WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,051–18,100 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 362 of 594
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
5.9 Medium pipDisqus Plugin pipdisqus Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28908 Patchstack
5.9 Medium WP Last Modified Plugin wp-last-modified Cross-Site Scripting ≤ 0.1 CVE-2025-28907 Patchstack
5.9 Medium Skitter Slideshow Plugin wp-skitter-slideshow Cross-Site Scripting ≤ 2.5.2 CVE-2025-28906 Patchstack
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack
7.1 High TabGarb Pro Plugin tabgarb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6 CVE-2025-28900 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
4.7 Medium AS English Admin Plugin as-english-admin Open Redirect No login needed ≤ 1.0.0 CVE-2025-28896 Patchstack
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High List of Posts from each Category Plugin list-posts-by-category Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28894 Patchstack
7.1 High FTP Sync Plugin ftp-sync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.6 CVE-2025-28892 Patchstack
7.1 High price-calc Plugin price-calc Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6.3 CVE-2025-28891 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
7.1 High WP Compare Tables Plugin wp-compare-tables Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-28883 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
6.5 Medium Bee Layer Slider Plugin bee-layer-slider Cross-Site Scripting ≤ 1.1 CVE-2025-28879 Patchstack
5.9 Medium Awesome Surveys Plugin awesome-surveys Cross-Site Scripting ≤ 2.0.10 CVE-2025-28878 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
5.9 Medium BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-28875 Patchstack
6.5 Medium BP Email Assign Templates Plugin bp-email-assign-templates Broken Access Control Arbitrary Content Deletion ≤ 1.7 Fixed in 1.8 CVE-2025-28874 Patchstack
5.3 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Broken Access Control No login needed ≤ 2.2.4 CVE-2025-28872 Patchstack
5.9 Medium Block Spam By Math Reloaded Plugin block-spam-by-math-reloaded Cross-Site Scripting ≤ 2.2.4 CVE-2025-28871 Patchstack
6.5 Medium amoCRM WebForm Plugin amocrm-webform Cross-Site Scripting ≤ 1.1 CVE-2025-28870 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
7.1 High WP jQuery Persian Datepicker Plugin wpjqp-datepicker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0 CVE-2025-28861 Patchstack
7.1 High Google News Editors Picks Feed Generator Plugin google-news-editors-picks-news-feeds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-28860 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack
7.1 High Rankchecker.io Integration Plugin rankchecker-io-integration Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28857 Patchstack
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
4.3 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Information Disclosure Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content ≤ 1.8.13 CVE-2024-13228 Wordfence
4.8 Medium Coronavirus (COVID-19) Notice Message Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.1.2 CVE-2025-0629 WPScan
7.1 High Countdown Timer Plugin widget-countdown Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13864 WPScan
7.1 High S3Bubble Media Streaming Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 8.0 CVE-2024-13862 WPScan
6.1 Medium SEO Tools Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 4.0.7 CVE-2024-13853 WPScan
7.1 High WP Login Control Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.0 CVE-2024-13836 WPScan
3.5 Low Social Media Plugin by Social Snap Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.3.6 CVE-2024-13615 WPScan
4.3 Medium XV Random Quotes Plugin xv-random-quotes Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 1.40 CVE-2024-13580 WPScan
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting Reflected XSS No login needed ≤ 1.40 CVE-2024-13574 WPScan
6.1 Medium ProductDyno Plugin productdyno Cross-Site Scripting Reflected Cross-Site Scripting via 'res' Parameter No login needed ≤ 1.0.24 CVE-2024-13413 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only