WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,501–18,550 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 371 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Custom Block Builder – Lazy Blocks Plugin lazy-blocks Cross-Site Scripting Lazy Blocks < 3.8.3 - Reflected XSS No login needed < 3.8.3 Fixed in 3.8.3 CVE-2024-12878 WPScan
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected XSS No login needed < 5.0.0 Fixed in 5.0.0 CVE-2024-12737 WPScan
5.4 Medium WooCommerce Cart Count Shortcode Plugin Cross-Site Scripting Contributor+ XSS < 1.1.0 Fixed in 1.1.0 CVE-2024-10563 WPScan
7.1 High SimplePress Forum Plugin Cross-Site Scripting Reflected XSS No login needed < 6.10.11 Fixed in 6.10.11 CVE-2024-10483 WPScan
7.1 High Simple Certain Time to Show Content Plugin Cross-Site Scripting Reflected XSS No login needed < 1.3.1 Fixed in 1.3.1 CVE-2024-10152 WPScan
5.3 Medium SureMembers Plugin suremembers-core Information Disclosure Sensitive Information Exposure No login needed ≤ 1.10.6 CVE-2024-12434 Wordfence
5.4 Medium Market Exporter Plugin market-exporter Broken Access Control ≤ 2.0.21 Fixed in 2.0.22 CVE-2025-26995 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-26993 Patchstack
7.1 High WPPizza Plugin wppizza Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.19.4 Fixed in 3.19.5 CVE-2025-26991 Patchstack
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-26983 Patchstack
7.1 High Web Accessibility By accessiBe Plugin accessibe Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-26981 Patchstack
6.5 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.5 Fixed in 2.5.1 CVE-2025-26980 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2025-26979 Patchstack
3.8 Low Filebird Plugin filebird Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.2.1 Fixed in 6.4.6 CVE-2025-26977 Patchstack
5.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-26975 Patchstack
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2025-26974 Patchstack
7.6 High Poll Maker Plugin poll-maker SQL Injection ≤ 5.6.5 Fixed in 5.6.6 CVE-2025-26971 Patchstack
9.8 Critical PrivateContent Plugin private-content Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 8.11.5 CVE-2025-26966 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-26965 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion ≤ 4.0.20 Fixed in 4.0.21 CVE-2025-26964 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
6.5 Medium Easy Contact Form Lite Plugin contact-form-lite Cross-Site Scripting ≤ 1.1.25 Fixed in 1.1.27 CVE-2025-26962 Patchstack
6.5 Medium Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Broken Access Control Unishippers Edition plugin <= 2.4.9 - Broken Access Control No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26960 Patchstack
7.5 High Affiliate Coupons Plugin affiliate-coupons Local File Inclusion ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-26957 Patchstack
6.5 Medium Business Card Block Plugin business-card-block Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-26952 Patchstack
6.5 Medium Team Section Block Plugin team-section Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-26949 Patchstack
4.3 Medium Pie Register Premium Plugin pie-register-premium Broken Access Control ≤ 3.8.3.2 Fixed in 3.8.3.3 CVE-2025-26948 Patchstack
6.5 Medium Services Section block Plugin services-section Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-26947 Patchstack
7.6 High WP Yelp Review Slider Plugin wp-yelp-review-slider SQL Injection ≤ 8.1 Fixed in 8.2 CVE-2025-26946 Patchstack
6.5 Medium Info Cards Plugin info-cards Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-26945 Patchstack
9.3 Critical Easy Quotes Plugin easy-quotes SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-26943 Patchstack
6.5 Medium Counters Block Plugin counters-block Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-26939 Patchstack
6.5 Medium Countdown Timer Plugin countdown-time Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-26938 Patchstack
6.5 Medium Icon List Block Plugin icon-list-block Cross-Site Scripting ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-26937 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-26935 Patchstack
7.5 High ChatBot Plugin chatbot Local File Inclusion ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-26932 Patchstack
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
4.3 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-26928 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
8.5 High Wishlist Plugin wishlist SQL Injection ≤ 1.0.41 Fixed in 1.0.42 CVE-2025-26915 Patchstack
6.5 Medium AR Plugin ar-for-wordpress Cross-Site Scripting ≤ 7.7 Fixed in 7.8 CVE-2025-26913 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-26912 Patchstack
4.3 Medium System Dashboard Plugin system-dashboard Information Disclosure Sensitive Data Exposure ≤ 2.8.18 Fixed in 2.8.19 CVE-2025-26911 Patchstack
7.5 High Mortgage Calculator Estatik Plugin estatik-mortgage-calculator Local File Inclusion ≤ 2.0.12 CVE-2025-26907 Patchstack
7.5 High Estatik Plugin estatik Local File Inclusion ≤ 4.3.0 CVE-2025-26905 Patchstack
6.5 Medium WP Responsive Auto Fit Text Plugin wp-responsive-slab-text Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2025-26904 Patchstack
9.8 Critical Flexmls® IDX Plugin flexmls-idx PHP Object Injection No login needed ≤ 3.14.27 Fixed in 3.14.28 CVE-2025-26900 Patchstack
6.5 Medium List Related Attachments Plugin list-related-attachments-widget Cross-Site Scripting ≤ 2.1.6 CVE-2025-26897 Patchstack
6.5 Medium PiwigoPress Plugin piwigopress Cross-Site Scripting ≤ 2.33 CVE-2025-26896 Patchstack
6.5 Medium Easy Charts Plugin easy-charts Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-26893 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only