WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,501–17,550 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 351 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 2.10.44 Fixed in 2.10.45 CVE-2025-22659 Patchstack
6.5 Medium Include Mastodon Feed Plugin include-mastodon-feed Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2025-22660 Patchstack
4.3 Medium RapidLoad Plugin unusedcss Broken Access Control ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-22665 Patchstack
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
6.5 Medium Awesome Event Booking Plugin awesome-event-booking Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.5 CVE-2025-22668 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
6.5 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-22670 Patchstack
4.3 Medium Disable Elementor Editor Translation Plugin disable-elementor-editor-translation Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-22671 Patchstack
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control ≤ 5.3.5 Fixed in 5.4.0 CVE-2025-22673 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
5.4 Medium Envo Multipurpose Theme envo-multipurpose Broken Access Control ≤ 1.1.6 CVE-2025-22770 Patchstack
7.1 High Secret Meta Plugin facebook-secret-meta Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-25086 Patchstack
6.5 Medium Power Mag Plugin power-mag Cross-Site Scripting ≤ 1.1.5 CVE-2025-22816 Patchstack
7.1 High Cazamba Plugin cazamba Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25100 Patchstack
6.5 Medium ARPrice Plugin arprice Cross-Site Scripting ≤ 4.1.3 CVE-2025-26731 Patchstack
6.5 Medium StoreBiz Plugin storebiz Cross-Site Scripting ≤ 1.0.32 CVE-2025-26732 Patchstack
6.5 Medium Hester Plugin hester Cross-Site Scripting ≤ 1.1.10 CVE-2025-26734 Patchstack
6.5 Medium MorningTime Lite Plugin morningtime-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-26736 Patchstack
6.5 Medium City Store Theme city-store Cross-Site Scripting ≤ 1.4.5 CVE-2025-26737 Patchstack
6.5 Medium Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting ≤ 3.1.5 CVE-2025-26738 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30925 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
6.5 Medium Simplebooklet PDF Viewer and Embedder Plugin simplebooklet Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-30922 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.9.9.7 Fixed in 4.9.9.8 CVE-2025-30921 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-30920 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-30918 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.3 Fixed in 7.2.4 CVE-2025-30909 Patchstack
6.5 Medium SecuPress Free Plugin secupress Cross-Site Scripting ≤ 2.2.5.3 Fixed in 2.2.5.4 CVE-2025-30907 Patchstack
5.9 Medium Chartify Plugin chart-builder Cross-Site Scripting ≤ 3.1.7 Fixed in 3.1.9 CVE-2025-30904 Patchstack
6.5 Medium SyntaxHighlighter Evolved Plugin syntaxhighlighter Cross-Site Scripting ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30903 Patchstack
6.5 Medium Zoho Billing – Embed Payment Form Plugin zoho-subscriptions Cross-Site Scripting Embed Payment Form plugin <= 4.0 - Stored Cross Site Scripting (XSS) ≤ 4.0 Fixed in 4.1 CVE-2025-30900 Patchstack
5.9 Medium User Registration Plugin user-registration Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-30899 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-30898 Patchstack
4.3 Medium Analytify Plugin wp-analytify Broken Access Control Settings Change ≤ 5.5.1 Fixed in 6.0.0 CVE-2025-30897 Patchstack
5.4 Medium WP ERP Plugin erp Broken Access Control ≤ 1.13.4 Fixed in 1.14.0 CVE-2025-30896 Patchstack
7.5 High WpEvently Plugin mage-eventpress PHP Object Injection ≤ 4.2.9 Fixed in 4.3.0 CVE-2025-30895 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Broken Access Control ≤ 1.79.262 Fixed in 1.79.264 CVE-2025-30894 Patchstack
6.5 Medium LeadConnector Plugin leadconnector Cross-Site Scripting ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-30893 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager Local File Inclusion ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30891 Patchstack
7.5 High Login Widget for Ultimate Member Plugin login-widget-for-ultimate-member Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-30890 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 4.2.9 Fixed in 4.3.0 CVE-2025-30887 Patchstack
4.7 Medium Bit Form Plugin bit-form Open Redirect No login needed ≤ 2.18.0 Fixed in 2.18.1 CVE-2025-30885 Patchstack
4.7 Medium Bit Integrations Plugin bit-integrations Open Redirect No login needed ≤ 2.4.10 Fixed in 2.5.0 CVE-2025-30884 Patchstack
4.3 Medium Trust.Reviews Plugin fb-reviews-widget Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2025-30883 Patchstack
4.3 Medium Big Store Plugin big-store Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-30881 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.8.9 Fixed in 1.9.0 CVE-2025-30879 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only