WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,701–17,750 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 355 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High AuMenu Plugin aumenu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-23728 Patchstack
7.1 High AppReview Plugin appreview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-23714 Patchstack
7.1 High Your Lightbox Plugin your-lightbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23704 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
7.1 High Management-screen-droptiles Plugin cxc-sawa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23666 Patchstack
7.1 High Frontend Post Submission Plugin frontend-post-submission Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23638 Patchstack
7.1 High WP Database Audit Plugin database-audit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23633 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23612 Patchstack
7.1 High RDP inGroups+ Plugin rdp-ingroups Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-23546 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack
7.1 High RDP Linkedin Login Plugin rdp-linkedin-login Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2025-23542 Patchstack
7.1 High Site Editor Google Map Plugin site-editor-google-map Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23466 Patchstack
7.1 High RWS Enquiry And Lead Follow-up Plugin rws-enquiry Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23460 Patchstack
7.1 High NS Simple Intro Loader Plugin ns-simple-intro-loader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2025-23459 Patchstack
7.1 High GetSocial Plugin getsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-22283 Patchstack
5.7 Medium Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Information Disclosure Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 1.6.8 CVE-2025-2228 Wordfence
7.2 High Product Import Export for WooCommerce Plugin product-import-export-for-woo PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.5.0 CVE-2025-1913 Wordfence
2.7 Low Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.5.0 CVE-2025-1911 Wordfence
7.6 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.5.0 CVE-2025-1912 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.7 CVE-2025-1312 Wordfence
6.4 Medium Zapier Plugin zapier Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user Function ≤ 1.5.1 CVE-2024-13411 Wordfence
4.9 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.5.0 CVE-2025-1769 Wordfence
7.2 High WordPress Importer Plugin wordpress-importer PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 0.8.3 CVE-2024-13889 Wordfence
8.8 High WP Compress Plugin wp-compress-image-optimizer Broken Access Control Authenticated (Subscriber+) Missing Authorization via Multiple Functions ≤ 6.30.15 CVE-2025-2110 Wordfence
5.3 Medium Advanced iFrame Plugin advanced-iframe Broken Access Control Unauthenticated Settings Update No login needed ≤ 2024.5 CVE-2025-1440 Wordfence
6.4 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via content Parameter ≤ 3.2.7 CVE-2025-1703 Wordfence
6.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header ≤ 2024.5 CVE-2025-1439 Wordfence
6.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2025.2 CVE-2025-1437 Wordfence
6.5 Medium Jobs Plugin job-postings Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 2.7.11 CVE-2025-1310 Wordfence
6.4 Medium CRM and Lead Management by vcita Plugin crm-customer-relationship-management-by-vcita Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.4 CVE-2024-13702 Wordfence
7.3 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Broken Access Control Unauthenticated Arbitrary Filter Call No login needed ≤ 1.0.6.7 CVE-2025-1514 Wordfence
8.1 High BWL Advanced FAQ Manager Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.1.4 CVE-2024-13801 Wordfence
5.4 Medium Event post Plugin event-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.9 CVE-2025-2167 Wordfence
7.2 High Newsletters Plugin newsletters-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.9.9.7 CVE-2025-2009 Wordfence
7.2 High Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Remote Code Execution WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection ≤ 1.16.10 CVE-2025-2257 Wordfence
8.8 High Booknetic Plugin Cross-Site Request Forgery Staff Creation via CSRF No login needed < 4.1.5 Fixed in 4.1.5 CVE-2024-13146 WPScan
3.5 Low Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Scripting Admin+ Stored XSS < 1.5.2 Fixed in 1.5.2 CVE-2024-12683 WPScan
4.8 Medium WP SVG Upload Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 1.0.0 CVE-2024-11847 WPScan
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.19.0 CVE-2025-1784 Wordfence
6.1 Medium SH Email Alert Plugin sh-email-alert Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-2165 Wordfence
6.1 Medium Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Scripting Reflected Cross-Site Scripting via setstatus Parameter No login needed ≤ 1.5.2 CVE-2025-1490 Wordfence
6.4 Medium Ayyash Studio Plugin ayyash-studio Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.3 CVE-2025-2576 Wordfence
6.4 Medium Amazing service box Addons For WPBakery Page Builder Plugin amazing-service-box-visual-composer-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.0.0 CVE-2025-2573 Wordfence
4.3 Medium Ultimate Dashboard Plugin ultimate-dashboard Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Modules Activation/Deactivation ≤ 3.8.7 CVE-2025-2276 Wordfence
6.4 Medium Advanced Woo Search Plugin advanced-woo-search Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aws_search_terms Shortcode ≤ 3.28 CVE-2025-2302 Wordfence
7.5 High WP01 Plugin wp01 Path Traversal Arbitrary File Download No login needed ≤ 2.6.2 CVE-2025-30567 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-28904 Patchstack
6.5 Medium Gallery for Social Photo Plugin feed-instagram-lite Cross-Site Scripting ≤ 1.0.0.35 Fixed in 1.0.0.37 CVE-2025-26742 Patchstack
5.8 Medium WP Compress Plugin wp-compress-image-optimizer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via init Function No login needed ≤ 6.30.15 CVE-2025-2109 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only