WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,201–18,250 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 365 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Company Directory Plugin staff-directory-pro Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Function No login needed ≤ 4.3 CVE-2024-13839 Wordfence
4.3 Medium Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 4.5.7 CVE-2024-13811 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.16.5 CVE-2024-13778 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin responsive-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library ≤ 1.3.4, ≤ 2.4.7 CVE-2024-5667 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.10.6 CVE-2024-13757 Wordfence
6.5 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion ≤ 1.16.5 CVE-2024-13780 Wordfence
6.1 Medium Hero Mega Menu - Responsive WordPress Menu Plugin Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-13779 Wordfence
8.1 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin PHP Object Injection WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection No login needed ≤ 6.91 CVE-2024-13777 Wordfence
8.1 High WooCommerce Recover Abandoned Cart Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 24.4.0 CVE-2025-0956 Wordfence
6.4 Medium Simple Notification Plugin simple-notification Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13866 Wordfence
6.4 Medium Recently Purchased Products For Woo Plugin recently-purchased-products-for-woo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter ≤ 1.1.3 CVE-2025-1008 Wordfence
6.1 Medium Razorpay Subscription Button Elementor Plugin razorpay-subscription-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions No login needed ≤ 1.0.3 CVE-2024-13827 Wordfence
6.4 Medium SearchIQ – The Search Solution Plugin searchiq Cross-Site Scripting The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.7 CVE-2024-13350 Wordfence
5.3 Medium JNews - WordPress Newspaper Magazine Blog AMP Theme Broken Access Control WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration No login needed ≤ 11.6.6 CVE-2024-8682 Wordfence
6.3 Medium bbPress Plugin bbpress Cross-Site Request Forgery Cross-Site Request Forgery to Limited Privilege Escalation No login needed ≤ 2.6.11 CVE-2025-1435 Wordfence
4.3 Medium I Am Gloria Plugin gloria-assistant-by-webtronic-labs Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-0990 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter ≤ 7.3.3 CVE-2025-0370 Wordfence
5.4 Medium Ultimate WordPress Auction Plugin ultimate-auction Broken Access Control Missing Authorization to Arbitrary Post Deletion ≤ 4.2.9 CVE-2025-0958 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 2.0.7.1 CVE-2025-0433 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization ≤ 2.6.2 CVE-2024-13724 Wordfence
6.4 Medium Structured Content (JSON-LD) #wpsc Plugin structured-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode ≤ 1.6.3 CVE-2025-0512 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.0.7.2 CVE-2024-9618 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
5.3 Medium Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Limit Login Attempt Bypass via IP Spoofing No login needed < 7.6.10 Fixed in 7.6.10 CVE-2024-13685 WPScan
9.8 Critical Newscrunch Theme newscrunch Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1307 Wordfence
8.8 High Newscrunch Theme newscrunch Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1306 Wordfence
8.8 High Animation Addons for Elementor Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.6 CVE-2025-1639 Wordfence
6.5 Medium teachPress Plugin teachpress SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.0.7 CVE-2025-1321 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.4 CVE-2025-0912 Wordfence
4.3 Medium VW Storefront Theme vw-storefront Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 0.9.9 CVE-2024-13686 Wordfence
7.1 High Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26994 Patchstack
7.1 High Zigaform Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26989 Patchstack
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
10.0 Critical Ark Theme Core Plugin ark-core Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.71.0 Fixed in 1.71.0 CVE-2025-26970 Patchstack
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory PHP Object Injection ≤ 2.3.14 Fixed in 2.3.15 CVE-2025-26967 Patchstack
7.1 High Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Cross-Site Scripting Unishippers Edition plugin <= 2.4.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26918 Patchstack
7.1 High WP Templata Plugin wptemplata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26917 Patchstack
7.1 High Variable Inspector Plugin variable-inspector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2025-26914 Patchstack
7.2 High WordPress Assistant Plugin assistant PHP Object Injection ≤ 1.5.1 Fixed in 1.5.1.1 CVE-2025-26885 Patchstack
7.1 High s2Member Plugin s2member Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 241216 Fixed in 250214 CVE-2025-26879 Patchstack
7.1 High Flashfader Plugin flashfader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-27279 Patchstack
7.1 High AcuGIS Leaflet Maps Plugin mapfig-premium-leaflet-map-maker Cross-Site Scripting Multiple Cross Site Scripting (XSS) vulnerabilities No login needed ≤ 5.1.1.0 CVE-2025-27278 Patchstack
7.1 High WOO Codice Fiscale Plugin woo-codice-fiscale Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-27275 Patchstack
4.9 Medium GPX Viewer Plugin gpx-viewer Path Traversal ≤ 2.2.11 Fixed in 2.2.12 CVE-2025-27274 Patchstack
5.8 Medium Affiliate Links Manager Plugin affiliate-links-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-27273 Patchstack
7.1 High DB Tables Import/Export Plugin db-tables-importexport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-27271 Patchstack
9.8 Critical Residential Address Detection Plugin residential-address-detection Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-27270 Patchstack
7.1 High .htaccess Login block Plugin htaccess-login-block Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9a CVE-2025-27269 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection Worldwide Express Edition Plugin <= 5.2.18 - SQL Injection No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-27268 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only