WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,751–1,800 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 36 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Docket Cache Plugin docket-cache Broken Access Control ≤ 24.07.04 Fixed in 24.07.05 CVE-2026-22492 Patchstack
5.4 Medium GA4WP: Google Analytics Plugin ga-for-wp Broken Access Control ≤ 2.10.0 CVE-2026-22517 Patchstack
6.5 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting ≤ 1.0.23 CVE-2026-22518 Patchstack
6.5 Medium MediaPress Plugin mediapress Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-22519 Patchstack
6.5 Medium Block Slider Plugin block-slider Broken Access Control ≤ 2.2.3 CVE-2026-22522 Patchstack
5.3 Medium Zorka Theme zorka Broken Access Control No login needed ≤ 1.5.7 CVE-2026-0676 Patchstack
4.3 Medium Campaign Monitor Plugin forms-for-campaign-monitor Broken Access Control ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-0674 Patchstack
5.4 Medium Easy Media Download Plugin easy-media-download Content Injection CSS Injection ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-69169 Patchstack
6.5 Medium Flaming Password Reset Plugin flaming-password-reset Cross-Site Scripting ≤ 1.0.3 CVE-2025-68875 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Cross-Site Scripting ≤ 1.2.1 CVE-2025-68867 Patchstack
6.5 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 1.10.4 Fixed in 1.10.5 CVE-2025-67926 Patchstack
6.5 Medium Woffice Core Plugin woffice-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67919 Patchstack
6.5 Medium Traveler Plugin traveler Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2025-67917 Patchstack
6.5 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control No login needed ≤ 3.0.3 Fixed in 3.0.3 CVE-2025-67913 Patchstack
6.4 Medium nK Themes Helper Plugin nk-themes-helper Server-Side Request Forgery ≤ 1.7.9 CVE-2025-22726 Patchstack
4.9 Medium External Media Plugin external-media Server-Side Request Forgery ≤ 1.0.36 CVE-2025-49335 Patchstack
6.5 Medium The Plus Addons for Elementor Pro Plugin theplus_elementor_addon Broken Access Control ≤ 6.3.7 Fixed in 6.3.7 CVE-2025-46434 Patchstack
6.4 Medium Advanced Database Cleaner PRO Plugin advanced-database-cleaner-pro Path Traversal Limited .txt Path Traversal ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-46256 Patchstack
4.3 Medium JetEngine Plugin jet-engine Broken Access Control ≤ 3.8.1.1 Fixed in 3.8.1.2 CVE-2025-69333 Patchstack
4.3 Medium Oneline Lite Plugin oneline-lite Broken Access Control ≤ 6.6 Fixed in 6.7 CVE-2025-69344 Patchstack
6.1 Medium Stumble! Plugin stumble-for-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 1.1.1 CVE-2025-14128 Wordfence
6.4 Medium Recras Plugin recras Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'recrasname' Shortcode Attribute ≤ 6.4.1 CVE-2025-13497 Wordfence
4.3 Medium MTCaptcha Plugin mtcaptcha Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.7.2 CVE-2025-13520 Wordfence
5.4 Medium aBlocks – WordPress Gutenberg Blocks Plugin ablocks Broken Access Control WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification ≤ 2.4.0 CVE-2025-12449 Wordfence
5.4 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion ≤ 4.3.2.1 CVE-2025-14802 Wordfence
6.5 Medium Flashcard Plugin flashcard Path Traversal Authenticated (Contributor+) Arbitrary File Read via Path Traversal ≤ 0.9 CVE-2025-14867 Wordfence
4.4 Medium twinklesmtp – Email Service Provider Plugin twinklesmtp Cross-Site Scripting Email Service Provider For WordPress <= 1.03 - Authenticated (Administrator+) Stored Cross-Site Scripting via Sender Settings ≤ 1.03 CVE-2025-14887 Wordfence
5.3 Medium Plant - Gardening & Houseplants Theme plant Information Disclosure Gardening & Houseplants WordPress Theme <= 1.0.0 - Sensitive Data Exposure No login needed ≤ 1.0.0 CVE-2025-31051 Patchstack
6.5 Medium AdsPlace'r – Ad Manager, Inserter, AdSense Ads Plugin adsplacer Cross-Site Scripting Ad Manager, Inserter, AdSense Ads plugin <= 1.1.5 - Cross Site Scripting (XSS) ≤ 1.1.5 CVE-2024-31088 Patchstack
5.3 Medium Breeze Plugin breeze Broken Access Control No login needed ≤ 2.2.21 Fixed in 2.2.22 CVE-2025-69364 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-69363 Patchstack
5.9 Medium UiChemy Plugin uichemy Cross-Site Scripting ≤ 4.4.2 Fixed in 4.4.3 CVE-2025-69362 Patchstack
4.3 Medium Post Expirator Plugin post-expirator Broken Access Control ≤ 4.9.3 Fixed in 4.9.4 CVE-2025-69361 Patchstack
6.5 Medium TheGem Theme Elements (for WPBakery) Plugin thegem-elements Cross-Site Scripting ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69360 Patchstack
5.3 Medium Creator LMS Plugin creatorlms Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2025-69359 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69357 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.4 Fixed in 3.5.6.5 CVE-2025-69355 Patchstack
4.3 Medium Better Business Reviews Plugin better-business-reviews Broken Access Control ≤ 0.1.1 Fixed in 0.1.2 CVE-2025-69354 Patchstack
4.3 Medium Proxy & VPN Blocker Plugin proxy-vpn-blocker Broken Access Control ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-69353 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.15.12.2 Fixed in 6.15.13 CVE-2025-69352 Patchstack
5.9 Medium Accordion Plugin accordions-wp Cross-Site Scripting ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-69350 Patchstack
5.4 Medium RSS Feed Widget Plugin rss-feed-widget Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-69349 Patchstack
4.3 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2025-69348 Patchstack
4.3 Medium AffiliateX Plugin affiliatex Broken Access Control ≤ 1.3.9.3 Fixed in 1.4.0 CVE-2025-69346 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Broken Access Control ≤ 1.27.9 Fixed in 1.27.10 CVE-2025-69345 Patchstack
5.4 Medium WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69341 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.9.4 Fixed in 2.9.5 CVE-2025-69336 Patchstack
6.5 Medium Team Showcase Plugin team-showcase Cross-Site Scripting ≤ 2.9 Fixed in 3.0.0 CVE-2025-69335 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-69334 Patchstack
4.3 Medium Theater Plugin theatre Broken Access Control ≤ 0.19 Fixed in 0.19.1 CVE-2025-69331 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only