WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 18,101–18,150 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Appsero Helper | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.3.2 |
CVE-2024-13436 |
Wordfence | |
| 7.3 High | WPCS – WordPress Currency Switcher Professional | Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.0.4 |
CVE-2025-2169 |
Wordfence | |
| 9.8 Critical | HUSKY – Products Filter Professional for WooCommerce | Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed |
≤ 1.3.6.5 |
CVE-2025-1661 |
Wordfence | |
| 10.0 Critical | Fresh Framework | Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed |
≤ 1.70.0 |
CVE-2025-26936 |
Patchstack | |
| 7.5 High | WC Place Order Without Payment | Local File Inclusion No login needed |
≤ 2.6.7 Fixed in 2.6.8 |
CVE-2025-26933 |
Patchstack | |
| 9.0 Critical | Massive Dynamic | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 8.2 |
CVE-2025-26916 |
Patchstack | |
| 7.1 High | WPBookit | Cross-Site Request Forgery No login needed |
≤ 1.0.1 Fixed in 1.0.2 |
CVE-2025-26910 |
Patchstack | |
| 8.8 High | Gtbabel | Privilege Escalation Unauthenticated Admin Account Takeover No login needed |
< 6.6.9 Fixed in 6.6.9 |
CVE-2024-11638 |
WPScan | |
| 4.3 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed |
≤ 1.9.8 |
CVE-2025-1926 |
Wordfence | |
| 6.1 Medium | Contact Us By Lord Linus | Cross-Site Scripting Admin+ Stored XSS via CSRF No login needed |
≤ 2.6 |
CVE-2025-1382 |
WPScan | |
| 3.5 Low | easy-broken-link-checker | Cross-Site Scripting Admin+ Stored XSS |
≤ 9.0.2 |
CVE-2025-1363 |
WPScan | |
| 4.3 Medium | easy-broken-link-checker | Cross-Site Request Forgery Bulk Actions via CSRF |
≤ 9.0.2 |
CVE-2025-1362 |
WPScan | |
| 5.3 Medium | Starter Templates by FancyWP | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 2.0.0 |
CVE-2024-13924 |
Wordfence | |
| 4.3 Medium | RomethemeKit For Elementor | Broken Access Control Missing Authorization in save_options and reset_widgets |
≤ 1.5.3 |
CVE-2024-10326 |
Wordfence | |
| 6.4 Medium | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.3.1 |
CVE-2025-1664 |
Wordfence | |
| 6.4 Medium | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.0 |
CVE-2024-13675 |
Wordfence | |
| 8.8 High | VikRentCar Car Rental Management System | Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed |
≤ 1.4.2 |
CVE-2024-11640 |
Wordfence | |
| 6.4 Medium | 140+ Widgets | Xpro Addons For Elementor – FREE | Cross-Site Scripting FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.6.7 |
CVE-2024-13649 |
Wordfence | |
| 6.4 Medium | Gallery Styles | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.4 |
CVE-2025-1783 |
Wordfence | |
| 6.3 Medium | WP-Recall – Registration, Profile, Commerce & More | Broken Access Control Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction |
≤ 16.26.10 |
CVE-2025-1325 |
Wordfence | |
| 7.5 High | WP-Recall – Registration, Profile, Commerce & More | SQL Injection Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection No login needed |
≤ 16.26.10 |
CVE-2025-1323 |
Wordfence | |
| 4.3 Medium | WP-Recall – Registration, Profile, Commerce & More | Information Disclosure Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure |
≤ 16.26.10 |
CVE-2025-1322 |
Wordfence | |
| 6.4 Medium | WP-Recall – Registration, Profile, Commerce & More | Cross-Site Scripting Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 16.26.10 |
CVE-2025-1324 |
Wordfence | |
| 8.1 High | Product Input Fields for WooCommerce | Arbitrary File Upload Unauthenticated Limited File Upload No login needed |
≤ 1.12.0 |
CVE-2024-13359 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 6.2.2 |
CVE-2025-1287 |
Wordfence | |
| 9.8 Critical | Javo Core | Privilege Escalation Unauthenticated Privilege Escalation in ajax_signup No login needed |
≤ 3.0.0.080 |
CVE-2025-0177 |
Wordfence | |
| 8.8 High | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit | Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload |
≤ 2.3.8 |
CVE-2024-13882 |
Wordfence | |
| 5.4 Medium | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit | Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions |
≤ 2.3.6 |
CVE-2024-13816 |
Wordfence | |
| 4.3 Medium | All-in-One Addons for Elementor – WidgetKit | Information Disclosure WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates |
≤ 2.5.5 |
CVE-2024-10321 |
Wordfence | |
| 8.1 High | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon | Authentication Bypass No login needed |
≤ 200.3.9 |
CVE-2024-11087 |
Wordfence | |
| 7.2 High | SMTP by BestWebSoft | Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload |
≤ 1.1.9 |
CVE-2024-13908 |
Wordfence | |
| 5.4 Medium | Email Keep | Cross-Site Request Forgery Email Deletion via CSRF |
≤ 1.1 |
CVE-2024-13826 |
WPScan | |
| 6.1 Medium | Email Keep | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.1 |
CVE-2024-13825 |
WPScan | |
| 4.3 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates |
≤ 2.4.29 |
CVE-2024-12114 |
Wordfence | |
| 4.9 Medium | Post SMTP | SQL Injection Authenticated (Administrator+) SQL Injection via columns Parameter |
≤ 3.1.2 |
CVE-2024-13844 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size |
≤ 2.4.29 |
CVE-2024-12119 |
Wordfence | |
| 5.9 Medium | Print Invoice & Delivery Notes for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 5.4.1 |
CVE-2024-13640 |
Wordfence | |
| 4.3 Medium | Code Snippets CPT | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 2.1.0 |
CVE-2024-13895 |
Wordfence | |
| 7.2 High | Post Meta Data Manager | Privilege Escalation Authentciated (Admin+) Multisite Privilege Escalation |
≤ 1.4.4 |
CVE-2024-13835 |
Wordfence | |
| 6.1 Medium | Wishlist for WooCommerce: Multi Wishlists Per Customer | Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed |
≤ 3.1.7 |
CVE-2024-13774 |
Wordfence | |
| 4.3 Medium | Post Lockdown | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Disclosure |
≤ 4.0.2 |
CVE-2025-1504 |
Wordfence | |
| 7.2 High | Allow PHP Execute | Remote Code Execution Authenticated (Editor+) PHP Code Injection |
≤ 1.0 |
CVE-2024-13890 |
Wordfence | |
| 6.4 Medium | Years Since – Timeless | Cross-Site Scripting Timeless <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-12460 |
Wordfence | |
| 6.5 Medium | Shortcode Cleaner Lite | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Export |
≤ 1.0.9 |
CVE-2025-1481 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget |
≤ 2.8.2 |
CVE-2025-1261 |
Wordfence | |
| 6.5 Medium | SEO Plugin by Squirrly SEO | SQL Injection Authenticated (Subscriber+) SQL Injection via search Parameter |
≤ 12.4.05 |
CVE-2025-1768 |
Wordfence | |
| 6.1 Medium | Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
2.0.59 |
CVE-2024-12634 |
Wordfence | |
| 7.1 High | WordPress Activity O Meter | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.0 |
CVE-2024-13668 |
WPScan | |
| 4.8 Medium | Reservit Hotel | Cross-Site Scripting Admin+ Stored XSS |
< 3.0 Fixed in 3.0 |
CVE-2024-9458 |
WPScan | |
| 5.5 Medium | WPGet API | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 2.2.10 |
CVE-2024-13857 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.