross-Site Scripting ≤ 1.1.8.4 CVE-2025-49336 Patchstack
5.3 Medium WoodMart Theme woodmart Arbitrary Shortcode Execution No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2025-47600 Patchstack
5.9 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting ≤ 3.19.5 Fixed in 3.19.6 CVE-2025-47500 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Request Forgery No login needed ≤ 8.3.13 Fixed in 8.3.14 CVE-2025-31413 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API No login needed ≤ 4.3.2.4 CVE-2025-14798 Wordfence
4.3 Medium Newsletter – Send awesome emails from Plugin newsletter Cross-Site Request Forgery Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription No login needed ≤ 9.1.0 CVE-2026-1051 Wordfence
4.3 Medium Phrase TMS Integration Plugin memsource-connector Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 4.7.5 CVE-2025-12168 Wordfence
5.0 Medium DK PDF – WordPress PDF Generator Plugin dk-pdf Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery ≤ 2.3.0 CVE-2025-14793 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
6.5 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed ≤ 6.3.6 CVE-2025-12641 Wordfence
4.3 Medium SocialChamp with Plugin auto-post-to-social-media-wp-to-social-champ Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.3.5 CVE-2025-14846 Wordfence
6.4 Medium Woodpecker Plugin woodpecker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_name' Shortcode Attribute ≤ 3.0.4 CVE-2025-13967 Wordfence
5.3 Medium Re Gallery Plugin regallery Broken Access Control No login needed ≤ 1.18.9 Fixed in 1.18.10 CVE-2026-22486 Patchstack
4.3 Medium Speed Kit Plugin baqend Broken Access Control ≤ 2.0.2 CVE-2026-22487 Patchstack
5.3 Medium Dashboard Welcome for Beaver Builder Plugin dashboard-welcome-for-beaver-builder Broken Access Control No login needed ≤ 1.0.8 CVE-2026-22488 Patchstack
4.3 Medium Image Slider Slideshow Plugin image-slider-slideshow Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8 CVE-2026-22489 Patchstack
5.4 Medium Bulk Landing Page Creator for WordPress LPagery Plugin lpagery Broken Access Control ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-22490 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only