WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,601–17,650 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 353 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Live Forms Plugin liveforms Broken Access Control Live Forms plugin <= 4.8.4 - Settings Change ≤ 4.8.4 Fixed in 4.8.5 CVE-2025-30809 Patchstack
8.5 High Vimeotheque Plugin codeflavors-vimeo-video-post-lite SQL Injection ≤ 2.3.4.2 Fixed in 2.3.4.3 CVE-2025-30806 Patchstack
4.3 Medium Flexible Cookies Plugin flexible-cookies Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-30805 Patchstack
4.3 Medium wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-30804 Patchstack
4.3 Medium Just Writing Statistics Plugin just-writing-statistics Broken Access Control ≤ 5.3 Fixed in 5.4 CVE-2025-30803 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.10 Fixed in 1.3.11 CVE-2025-30800 Patchstack
5.9 Medium WP Google Street View Plugin wp-google-street-view Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-30799 Patchstack
4.7 Medium FunnelKit Automations Plugin wp-marketing-automations Open Redirect No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-30795 Patchstack
5.9 Medium Comment Approved Notifier Extended Plugin comment-approved-notifier-extended Cross-Site Scripting ≤ 5.2 Fixed in 5.3 CVE-2025-30792 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
5.3 Medium Chatbox Manager Plugin wa-chatbox-manager Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-30790 Patchstack
5.9 Medium Clearout Email Validator Plugin clearout-email-validator Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-30789 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
6.5 Medium Quotes llama Plugin quotes-llama Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-30786 Patchstack
7.5 High Subscribe to Download Lite Plugin subscribe-to-download-lite Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-30785 Patchstack
8.5 High WP Subscription Forms Plugin wp-subscription-forms SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-30784 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
4.7 Medium Scheduled & Automatic Order Status Controller for WooCommerce Plugin order-status-rules-for-woocommerce Open Redirect No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30781 Patchstack
6.5 Medium Audio Album Plugin audio-album Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-30780 Patchstack
6.5 Medium Doneren met Mollie Plugin doneren-met-mollie Cross-Site Scripting ≤ 2.10.7 Fixed in 2.10.8 CVE-2025-30779 Patchstack
4.3 Medium Support Genix Plugin support-genix-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.11 Fixed in 1.4.12 CVE-2025-30777 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-30776 Patchstack
8.5 High WPGuppy Plugin wpguppy-lite SQL Injection ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-30775 Patchstack
7.2 High TranslatePress Plugin translatepress-multilingual PHP Object Injection ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-30773 Patchstack
6.5 Medium WP Cassify Plugin wp-cassify Cross-Site Scripting ≤ 2.3.5 Fixed in 2.3.6 CVE-2025-30771 Patchstack
6.5 Medium Charitable Plugin charitable Cross-Site Scripting ≤ 1.8.4.7 Fixed in 1.8.4.8 CVE-2025-30770 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
6.5 Medium jAlbum Bridge Plugin jalbum-bridge Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2025-30768 Patchstack
5.4 Medium PDF for WPForms Plugin pdf-for-wpforms Arbitrary Shortcode Execution ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-30767 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.16.2 Fixed in 3.16.3 CVE-2025-30766 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
4.3 Medium Football Pool Plugin football-pool Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2025-30764 Patchstack
6.5 Medium EO4WP Plugin fw-integration-for-emailoctopus Cross-Site Scripting ≤ 1.0.8.4 Fixed in 1.0.8.5 CVE-2025-30763 Patchstack
6.4 Medium TablePress – Tables in WordPress made easy Plugin tablepress Cross-Site Scripting Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.0.4 CVE-2025-2685 Wordfence
9.8 Critical Export All Posts, Products, Orders, Refunds & Users Plugin wp-ultimate-exporter PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.13 CVE-2025-2332 Wordfence
6.1 Medium MediaView Plugin mediaview Cross-Site Scripting Reflected Cross-Site Scripting via id Parameter No login needed ≤ 1.1.2 CVE-2025-2481 Wordfence
6.5 Medium newseqo Theme newseqo Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.1 CVE-2025-26739 Patchstack
6.5 Medium RainbowNews Theme rainbownews Cross-Site Scripting ≤ 1.0.7 CVE-2025-26747 Patchstack
6.5 Medium Build Theme build Cross-Site Scripting ≤ 1.0.3 CVE-2025-26869 Patchstack
6.5 Medium AuraMart Plugin auramart Cross-Site Scripting ≤ 2.0.7 CVE-2025-26922 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.9.8 Fixed in 5.9.9 CVE-2025-26923 Patchstack
5.9 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-26929 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.0.18 Fixed in 5.0.19 CVE-2025-26941 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 30.1 Fixed in 30.1 CVE-2025-27014 Patchstack
7.5 High Hostiko Plugin hostiko Local File Inclusion ≤ 30.1 Fixed in 30.1 CVE-2025-27015 Patchstack
9.3 Critical Product Catalog Plugin displayproduct SQL Injection No login needed ≤ 1.0.4 CVE-2025-30524 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only