WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,101–18,150 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 363 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Appsero Helper Plugin appsero-helper Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2024-13436 Wordfence
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
9.8 Critical HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.6.5 CVE-2025-1661 Wordfence
10.0 Critical Fresh Framework Plugin fresh-framework Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.70.0 CVE-2025-26936 Patchstack
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
9.0 Critical Massive Dynamic Plugin massive-dynamic Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 8.2 CVE-2025-26916 Patchstack
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
8.8 High Gtbabel Plugin gtbabel Privilege Escalation Unauthenticated Admin Account Takeover No login needed < 6.6.9 Fixed in 6.6.9 CVE-2024-11638 WPScan
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.1 Medium Contact Us By Lord Linus Plugin Cross-Site Scripting Admin+ Stored XSS via CSRF No login needed ≤ 2.6 CVE-2025-1382 WPScan
3.5 Low easy-broken-link-checker Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 9.0.2 CVE-2025-1363 WPScan
4.3 Medium easy-broken-link-checker Plugin Cross-Site Request Forgery Bulk Actions via CSRF ≤ 9.0.2 CVE-2025-1362 WPScan
5.3 Medium Starter Templates by FancyWP Plugin starter-templates Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.0.0 CVE-2024-13924 Wordfence
4.3 Medium RomethemeKit For Elementor Plugin rometheme-for-elementor Broken Access Control Missing Authorization in save_options and reset_widgets ≤ 1.5.3 CVE-2024-10326 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 CVE-2025-1664 Wordfence
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.0 CVE-2024-13675 Wordfence
8.8 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.4.2 CVE-2024-11640 Wordfence
6.4 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin Cross-Site Scripting FREE <= 1.4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.6.7 CVE-2024-13649 Wordfence
6.4 Medium Gallery Styles Plugin gallery-styles Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 CVE-2025-1783 Wordfence
6.3 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Broken Access Control Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction ≤ 16.26.10 CVE-2025-1325 Wordfence
7.5 High WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall SQL Injection Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection No login needed ≤ 16.26.10 CVE-2025-1323 Wordfence
4.3 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Information Disclosure Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure ≤ 16.26.10 CVE-2025-1322 Wordfence
6.4 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Cross-Site Scripting Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 16.26.10 CVE-2025-1324 Wordfence
8.1 High Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.12.0 CVE-2024-13359 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
9.8 Critical Javo Core Plugin Privilege Escalation Unauthenticated Privilege Escalation in ajax_signup No login needed ≤ 3.0.0.080 CVE-2025-0177 Wordfence
8.8 High Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload ≤ 2.3.8 CVE-2024-13882 Wordfence
5.4 Medium Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 2.3.6 CVE-2024-13816 Wordfence
4.3 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Information Disclosure WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 2.5.5 CVE-2024-10321 Wordfence
8.1 High miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon Plugin Authentication Bypass No login needed ≤ 200.3.9 CVE-2024-11087 Wordfence
7.2 High SMTP by BestWebSoft Plugin bws-smtp Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 1.1.9 CVE-2024-13908 Wordfence
5.4 Medium Email Keep Plugin Cross-Site Request Forgery Email Deletion via CSRF ≤ 1.1 CVE-2024-13826 WPScan
6.1 Medium Email Keep Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13825 WPScan
4.3 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates ≤ 2.4.29 CVE-2024-12114 Wordfence
4.9 Medium Post SMTP Plugin post-smtp SQL Injection Authenticated (Administrator+) SQL Injection via columns Parameter ≤ 3.1.2 CVE-2024-13844 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size ≤ 2.4.29 CVE-2024-12119 Wordfence
5.9 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 5.4.1 CVE-2024-13640 Wordfence
4.3 Medium Code Snippets CPT Plugin code-snippets-cpt Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 2.1.0 CVE-2024-13895 Wordfence
7.2 High Post Meta Data Manager Plugin post-meta-data-manager Privilege Escalation Authentciated (Admin+) Multisite Privilege Escalation ≤ 1.4.4 CVE-2024-13835 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 CVE-2024-13774 Wordfence
4.3 Medium Post Lockdown Plugin post-lockdown Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Disclosure ≤ 4.0.2 CVE-2025-1504 Wordfence
7.2 High Allow PHP Execute Plugin allow-php-execute Remote Code Execution Authenticated (Editor+) PHP Code Injection ≤ 1.0 CVE-2024-13890 Wordfence
6.4 Medium Years Since – Timeless Plugin years-since Cross-Site Scripting Timeless <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-12460 Wordfence
6.5 Medium Shortcode Cleaner Lite Plugin shortcode-cleaner-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Export ≤ 1.0.9 CVE-2025-1481 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget ≤ 2.8.2 CVE-2025-1261 Wordfence
6.5 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo SQL Injection Authenticated (Subscriber+) SQL Injection via search Parameter ≤ 12.4.05 CVE-2025-1768 Wordfence
6.1 Medium Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins Plugin related-post Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed 2.0.59 CVE-2024-12634 Wordfence
7.1 High WordPress Activity O Meter Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13668 WPScan
4.8 Medium Reservit Hotel Plugin reservit-hotel Cross-Site Scripting Admin+ Stored XSS < 3.0 Fixed in 3.0 CVE-2024-9458 WPScan
5.5 Medium WPGet API Plugin wpgetapi Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.2.10 CVE-2024-13857 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only