WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 18,951–19,000 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Easy Amazon Product Information | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 4.0.1 |
CVE-2025-26568 |
Patchstack | |
| 6.5 Medium | Font Awesome WP | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-26567 |
Patchstack | |
| 7.1 High | RSS Filter | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-26562 |
Patchstack | |
| 5.9 Medium | Elfsight Yottie Lite | Cross-Site Scripting |
≤ 1.3.3 |
CVE-2025-26561 |
Patchstack | |
| 6.5 Medium | Aparat Responsive | Cross-Site Scripting |
≤ 1.3 |
CVE-2025-26558 |
Patchstack | |
| 7.1 High | Naver Syndication V2 | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 0.8.3 |
CVE-2025-26552 |
Patchstack | |
| 7.1 High | Bootstrap collapse | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.0.4 |
CVE-2025-26551 |
Patchstack | |
| 7.1 High | Global Meta Keyword & Description | Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed |
≤ 2.3 |
CVE-2025-26550 |
Patchstack | |
| 7.1 High | WP Html Page Sitemap | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2025-26549 |
Patchstack | |
| 7.1 High | My Login Logout | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 2.4 |
CVE-2025-26547 |
Patchstack | |
| 7.1 High | Related Posts Line-up-Exactly by Milliard | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 0.0.22 |
CVE-2025-26545 |
Patchstack | |
| 7.1 High | Simple Responsive Menu | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1 |
CVE-2025-26543 |
Patchstack | |
| 9.8 Critical | WP Directorybox Manager | Authentication Bypass No login needed |
≤ 2.5 |
CVE-2024-13182 |
Wordfence | |
| 7.5 High | JS Help Desk – The Ultimate Help Desk & Support | Information Disclosure The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 2.8.8 |
CVE-2024-13606 |
Wordfence | |
| 6.1 Medium | Listivo - Classified Ads | Cross-Site Scripting Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting No login needed |
≤ 2.3.67 |
CVE-2024-13867 |
Wordfence | |
| 4.3 Medium | Read More & Accordion | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletion |
≤ 3.4.2 |
CVE-2024-13639 |
Wordfence | |
| 7.3 High | Avada Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.11.13 |
CVE-2024-13345 |
Wordfence | |
| 4.3 Medium | DethemeKit For Elementor | Information Disclosure Authenticated (Contributor+) Protected Post Disclosure |
≤ 2.1.8 |
CVE-2025-0661 |
Wordfence | |
| 7.3 High | Avada | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 7.11.13 |
CVE-2024-13346 |
Wordfence | |
| 3.5 Low | Simple Video Management System | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.0.4 |
CVE-2025-0692 |
WPScan | |
| 3.5 Low | Everest Forms | Cross-Site Scripting Admin+ Stored XSS |
< 3.0.8.1 Fixed in 3.0.8.1 |
CVE-2024-13125 |
WPScan | |
| 3.5 Low | Paid Membership | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.20 Fixed in 4.15.20 |
CVE-2024-13121 |
WPScan | |
| 4.8 Medium | ProfilePress | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.20 Fixed in 4.15.20 |
CVE-2024-13120 |
WPScan | |
| 4.8 Medium | ProfilePress | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.20 Fixed in 4.15.20 |
CVE-2024-13119 |
WPScan | |
| 6.1 Medium | Chalet Montagne Com Tools | Cross-Site Scripting Reflected XSS No login needed |
≤ 2.7.8 |
CVE-2024-12586 |
WPScan | |
| 9.8 Critical | Campress | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 1.35 |
CVE-2024-10763 |
Wordfence | |
| 6.4 Medium | Puzzles | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.2.6 |
CVE-2025-0837 |
Wordfence | |
| 8.1 High | Puzzles | WP Magazine / Review with Store WordPress Theme + RTL | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 4.2.4 |
CVE-2024-13770 |
Wordfence | |
| 4.3 Medium | Rank Math SEO | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion |
≤ 1.0.235 |
CVE-2024-13229 |
Wordfence | |
| 6.4 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Cross-Site Scripting AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API |
≤ 1.0.235 |
CVE-2024-13227 |
Wordfence | |
| 6.4 Medium | DethemeKit For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget |
≤ 2.1.8 |
CVE-2024-13644 |
Wordfence | |
| 6.4 Medium | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.6.8 |
CVE-2024-10322 |
Wordfence | |
| 7.5 High | Small Package Quotes – Purolator Edition | SQL Injection Purolator Edition <= 3.6.4 - Unauthenticated SQL Injection No login needed |
≤ 3.6.4 |
CVE-2024-13532 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – For Customers of FedEx Freight | SQL Injection For Customers of FedEx Freight <= 3.4.1 - Unauthenticated SQL Injection No login needed |
≤ 3.4.1 |
CVE-2024-13480 |
Wordfence | |
| 8.1 High | WP Abstracts | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Account Deletion No login needed |
≤ 2.7.3 |
CVE-2024-12386 |
Wordfence | |
| 7.2 High | Welcart e-Commerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via name Parameter No login needed |
≤ 2.11.9 |
CVE-2025-0511 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – Unishippers Edition | SQL Injection Unishippers Edition <= 2.5.8 - Unauthenticated SQL Injection No login needed |
≤ 2.5.8 |
CVE-2024-13477 |
Wordfence | |
| 9.9 Critical | Brizy – Page Builder | Arbitrary File Upload Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads |
≤ 2.6.4 |
CVE-2024-10960 |
Wordfence | |
| 7.5 High | ShipEngine Shipping Quotes | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.0.7 |
CVE-2024-13531 |
Wordfence | |
| 8.8 High | Apus Framework | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in import_page_options |
≤ 2.4 |
CVE-2024-12296 |
Wordfence | |
| 7.5 High | Small Package Quotes – UPS Edition | SQL Injection UPS Edition <= 4.5.16 - Unauthenticated SQL Injection No login needed |
≤ 4.5.16 |
CVE-2024-13475 |
Wordfence | |
| 6.4 Medium | FuseDesk | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.6.1 |
CVE-2024-13459 |
Wordfence | |
| 4.3 Medium | Book a Room | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 2.9 |
CVE-2024-13437 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – XPO Edition | SQL Injection XPO Edition <= 4.3.7 - Unauthenticated SQL Injection No login needed |
≤ 4.3.7 |
CVE-2024-13490 |
Wordfence | |
| 9.8 Critical | Security & Malware scan by CleanTalk | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.149 |
CVE-2024-13365 |
Wordfence | |
| 6.4 Medium | Easy Quiz Maker | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0 |
CVE-2024-13456 |
Wordfence | |
| 7.5 High | Ebook Downloader | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.0 |
CVE-2024-13435 |
Wordfence | |
| 9.8 Critical | WP Job Board Pro | Privilege Escalation Unauthenticated Privilege Escalation via process_register No login needed |
< 1.2.85 Fixed in 1.2.85 |
CVE-2024-12213 |
Wordfence | |
| 6.4 Medium | Rise Blocks – A Complete Gutenberg Page Builder | Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleTag Parameter |
≤ 3.6 |
CVE-2025-0506 |
Wordfence | |
| 7.5 High | LTL Freight Quotes - Worldwide Express Edition | SQL Injection Worldwide Express Edition <= 5.0.20 - Unauthenticated SQL Injection No login needed |
≤ 5.0.20 |
CVE-2024-13473 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.