WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 19,201–19,250 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 385 of 589
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Broadstreet Plugin broadstreet Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via zone Parameter ≤ 1.51.0 CVE-2024-11825 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin learnpress Cross-Site Scripting WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name ≤ 4.2.7.5 CVE-2024-13599 Wordfence
6.4 Medium Power Ups for Elementor Plugin power-ups-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-13548 Wordfence
6.4 Medium WordPress SEO Friendly Accordion FAQ with AI assisted content generation Plugin notice-faq Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-13458 Wordfence
6.5 Medium Connections Business Directory Plugin connections Arbitrary File Deletion Authenticated (Admin+) Arbitrary Directory Deletion ≤ 10.4.66 CVE-2024-12885 Wordfence
6.4 Medium brodos.net Onlineshop Plugin brodos-net-onlineshop Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 CVE-2024-12529 Wordfence
6.4 Medium Ask Me Anything (Anonymously) Plugin ask-me-anything-anonymously Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6 CVE-2024-12512 Wordfence
6.1 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.8.3 CVE-2024-12076 Wordfence
6.4 Medium NOTICE BOARD BY TOWKIR Plugin notice-board-by-towkir Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1 CVE-2024-12816 Wordfence
7.2 High Custom Product Tabs Lite for WooCommerce Plugin woocommerce-custom-product-tabs-lite PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.9.0 CVE-2024-12600 Wordfence
6.4 Medium Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via API parameters ≤ 3.14.26 CVE-2024-10552 Wordfence
6.4 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via anchor ≤ 1.1.8 CVE-2024-13721 Wordfence
8.8 High ThemeREX Addons Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.33.0 CVE-2025-0682 Wordfence
4.3 Medium Linear Plugin linear Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset No login needed ≤ 2.8.1 CVE-2024-13709 Wordfence
9.8 Critical WPBookit Plugin wpbookit Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6.9 CVE-2025-0357 Wordfence
7.6 High Email Subscription Popup Plugin email-subscribe SQL Injection ≤ 1.2.23 Fixed in 1.2.24 CVE-2025-24587 Patchstack
6.5 Medium Popup Maker Plugin popup-maker Cross-Site Scripting ≤ 1.20.2 Fixed in 1.20.3 CVE-2025-24746 Patchstack
4.3 Medium Post Duplicator Plugin post-duplicator Broken Access Control ≤ 2.35 Fixed in 2.36 CVE-2025-24736 Patchstack
6.5 Medium PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce Cross-Site Scripting ≤ 4.6.0 Fixed in 4.7.0 CVE-2025-24755 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-24753 Patchstack
4.3 Medium CoBlocks Plugin coblocks Broken Access Control ≤ 3.1.13 Fixed in 3.1.14 CVE-2025-24751 Patchstack
5.4 Medium ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control ≤ 8.1.0 Fixed in 8.2.0 CVE-2025-24750 Patchstack
7.1 High Roi Calculator Plugin roi-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24756 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-24729 Patchstack
6.5 Medium Post Grid Master Plugin ajax-filter-posts Local File Inclusion ≤ 3.4.12 Fixed in 3.4.13 CVE-2025-24733 Patchstack
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
6.5 Medium HT Contact Form 7 Plugin ht-contactform Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-24726 Patchstack
6.5 Medium WP VR Plugin wpvr Cross-Site Scripting ≤ 8.5.14 Fixed in 8.5.15 CVE-2025-24730 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-24725 Patchstack
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
8.5 High Bug Library Plugin bug-library SQL Injection ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-24728 Patchstack
5.9 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.55 Fixed in 1.2.56 CVE-2025-24723 Patchstack
6.5 Medium Widget Countdown Plugin widget-countdown Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-24719 Patchstack
6.5 Medium BookingPress Plugin bookingpress-appointment-booking Cross-Site Scripting ≤ 1.1.25 Fixed in 1.1.26 CVE-2025-24732 Patchstack
5.9 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Scripting ≤ 2.38.3 Fixed in 2.38.4 CVE-2025-24731 Patchstack
4.3 Medium FluentSMTP Plugin fluent-smtp Cross-Site Request Forgery No login needed ≤ 2.2.80 Fixed in 2.2.81 CVE-2025-24739 Patchstack
5.4 Medium Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-24724 Patchstack
5.4 Medium Herd Effects Plugin mwp-herd-effect Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-24716 Patchstack
5.9 Medium Contact Form Email Plugin contact-form-to-email Cross-Site Scripting ≤ 1.3.52 Fixed in 1.3.53 CVE-2025-24727 Patchstack
5.4 Medium Modal Window Plugin modal-window Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.4 Fixed in 6.1.5 CVE-2025-24717 Patchstack
4.4 Medium Comment Edit Core – Simple Comment Editing Plugin simple-comment-editing Server-Side Request Forgery Simple Comment Editing Plugin <= 3.0.33 - Server Side Request Forgery (SSRF) ≤ 3.0.33 Fixed in 3.1.0 CVE-2025-24703 Patchstack
5.4 Medium Counter Box Plugin counter-box Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-24715 Patchstack
5.9 Medium FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-24722 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.13 Fixed in 4.2.14 CVE-2025-24706 Patchstack
6.5 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.5 Fixed in 1.2.1 CVE-2025-24709 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only