WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 18,201–18,250 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Company Directory | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Function No login needed |
≤ 4.3 |
CVE-2024-13839 |
Wordfence | |
| 4.3 Medium | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce | Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 4.5.7 |
CVE-2024-13811 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.16.5 |
CVE-2024-13778 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library |
≤ 1.3.4, ≤ 2.4.7 |
CVE-2024-5667 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode |
≤ 3.10.6 |
CVE-2024-13757 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion |
≤ 1.16.5 |
CVE-2024-13780 |
Wordfence | |
| 6.1 Medium | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-13779 |
Wordfence | |
| 8.1 High | ZoomSounds - WordPress Wave Audio Player with Playlist | PHP Object Injection WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection No login needed |
≤ 6.91 |
CVE-2024-13777 |
Wordfence | |
| 8.1 High | WooCommerce Recover Abandoned Cart | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 24.4.0 |
CVE-2025-0956 |
Wordfence | |
| 6.4 Medium | Simple Notification | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.3 |
CVE-2024-13866 |
Wordfence | |
| 6.4 Medium | Recently Purchased Products For Woo | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter |
≤ 1.1.3 |
CVE-2025-1008 |
Wordfence | |
| 6.1 Medium | Razorpay Subscription Button Elementor | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed |
≤ 1.0.3 |
CVE-2024-13827 |
Wordfence | |
| 6.4 Medium | SearchIQ – The Search Solution | Cross-Site Scripting The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.7 |
CVE-2024-13350 |
Wordfence | |
| 5.3 Medium | JNews - WordPress Newspaper Magazine Blog AMP | Broken Access Control WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration No login needed |
≤ 11.6.6 |
CVE-2024-8682 |
Wordfence | |
| 6.3 Medium | bbPress | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed |
≤ 2.6.11 |
CVE-2025-1435 |
Wordfence | |
| 4.3 Medium | I Am Gloria | Cross-Site Request Forgery No login needed |
≤ 1.1.4 |
CVE-2025-0990 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter |
≤ 7.3.3 |
CVE-2025-0370 |
Wordfence | |
| 5.4 Medium | Ultimate WordPress Auction | Broken Access Control Missing Authorization to Arbitrary Post Deletion |
≤ 4.2.9 |
CVE-2025-0958 |
Wordfence | |
| 6.4 Medium | Master Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.7.1 |
CVE-2025-0433 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization |
≤ 2.6.2 |
CVE-2024-13724 |
Wordfence | |
| 6.4 Medium | Structured Content (JSON-LD) #wpsc | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode |
≤ 1.6.3 |
CVE-2025-0512 |
Wordfence | |
| 6.4 Medium | Master Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.0.7.2 |
CVE-2024-9618 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed |
≤ 2.6.2 |
CVE-2024-13682 |
Wordfence | |
| 5.3 Medium | Admin and Site Enhancements (ASE) | Authentication Bypass Limit Login Attempt Bypass via IP Spoofing No login needed |
< 7.6.10 Fixed in 7.6.10 |
CVE-2024-13685 |
WPScan | |
| 9.8 Critical | Newscrunch | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload No login needed |
≤ 1.8.4 |
CVE-2025-1307 |
Wordfence | |
| 8.8 High | Newscrunch | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed |
≤ 1.8.4 |
CVE-2025-1306 |
Wordfence | |
| 8.8 High | Animation Addons for Elementor Pro | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation |
≤ 1.6 |
CVE-2025-1639 |
Wordfence | |
| 6.5 Medium | teachPress | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 9.0.7 |
CVE-2025-1321 |
Wordfence | |
| 9.8 Critical | GiveWP – Donation Plugin and Fundraising Platform | PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection No login needed |
≤ 3.19.4 |
CVE-2025-0912 |
Wordfence | |
| 4.3 Medium | VW Storefront | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 0.9.9 |
CVE-2024-13686 |
Wordfence | |
| 7.1 High | Zigaform – Price Calculator & Cost Estimation Form Builder Lite | Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed |
≤ 7.4.2 Fixed in 7.4.3 |
CVE-2025-26994 |
Patchstack | |
| 7.1 High | Zigaform | Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed |
≤ 7.4.2 Fixed in 7.4.3 |
CVE-2025-26989 |
Patchstack | |
| 9.3 Critical | SMS Alert Order Notifications | SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed |
≤ 3.7.8 Fixed in 3.7.9 |
CVE-2025-26988 |
Patchstack | |
| 7.1 High | SMS Alert Order Notifications | Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.7.8 Fixed in 3.7.9 |
CVE-2025-26984 |
Patchstack | |
| 10.0 Critical | Ark Theme Core | Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed |
≤ 1.71.0 Fixed in 1.71.0 |
CVE-2025-26970 |
Patchstack | |
| 8.8 High | Events Calendar for GeoDirectory | PHP Object Injection |
≤ 2.3.14 Fixed in 2.3.15 |
CVE-2025-26967 |
Patchstack | |
| 7.1 High | Small Package Quotes – Unishippers Edition | Cross-Site Scripting Unishippers Edition plugin <= 2.4.9 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.4.9 Fixed in 2.4.10 |
CVE-2025-26918 |
Patchstack | |
| 7.1 High | WP Templata | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.7 Fixed in 1.0.8 |
CVE-2025-26917 |
Patchstack | |
| 7.1 High | Variable Inspector | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.2 Fixed in 2.6.3 |
CVE-2025-26914 |
Patchstack | |
| 7.2 High | WordPress Assistant | PHP Object Injection |
≤ 1.5.1 Fixed in 1.5.1.1 |
CVE-2025-26885 |
Patchstack | |
| 7.1 High | s2Member | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 241216 Fixed in 250214 |
CVE-2025-26879 |
Patchstack | |
| 7.1 High | Flashfader | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.1 |
CVE-2025-27279 |
Patchstack | |
| 7.1 High | AcuGIS Leaflet Maps | Cross-Site Scripting Multiple Cross Site Scripting (XSS) vulnerabilities No login needed |
≤ 5.1.1.0 |
CVE-2025-27278 |
Patchstack | |
| 7.1 High | WOO Codice Fiscale | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.3 |
CVE-2025-27275 |
Patchstack | |
| 4.9 Medium | GPX Viewer | Path Traversal |
≤ 2.2.11 Fixed in 2.2.12 |
CVE-2025-27274 |
Patchstack | |
| 5.8 Medium | Affiliate Links Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-27273 |
Patchstack | |
| 7.1 High | DB Tables Import/Export | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-27271 |
Patchstack | |
| 9.8 Critical | Residential Address Detection | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 2.5.4 Fixed in 2.5.5 |
CVE-2025-27270 |
Patchstack | |
| 7.1 High | .htaccess Login block | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.9a |
CVE-2025-27269 |
Patchstack | |
| 9.3 Critical | Small Package Quotes – Worldwide Express Edition | SQL Injection Worldwide Express Edition Plugin <= 5.2.18 - SQL Injection No login needed |
≤ 5.2.18 Fixed in 5.2.19 |
CVE-2025-27268 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.