WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,451–18,500 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 370 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium wpForo Forum Plugin wpforo Path Traversal Authenticated (Subscriber+) Arbitrary File Read in update ≤ 2.4.1 CVE-2025-0764 Wordfence
4.3 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 3.1.0 CVE-2025-1506 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
6.4 Medium MK Google Directions Plugin google-distance-calculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1 CVE-2024-12820 Wordfence
6.1 Medium User Registration & Membership – Custom Registration Form, Login Form, and User Profile Plugin user-registration Cross-Site Scripting Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting No login needed ≤ 4.0.4 CVE-2025-1511 Wordfence
4.3 Medium RateMyAgent Official Plugin ratemyagent-official Cross-Site Request Forgery Cross-Site Request Forgery to API Key Update No login needed ≤ 1.4.0 CVE-2025-0801 Wordfence
6.4 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-1757 Wordfence
6.1 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.1 CVE-2025-1505 Wordfence
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Information Disclosure ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure No login needed ≤ 2.3.6 CVE-2024-13796 Wordfence
8.8 High Traveler Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.1.9 CVE-2024-12811 Wordfence
8.8 High Cardealer Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Update via update_user_profile No login needed ≤ 1.6.4 CVE-2025-1687 Wordfence
8.8 High Cardealer Theme Privilege Escalation Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation ≤ 1.6.4 CVE-2025-1682 Wordfence
5.4 Medium Cardealer Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files ≤ 1.6.4 CVE-2025-1681 Wordfence
5.1 Medium FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed 2.4.29 CVE-2025-22624 Fluid Attacks
6.3 Medium WP Activity Log Plugin wp-security-audit-log PHP Object Injection Insecure deserialization No login needed 5.3.2 CVE-2025-0767 Fluid Attacks
7.1 High Woo Store Mode Plugin woo-store-mode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23687 Patchstack
7.6 High DefendWP Firewall Plugin defend-wp-firewall Broken Access Control ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-22280 Patchstack
6.4 Medium BuddyBoss Platform Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title' ≤ 2.7.70 CVE-2024-13402 Wordfence
4.3 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas ≤ 2.6.11 CVE-2024-13217 Wordfence
6.4 Medium Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Plugin chaty Cross-Site Scripting Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.3.5 CVE-2025-1450 Wordfence
6.4 Medium Card Elements for Elementor Plugin card-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Profile Card Widget ≤ 1.2.6 CVE-2024-13734 Wordfence
8.8 High Car Dealer Automotive WordPress Theme – Responsive Theme Arbitrary File Deletion Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read ≤ 1.6.3 CVE-2025-1282 Wordfence
6.4 Medium ThemeMakers Stripe Checkout Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2025-1690 Wordfence
8.1 High Login Me Now Plugin login-me-now Authentication Bypass No login needed ≤ 1.7.2 CVE-2025-1717 Wordfence
6.4 Medium ThemeMakers PayPal Express Checkout Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.9 CVE-2025-1689 Wordfence
4.9 Medium Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Server-Side Request Forgery WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery ≤ 1.16.8 CVE-2024-13907 Wordfence
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.6.0 CVE-2024-6261 Wordfence
7.1 High Bricksbuilder Theme Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave ≤ 1.9.6.1 CVE-2024-2297 Wordfence
8.8 High Templines Elementor Helper Core Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.7 CVE-2025-1295 Wordfence
5.3 Medium OneStore Sites Plugin onestore-sites Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 0.1.1 CVE-2024-13905 Wordfence
6.4 Medium Forminator Plugin forminator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting 1.39.2 CVE-2025-0469 Wordfence
4.3 Medium School Management System – SakolaWP Plugin sakolawp-lite Cross-Site Request Forgery SakolaWP <= 1.0.8 - Cross-Site Request Forgery to Exam Setting Manipulation No login needed ≤ 1.0.8 CVE-2024-13647 Wordfence
5.3 Medium Events Manager Plugin events-manager Broken Access Control No login needed ≤ 6.6.4.1 Fixed in 6.6.4.2 CVE-2025-1249 Patchstack
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
4.4 Medium Quiz Organizer Plugin quiz-organizer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.9.1 CVE-2024-6810 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text, Countdown Widget, and Login Form Shortcodes ≤ 3.6.0 CVE-2025-1517 Wordfence
4.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.1.6 CVE-2024-13560 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.3 CVE-2024-13803 Wordfence
6.1 Medium R3W Instafeed Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13678 WPScan
6.1 Medium CalendApp Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13669 WPScan
6.1 Medium Post Sync Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13634 WPScan
7.1 High Simple Catalogue Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.2 CVE-2024-13633 WPScan
7.1 High WP Extra Fields Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1 CVE-2024-13632 WPScan
7.1 High OM Stripe Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 02.00.00 CVE-2024-13631 WPScan
6.1 Medium News List Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13630 WPScan
6.1 Medium Pushbiz Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13629 WPScan
6.1 Medium WP Pricing Table Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-13628 WPScan
7.1 High WPMovieLibrary Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.1.4.8 CVE-2024-13624 WPScan
7.1 High Post Timeline Plugin post-timeline Cross-Site Scripting Reflected XSS No login needed < 2.3.10 Fixed in 2.3.10 CVE-2024-13571 WPScan
5.9 Medium Countdown Timer for Elementor Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.3.7 Fixed in 1.3.7 CVE-2024-13113 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only