WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,951–19,000 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 380 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Easy Amazon Product Information Plugin easy-amazon-product-information Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.1 CVE-2025-26568 Patchstack
6.5 Medium Font Awesome WP Plugin font-awesome-wp Cross-Site Scripting ≤ 1.0 CVE-2025-26567 Patchstack
7.1 High RSS Filter Plugin rss-filter Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-26562 Patchstack
5.9 Medium Elfsight Yottie Lite Plugin yottie-lite Cross-Site Scripting ≤ 1.3.3 CVE-2025-26561 Patchstack
6.5 Medium Aparat Responsive Plugin aparat-responsive Cross-Site Scripting ≤ 1.3 CVE-2025-26558 Patchstack
7.1 High Naver Syndication V2 Plugin badr-naver-syndication Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.8.3 CVE-2025-26552 Patchstack
7.1 High Bootstrap collapse Plugin bootstrap-collapse Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-26551 Patchstack
7.1 High Global Meta Keyword & Description Plugin global-meta-keyword-and-description Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 2.3 CVE-2025-26550 Patchstack
7.1 High WP Html Page Sitemap Plugin wp-html-page-sitemap Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26549 Patchstack
7.1 High My Login Logout Plugin my-loginlogout Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26547 Patchstack
7.1 High Related Posts Line-up-Exactly by Milliard Plugin related-posts-line-up-exactry-by-milliard Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.22 CVE-2025-26545 Patchstack
7.1 High Simple Responsive Menu Plugin simple-responsive-menu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26543 Patchstack
9.8 Critical WP Directorybox Manager Plugin Authentication Bypass No login needed ≤ 2.5 CVE-2024-13182 Wordfence
7.5 High JS Help Desk – The Ultimate Help Desk & Support Plugin js-support-ticket Information Disclosure The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.8.8 CVE-2024-13606 Wordfence
6.1 Medium Listivo - Classified Ads Theme Cross-Site Scripting Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting No login needed ≤ 2.3.67 CVE-2024-13867 Wordfence
4.3 Medium Read More & Accordion Plugin expand-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletion ≤ 3.4.2 CVE-2024-13639 Wordfence
7.3 High Avada Builder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.11.13 CVE-2024-13345 Wordfence
4.3 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Information Disclosure Authenticated (Contributor+) Protected Post Disclosure ≤ 2.1.8 CVE-2025-0661 Wordfence
7.3 High Avada Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.11.13 CVE-2024-13346 Wordfence
3.5 Low Simple Video Management System Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.4 CVE-2025-0692 WPScan
3.5 Low Everest Forms Plugin everest-forms Cross-Site Scripting Admin+ Stored XSS < 3.0.8.1 Fixed in 3.0.8.1 CVE-2024-13125 WPScan
3.5 Low Paid Membership Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.20 Fixed in 4.15.20 CVE-2024-13121 WPScan
4.8 Medium ProfilePress Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.20 Fixed in 4.15.20 CVE-2024-13120 WPScan
4.8 Medium ProfilePress Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.20 Fixed in 4.15.20 CVE-2024-13119 WPScan
6.1 Medium Chalet Montagne Com Tools Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.7.8 CVE-2024-12586 WPScan
9.8 Critical Campress Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.35 CVE-2024-10763 Wordfence
6.4 Medium Puzzles Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.2.6 CVE-2025-0837 Wordfence
8.1 High Puzzles | WP Magazine / Review with Store WordPress Theme + RTL Theme PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.2.4 CVE-2024-13770 Wordfence
4.3 Medium Rank Math SEO Plugin seo-by-rank-math Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion ≤ 1.0.235 CVE-2024-13229 Wordfence
6.4 Medium Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math Cross-Site Scripting AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API ≤ 1.0.235 CVE-2024-13227 Wordfence
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget ≤ 2.1.8 CVE-2024-13644 Wordfence
6.4 Medium Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.6.8 CVE-2024-10322 Wordfence
7.5 High Small Package Quotes – Purolator Edition Plugin small-package-quotes-purolator-edition SQL Injection Purolator Edition <= 3.6.4 - Unauthenticated SQL Injection No login needed ≤ 3.6.4 CVE-2024-13532 Wordfence
7.5 High LTL Freight Quotes – For Customers of FedEx Freight Plugin ltl-freight-quotes-fedex-freight-edition SQL Injection For Customers of FedEx Freight <= 3.4.1 - Unauthenticated SQL Injection No login needed ≤ 3.4.1 CVE-2024-13480 Wordfence
8.1 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Account Deletion No login needed ≤ 2.7.3 CVE-2024-12386 Wordfence
7.2 High Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via name Parameter No login needed ≤ 2.11.9 CVE-2025-0511 Wordfence
7.5 High LTL Freight Quotes – Unishippers Edition Plugin ltl-freight-quotes-unishippers-edition SQL Injection Unishippers Edition <= 2.5.8 - Unauthenticated SQL Injection No login needed ≤ 2.5.8 CVE-2024-13477 Wordfence
9.9 Critical Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads ≤ 2.6.4 CVE-2024-10960 Wordfence
7.5 High ShipEngine Shipping Quotes Plugin shipengine-shipping-quotes SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.7 CVE-2024-13531 Wordfence
8.8 High Apus Framework Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in import_page_options ≤ 2.4 CVE-2024-12296 Wordfence
7.5 High Small Package Quotes – UPS Edition Plugin small-package-quotes-ups-edition SQL Injection UPS Edition <= 4.5.16 - Unauthenticated SQL Injection No login needed ≤ 4.5.16 CVE-2024-13475 Wordfence
6.4 Medium FuseDesk Plugin fusedesk Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.6.1 CVE-2024-13459 Wordfence
4.3 Medium Book a Room Plugin book-a-room Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.9 CVE-2024-13437 Wordfence
7.5 High LTL Freight Quotes – XPO Edition Plugin ltl-freight-quotes-xpo-edition SQL Injection XPO Edition <= 4.3.7 - Unauthenticated SQL Injection No login needed ≤ 4.3.7 CVE-2024-13490 Wordfence
9.8 Critical Security & Malware scan by CleanTalk Plugin security-malware-firewall Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.149 CVE-2024-13365 Wordfence
6.4 Medium Easy Quiz Maker Plugin n-media-wp-simple-quiz Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-13456 Wordfence
7.5 High Ebook Downloader Plugin ebook-downloader SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0 CVE-2024-13435 Wordfence
9.8 Critical WP Job Board Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via process_register No login needed < 1.2.85 Fixed in 1.2.85 CVE-2024-12213 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleTag Parameter ≤ 3.6 CVE-2025-0506 Wordfence
7.5 High LTL Freight Quotes - Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition SQL Injection Worldwide Express Edition <= 5.0.20 - Unauthenticated SQL Injection No login needed ≤ 5.0.20 CVE-2024-13473 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only