WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 19,101–19,150 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 383 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Links in Captions Plugin links-in-captions Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2 CVE-2025-25098 Patchstack
6.5 Medium FlexIDX Home Search Plugin flexidx-home-search Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.2 CVE-2025-25082 Patchstack
5.9 Medium Easy WP Tiles Plugin easy-wp-tiles Cross-Site Scripting ≤ 1 CVE-2025-25073 Patchstack
7.1 High WP Admin Custom Page Plugin wp-admin-custom-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.0 CVE-2025-25072 Patchstack
6.5 Medium NextGen Cooliris Gallery Plugin nextgen-cooliris-gallery Cross-Site Scripting ≤ 0.7 CVE-2025-25091 Patchstack
6.5 Medium Graceful Email Obfuscation Plugin graceful-email-obfuscation Cross-Site Scripting ≤ 0.2.2 CVE-2025-25076 Patchstack
4.3 Medium Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time Plugin builder-shortcode-extras Information Disclosure WordPress Shortcodes Collection to Save You Time <= 1.0.0 - Authenticated (Contributor+) Post Disclosure ≤ 1.0.0 CVE-2024-13841 Wordfence
6.1 Medium Guten Free Options Plugin guten-free-options Cross-Site Scripting Reflected XSS No login needed ≤ 0.9.5 CVE-2024-13492 WPScan
7.1 High Legull Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2.2 CVE-2024-13352 WPScan
9.8 Critical Nextend Social Login Pro Plugin Authentication Bypass Authentication Bypass via Apple OAuth provider No login needed ≤ 3.1.16 CVE-2025-1061 Wordfence
6.5 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function ≤ 1.27.6 CVE-2025-0859 Wordfence
7.3 High CURCY – Multi Currency for WooCommerce Plugin woo-multi-currency Arbitrary Shortcode Execution Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function No login needed ≤ 2.2.5 CVE-2024-13487 Wordfence
4.7 Medium LikeBot – Decentralized like-system Plugin Cross-Site Scripting Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF No login needed ≤ 0.85 CVE-2025-0522 WPScan
5.3 Medium WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Information Disclosure Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.0.8 CVE-2024-13829 Wordfence
8.1 High Contact Manager Plugin Arbitrary File Upload Unauthenticated Arbitrary Double File Extension Upload No login needed ≤ 8.6.4 CVE-2025-1028 Wordfence
7.1 High World Cup Predictor Plugin world-cup-predictor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.8 CVE-2025-22794 Patchstack
6.5 Medium Ksher Plugin ksher-payment Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22730 Patchstack
6.5 Medium Alert Box Block – Display notice/alerts in the front end Plugin alert-box-block Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-22675 Patchstack
6.5 Medium Product Blocks for WooCommerce Plugin product-blocks-for-woocommerce Cross-Site Scripting ≤ 1.9.1 Fixed in 2.0 CVE-2025-22674 Patchstack
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.1.3.5 Fixed in 5.1.3.6 CVE-2025-22664 Patchstack
6.5 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-22662 Patchstack
6.5 Medium Music Press Pro Plugin music-press-pro Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.4.6 CVE-2025-22653 Patchstack
4.3 Medium OnePress Plugin onepress Broken Access Control ≤ 2.3.11 CVE-2025-22643 Patchstack
6.5 Medium Dynamic Conditions Plugin dynamicconditions Cross-Site Scripting ≤ 1.7.4 Fixed in 1.7.5 CVE-2025-22642 Patchstack
5.9 Medium FM Notification Bar Plugin fm-notification-bar Cross-Site Scripting ≤ 1.0.4 CVE-2025-22641 Patchstack
9.9 Critical Post/Page Copying Tool Plugin postpage-import-export-with-custom-fields-taxonomies Remote Code Execution ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-24677 Patchstack
7.5 High Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Privilege Escalation ≤ 7.6.2.1 Fixed in 7.6.3 CVE-2025-24648 Patchstack
7.1 High WP24 Domain Check Plugin wp24-domain-check Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.10.14 Fixed in 1.10.15 CVE-2025-24602 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.9.6 Fixed in 4.9.9.7 CVE-2025-24599 Patchstack
7.1 High WP Mailster Plugin wp-mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.17.0 Fixed in 1.8.18.0 CVE-2025-24598 Patchstack
7.1 High Find Content IDs Plugin find-content-ids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23645 Patchstack
8.5 High Traveler Code Plugin traveler-code SQL Injection Subscriber+ Arbitrary SQL Execution ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-22700 Patchstack
9.0 Critical Traveler Code Plugin traveler-code SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.1.2 Fixed in 3.1.2 CVE-2025-22699 Patchstack
6.5 Medium Responsive Blocks Plugin responsive-block-editor-addons Cross-Site Scripting ≤ 1.9.9 Fixed in 2.0.0 CVE-2025-22697 Patchstack
5.4 Medium Document Block – Upload & Embed Docs Plugin document Broken Access Control Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin <= 1.1.0 - Broken Access Control ≤ 1.1.0 CVE-2025-22696 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.7 CVE-2024-13699 Wordfence
6.5 Medium SocialV - Social Network and Community BuddyPress Theme Broken Access Control Social Network and Community BuddyPress Theme <= 2.0.15 - Missing Authorization to Arbitrary File Download ≤ 2.0.15 CVE-2024-13529 Wordfence
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13733 Wordfence
6.1 Medium ShopSite Plugin shopsite-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.10 CVE-2024-13510 Wordfence
6.5 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion No login needed ≤ 4.6 CVE-2024-13356 Wordfence
6.4 Medium WPForms Lite Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter ≤ 1.9.3.1 CVE-2024-13403 Wordfence
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
4.3 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 1.6.2 CVE-2024-12046 Wordfence
4.3 Medium JS Help Desk – The Ultimate Help Desk & Support Plugin js-support-ticket Broken Access Control The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.8.8 CVE-2024-13607 Wordfence
6.4 Medium HT Mega Plugin ht-mega-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css ≤ 2.7.6 CVE-2024-12597 Wordfence
5.3 Medium Sensei LMS Plugin sensei-lms Information Disclosure Unauthenticated sensei_email/sensei_message Disclosure No login needed < 4.24.4 Fixed in 4.24.4 CVE-2025-0466 WPScan
6.1 Medium Banner Garden Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.1.3 CVE-2025-0368 WPScan
6.1 Medium TransFinanz Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13332 WPScan
6.1 Medium WP Dream Carousel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1b CVE-2024-13331 WPScan
7.1 High Justrows Free Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.2 CVE-2024-13330 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only