WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 17,901–17,950 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 359 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.9.179 CVE-2024-13558 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
9.8 Critical Age Gate Plugin age-gate Local File Inclusion Unauthenticated Local PHP File Inclusion via 'lang' No login needed ≤ 3.5.3 CVE-2025-2505 Wordfence
6.4 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Cross-Site Scripting FREE <= 1.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Site Title' widget ≤ 1.4.7.1 CVE-2025-2108 Wordfence
7.1 High LinkMyPosts Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13881 WPScan
7.1 High My Quota Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.8 CVE-2024-13880 WPScan
7.1 High SpotBot Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.1.8 CVE-2024-13878 WPScan
7.1 High Passbeemedia Web Push Notifications Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13877 WPScan
7.1 High Meintopf Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.2.1 CVE-2024-13876 WPScan
7.1 High WP Programmmanager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2 CVE-2024-13875 WPScan
5.3 Medium Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update No login needed ≤ 4.0.24 CVE-2025-1766 Wordfence
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.24 CVE-2025-1770 Wordfence
4.3 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function No login needed ≤ 2.2.5 CVE-2025-1314 Wordfence
9.8 Critical File Away Plugin file-away Broken Access Control Missing Authorization to Unauthenticated File Upload via upload Function No login needed ≤ 3.9.9.0.1 CVE-2025-2512 Wordfence
4.9 Medium AHAthat Plugin ahathat SQL Injection Authenticated (Administrator+) SQL Injection via id Parameter ≤ 1.6 CVE-2025-2511 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Broken Access Control Missing Authorization in Multiple Functions ≤ 4.7 CVE-2024-12920 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 5.0 CVE-2024-13442 Wordfence
9.8 Critical MinimogWP – The High Converting eCommerce Theme Local File Inclusion The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion No login needed ≤ 3.7.0 CVE-2024-13790 Wordfence
7.5 High CozyStay Theme Broken Access Control Missing Authorization to Arbitrary Action Execution in ajax_handler No login needed ≤ 1.7.0 CVE-2024-13412 Wordfence
9.8 Critical CozyStay Plugin PHP Object Injection Unauthenticated PHP Object Injection in ajax_handler No login needed ≤ 1.7.0, ≤ 3.9.0 CVE-2024-13410 Wordfence
8.8 High Site Reviews Plugin site-reviews Cross-Site Scripting Unauthenticated Stored XSS No login needed < 7.2.5 Fixed in 7.2.5 CVE-2025-1232 WPScan
9.8 Critical Altair Theme Broken Access Control Unauthenticated Arbitrary Options Update via pp_import_current No login needed ≤ 5.2.4 CVE-2024-12922 Wordfence
8.8 High BoomBox Theme Extensions Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Reset/Account Takeover in boombox_ajax_reset_password ≤ 1.8.0 CVE-2024-12295 Wordfence
5.3 Medium LifterLMS Plugin lifterlms Broken Access Control Missing Authorization to Unauthenticated Post Trashing No login needed ≤ 8.0.1 CVE-2025-2290 Wordfence
8.8 High s2Member Pro Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion to Remote Code Execution via Shortcode ≤ 250214 CVE-2024-12563 Wordfence
7.3 High Logo Slider Plugin gs-logo-slider Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.7.3 CVE-2025-2262 Wordfence
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.9 Fixed in 4.15.9 CVE-2025-1624 WPScan
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.9 Fixed in 4.15.9 CVE-2025-1623 WPScan
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1622 WPScan
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1621 WPScan
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1620 WPScan
4.8 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1619 WPScan
4.8 Medium Poll Maker Plugin poll-maker Cross-Site Scripting Admin+ Stored XSS < 5.5.4 Fixed in 5.5.4 CVE-2024-13602 WPScan
4.6 Medium Download Manager Plugin download-manager Information Disclosure Unauthenticated Data Exposure < 3.3.07 Fixed in 3.3.07 CVE-2024-13126 WPScan
8.5 High All In Menu Plugin all-in-menu SQL Injection ≤ 1.1.5 CVE-2025-27281 Patchstack
8.5 High FS Poster Plugin fs-poster SQL Injection ≤ 6.5.8 Fixed in 6.5.9 CVE-2025-26978 Patchstack
8.5 High PrivateContent Plugin private-content SQL Injection ≤ 8.11.4 CVE-2025-26976 Patchstack
7.1 High PrivateContent Plugin private-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.11.5 CVE-2025-26972 Patchstack
8.3 High PrivateContent Plugin private-content Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 8.11.5 CVE-2025-26969 Patchstack
8.6 High Fresh Framework Plugin fresh-framework Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.70.0 CVE-2025-26961 Patchstack
6.3 Medium Pie Register Premium Plugin pie-register-premium Path Traversal Path Traversal to Non-Arbitrary File Deletion ≤ 3.8.3.2 Fixed in 3.8.3.3 CVE-2025-26940 Patchstack
6.5 Medium Ohio Extra Plugin ohio-extra Content Injection Shortcode Injection No login needed ≤ 3.4.7 CVE-2025-26924 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
6.5 Medium m1.DownloadList Plugin m1downloadlist Cross-Site Scripting ≤ 0.19 Fixed in 0.20 CVE-2025-26895 Patchstack
7.6 High PublishPress Authors Plugin publishpress-authors SQL Injection ≤ 4.7.3 Fixed in 4.7.4 CVE-2025-26886 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
7.1 High WP AntiDDOS Plugin wpantiddos Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-26556 Patchstack
7.1 High Debug-Bar-Extender Plugin debug-bar-extender Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-26555 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only