WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,751–17,800 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 356 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Digital License Manager Plugin digital-license-manager Cross-Site Scripting Reflected Cross-Site Scripting via remove_query_arg Function No login needed ≤ 1.7.3 CVE-2025-2635 Wordfence
6.4 Medium Your Simple SVG Support Plugin your-simple-svg-support Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.1 CVE-2025-2542 Wordfence
8.8 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed 4.11.13 – 5.25.08 CVE-2025-2319 Wordfence
7.2 High WP Church Donation Plugin wp-church-donation Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.7 CVE-2024-13690 Wordfence
6.4 Medium Alert Box Block – Display notice/alerts in the front end Plugin alert-box-block Cross-Site Scripting Display notice/alerts in the front end <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Alert Box Block ≤ 1.1.3 CVE-2024-13731 Wordfence
4.3 Medium Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings <= 5.5.0 - Cross-Site Request Forgery to Settings Update No login needed ≤ 5.5.0 CVE-2024-13710 Wordfence
5.5 Medium Frndzk Expandable Bottom Bar Plugin frndzk-expandable-bottom-bar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via text Parameter ≤ 1.0 CVE-2025-2510 Wordfence
4.3 Medium teachPress Plugin teachpress Cross-Site Request Forgery Cross-Site Request Forgery to Import Delete No login needed ≤ 9.0.9 CVE-2025-1320 Wordfence
6.4 Medium DICOM Support Plugin dicom-support Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.10.6 CVE-2024-12623 Wordfence
5.3 Medium Easy Digital Downloads – eCommerce Payments and Subscriptions made easy Plugin easy-digital-downloads Information Disclosure eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure No login needed ≤ 3.3.6.1 CVE-2025-2252 Wordfence
3.5 Low Favorites Plugin favorites Cross-Site Scripting Admin+ Stored XSS < 2.3.5 Fixed in 2.3.5 CVE-2025-1452 WPScan
7.1 High Stylish Google Sheet Reader Plugin stylish-google-sheet-reader Cross-Site Scripting Reflected XSS No login needed < 4.1 Fixed in 4.1 CVE-2024-13863 WPScan
7.2 High Downloable by American Osteopathic Association Plugin Server-Side Request Forgery Unauthenticated SSRF No login needed ≤ 0.1.0 CVE-2024-13618 WPScan
8.6 High Downloable by American Osteopathic Association Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 0.1.0 CVE-2024-13617 WPScan
4.7 Medium WP-Recall Plugin SQL Injection Admin+ SQL Injection No login needed < 16.26.12 Fixed in 16.26.12 CVE-2024-9770 WPScan
3.5 Low AFI Plugin Cross-Site Scripting Admin+ Stored XSS < 1.100.0 Fixed in 1.100.0 CVE-2024-13123 WPScan
3.5 Low AFI Plugin Cross-Site Scripting Admin+ Stored XSS < 1.100.0 Fixed in 1.100.0 CVE-2024-13122 WPScan
4.3 Medium IP Based Login Plugin ip-based-login Cross-Site Request Forgery Log Deletion via CSRF No login needed < 2.4.1 Fixed in 2.4.1 CVE-2024-13118 WPScan
3.5 Low Simple Banner Plugin simple-banner Cross-Site Scripting Admin+ Stored XSS < 3.0.4 Fixed in 3.0.4 CVE-2024-12769 WPScan
6.1 Medium Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Scripting Admin+ Stored XSS No login needed < 1.5.2 Fixed in 1.5.2 CVE-2024-12682 WPScan
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.9 Fixed in 1.5.9 CVE-2024-12109 WPScan
6.1 Medium WP Tabs Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.2.7 Fixed in 2.2.7 CVE-2024-11503 WPScan
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11273 WPScan
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11272 WPScan
6.1 Medium Registrations for The Events Calendar Plugin registrations-for-the-events-calendar Cross-Site Scripting Admin+ Stored XSS No login needed < 2.13.4 Fixed in 2.13.4 CVE-2024-10703 WPScan
6.1 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Author+ Stored XSS No login needed < 9.2.1 Fixed in 9.2.1 CVE-2024-10679 WPScan
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.11 Fixed in 1.5.11 CVE-2024-10638 WPScan
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Contributor+ Stored XSS No login needed < 1.2.62 Fixed in 1.2.62 CVE-2024-10566 WPScan
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Admin+ Stored XSS via Widget No login needed < 1.2.62 Fixed in 1.2.62 CVE-2024-10565 WPScan
3.5 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.30 Fixed in 1.15.30 CVE-2024-10560 WPScan
3.5 Low WP-Advanced-Search Plugin Cross-Site Scripting Admin+ Stored XSS < 3.3.9.3 Fixed in 3.3.9.3 CVE-2024-10554 WPScan
5.9 Medium Stylish Price List Plugin stylish-price-list Cross-Site Scripting Contributor+ Stored XSS < 7.1.12 Fixed in 7.1.12 CVE-2024-10472 WPScan
5.9 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.11 Fixed in 2.7.11 CVE-2024-10105 WPScan
5.3 Medium Directorist Plugin directorist Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Publishing No login needed ≤ 8.2 CVE-2025-2224 Wordfence
6.4 Medium DesignThemes Core Features Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.8 CVE-2025-0845 Wordfence
5.9 Medium wA11y – The Web Accessibility Toolbox Plugin wa11y Cross-Site Scripting The Web Accessibility Toolbox plugin <= 1.0.3 - Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2025-30623 Patchstack
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
6.5 Medium WP Social Widget Plugin wp-social-widget Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-30610 Patchstack
5.3 Medium AppExperts Plugin appexperts Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.5 CVE-2025-30609 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
5.9 Medium Easy Page Transition Plugin easy-page-transition Cross-Site Scripting ≤ 1.0.1 CVE-2025-30606 Patchstack
4.3 Medium sourceplay-navermap Plugin sourceplay-navermap Broken Access Control ≤ 0.0.2 CVE-2025-30605 Patchstack
7.6 High JiangQie Official Website Mini Program Plugin jiangqie-official-website-mini-program SQL Injection ≤ 1.8.2 CVE-2025-30604 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only