WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,551–18,600 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 372 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ibtana Plugin ibtana-visual-editor Cross-Site Scripting ≤ 1.2.5.9 CVE-2025-26891 Patchstack
6.5 Medium EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Scripting ≤ 5.21.35 Fixed in 5.25.08 CVE-2025-26887 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 10.8 Fixed in 10.9 CVE-2025-26884 Patchstack
6.5 Medium Popup Builder Plugin easy-notify-lite Cross-Site Scripting ≤ 1.1.33 Fixed in 1.1.35 CVE-2025-26882 Patchstack
6.5 Medium Sticky Content Plugin sticky-menu-block Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26881 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.5 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-26877 Patchstack
6.8 Medium Search with Typesense Plugin search-with-typesense Path Traversal ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-26876 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.8.3 Fixed in 4.8.4 CVE-2025-26871 Patchstack
7.1 High Fast Flow Plugin fast-flow-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.16 Fixed in 1.2.18 CVE-2025-26868 Patchstack
7.5 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Path Traversal Arbitrary File Download No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26753 Patchstack
8.6 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Arbitrary File Deletion No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26752 Patchstack
7.1 High Alphabetic Pagination Plugin alphabetic-pagination Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-26751 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.25.10 Fixed in 3.25.11 CVE-2024-54444 Patchstack
5.4 Medium Simple Photo Feed Plugin simple-photo-feed Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-27000 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.25.17 Fixed in 3.25.18 CVE-2025-26987 Patchstack
8.1 High Majestic Support Plugin majestic-support Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-26985 Patchstack
5.3 Medium Advanced Google reCaptcha Plugin advanced-google-recaptcha Authentication Bypass Built-in Math CAPTCHA Bypass No login needed ≤ 1.27 CVE-2025-1262 Wordfence
6.4 Medium Enfold Theme Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id ≤ 6.0.9 CVE-2024-13695 Wordfence
5.3 Medium Enfold Theme Broken Access Control Missing Authorization to Sensitive Information Disclosure in avia-export-class.php No login needed ≤ 6.0.9 CVE-2024-13693 Wordfence
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Cross-Site Request Forgery in wfu_file_details No login needed ≤ 4.25.2 CVE-2024-13494 Wordfence
9.8 Critical Everest Forms Plugin everest-forms Arbitrary File Upload Unauthenticated Arbitrary File Upload, Read, and Deletion No login needed ≤ 3.0.9.4 CVE-2025-1128 Wordfence
5.3 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Information Disclosure Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure No login needed ≤ 4.0.4 CVE-2025-1063 Wordfence
7.5 High Yawave Plugin yawave SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.1 CVE-2025-1648 Wordfence
3.5 Low NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.9 Fixed in 3.59.9 CVE-2024-10545 WPScan
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
5.4 Medium Sticky Header On Scroll Plugin sticky-header-on-scroll Broken Access Control ≤ 1.0 CVE-2025-27356 Patchstack
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
7.1 High 无觅相关文章插件 Plugin wumii-related-posts Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.5.7 CVE-2025-27352 Patchstack
6.5 Medium Local Search SEO Contact Page Plugin local-search-seo-contact-page Cross-Site Scripting ≤ 4.0.1 CVE-2025-27351 Patchstack
6.5 Medium Get Posts Plugin nurelm-get-posts Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.6 CVE-2025-27349 Patchstack
6.5 Medium WP Social SEO Booster – Knowledge Graph Social Signals SEO Plugin wp-social-seo-booster Cross-Site Scripting ≤ 1.2.0 CVE-2025-27348 Patchstack
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
6.5 Medium Reactive Mortgage Calculator Plugin reactive-mortgage-calculator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-27341 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
7.1 High Smart Maintenance & Countdown Plugin smart-maintenance-countdown Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-27332 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
6.5 Medium PlayerJS Plugin playerjs Cross-Site Scripting ≤ 2.23 Fixed in 2.24 CVE-2025-27330 Patchstack
6.5 Medium EZ InLinkz linkup Plugin inlinkz-scripter Cross-Site Scripting ≤ 0.18 CVE-2025-27329 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
6.5 Medium Live Streaming Video Player – by SRS Player Plugin srs-player Cross-Site Scripting by SRS Player plugin <= 1.0.18 - Cross Site Scripting (XSS) ≤ 1.0.18 CVE-2025-27327 Patchstack
6.5 Medium Animated Text Block Plugin animated-text-block Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26883 Patchstack
6.5 Medium Video.js HLS Player Plugin videojs-hls-player Cross-Site Scripting ≤ 1.0.2 CVE-2025-27325 Patchstack
6.5 Medium WP About Author Plugin wp-about-author Cross-Site Scripting ≤ 1.5 Fixed in 1.6 CVE-2025-27323 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only