WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,001–18,050 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 361 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WoWPth Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2025-1487 WPScan
7.1 High WoWPth Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2025-1486 WPScan
7.1 High Limit Bio Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2025-1436 WPScan
7.1 High WP Click Info Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.7.4 CVE-2025-1401 WPScan
7.1 High Schedule Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13891 WPScan
7.1 High WP E Customers Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.0.1 CVE-2024-13885 WPScan
7.1 High Limit Bio Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13884 WPScan
7.2 High AppPresser – Mobile App Framework Plugin apppresser Cross-Site Scripting Mobile App Framework <= 4.4.10 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.10 CVE-2025-1561 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.8.0 CVE-2025-1503 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication ≤ 1.9.8 CVE-2025-2104 Wordfence
4.9 Medium WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins Plugin reportattacks SQL Injection Authenticated (Admin+) SQL Injection ≤ 2.32 CVE-2025-2250 Wordfence
5.3 Medium Business Directory Plugin - Easy Listing Directories Plugin business-directory-plugin Broken Access Control Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition No login needed ≤ 6.4.14 CVE-2024-13887 Wordfence
7.5 High Arielbrailovsky-Viralad Plugin arielbrailovsky-viralad SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.8 CVE-2025-2107 Wordfence
6.4 Medium CC-IMG-Shortcode Plugin cc-img-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2025-1559 Wordfence
4.3 Medium CRM and Lead Management by vcita Plugin crm-customer-relationship-management-by-vcita Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Widget Toggle ≤ 2.7.5 CVE-2024-13703 Wordfence
7.5 High Arielbrailovsky-Viralad Plugin arielbrailovsky-viralad SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.8 CVE-2025-2106 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
9.8 Critical Workreap Plugin Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.2.5 CVE-2024-13446 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 CVE-2024-13430 Wordfence
5.5 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 6.2 CVE-2024-13838 Wordfence
6.4 Medium Finale Lite – Sales Countdown Timer & Discount for WooCommerce Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer ≤ 2.19.0 CVE-2024-12589 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Information Disclosure Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.8.1 CVE-2024-13498 Wordfence
4.4 Medium BlogBuzzTime-for-wp Plugin blogbuzztime-for-wp Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-2078 Wordfence
6.1 Medium Simple Amazon Affiliate Plugin simple-amazon-affiliate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.9 CVE-2025-2077 Wordfence
4.4 Medium binlayerpress Plugin binlayerpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-2076 Wordfence
5.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Content Download No login needed ≤ 2.1.14 CVE-2025-1508 Wordfence
4.4 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.15.6 CVE-2025-2205 Wordfence
8.8 High Review Schema Plugin review-schema Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Meta ≤ 2.2.4 CVE-2025-1707 Wordfence
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
5.9 Medium DP ALTerminator - Missing ALT manager Plugin dp-alterminator-missing-alt-manager Cross-Site Scripting Missing ALT manager Plugin <= 1.0.2 - Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2025-28943 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-28938 Patchstack
5.9 Medium Lava Ajax Search Plugin lava-ajax-search Cross-Site Scripting ≤ 1.1.9 CVE-2025-28937 Patchstack
5.9 Medium Lunar Plugin lunar-sell-photos-online Cross-Site Scripting ≤ 1.3.0 CVE-2025-28936 Patchstack
7.1 High MaxA/B Plugin maxab Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-28933 Patchstack
7.1 High Insert Code Plugin insert-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 CVE-2025-28932 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
6.5 Medium List Mixcloud Plugin list-mixcloud Cross-Site Scripting ≤ 1.4 CVE-2025-28930 Patchstack
6.5 Medium Tabbed Login Widget Plugin tabbed-login Cross-Site Scripting ≤ 1.1.2 CVE-2025-28929 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
5.9 Medium Post Read Time Plugin post-read-time Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.6 CVE-2025-28926 Patchstack
7.1 High WATI Chat and Notification Plugin wati-chat-and-notification Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.5 CVE-2025-28925 Patchstack
7.1 High No Disposable Email Plugin no-disposable-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-28923 Patchstack
7.1 High Go To Top Plugin go-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.8 CVE-2025-28922 Patchstack
5.3 Medium Responsive Google Map Plugin responsive-google-map Broken Access Control No login needed ≤ 3.1.5 CVE-2025-28920 Patchstack
6.5 Medium Easy Image Display Plugin easy-image-display Cross-Site Scripting ≤ 1.2.5 CVE-2025-28919 Patchstack
6.5 Medium Featured Image Thumbnail Grid Plugin thumbnail-grid Cross-Site Scripting ≤ 6.8 Fixed in 6.9 CVE-2025-28918 Patchstack
9.1 Critical ThemeEgg ToolKit Plugin themeegg-toolkit Arbitrary File Upload ≤ 1.2.9 CVE-2025-28915 Patchstack
5.9 Medium wordpress login form to anywhere Plugin wp-show-login-form Cross-Site Scripting ≤ 0.2 CVE-2025-28914 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only