WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 19,351–19,400 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 388 of 589
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Automate Hub Free by Sperse.IO Plugin automate-hub-free-by-sperse-io Cross-Site Request Forgery Cross-Site Request Forgery to Activation Status Update No login needed ≤ 1.7.0 CVE-2024-13683 Wordfence
6.5 Medium Form Builder CP Plugin cp-easy-form-builder SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.41 CVE-2024-13680 Wordfence
6.4 Medium Listamester Plugin listamester Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.4 CVE-2024-13659 Wordfence
7.1 High Save & Import Image from URL Plugin save-import-image-from-url Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7 CVE-2025-23960 Patchstack
7.1 High wp-flickr-press Plugin wp-flickr-press Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.4 CVE-2025-23894 Patchstack
7.1 High Custom Coming Soon Plugin custom-coming-soon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-23836 Patchstack
7.1 High Legal + Plugin legal-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23835 Patchstack
7.1 High Links/Problem Reporter Plugin report-broken-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-23834 Patchstack
7.1 High SC Simple Zazzle Plugin sc-simple-zazzle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23733 Patchstack
7.1 High FLX Dashboard Groups Plugin flx-dashboard-groups Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23730 Patchstack
7.1 High XTRA Settings Plugin xtra-settings Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.8 CVE-2025-23729 Patchstack
7.1 High AZ Content Finder Plugin az-content-finder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23727 Patchstack
7.1 High Accessibility Task Manager Plugin accessibility-task-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23725 Patchstack
7.1 High University Quizzes Online Plugin university-quizzes-online Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23724 Patchstack
7.1 High Plestar Directory Listing Plugin plestar-directory-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23723 Patchstack
7.1 High Mind3doM RyeBread Widgets Plugin mind3dom-ryebread-widgets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23722 Patchstack
7.1 High My Favorite Car Plugin my-favorite-cars Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23636 Patchstack
7.1 High Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-23634 Patchstack
7.1 High Gallerio Plugin gallerio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23629 Patchstack
7.1 High GeoDigs Plugin geodigs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.1 CVE-2025-23628 Patchstack
7.1 High Kumihimo Plugin kumihimo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23626 Patchstack
7.1 High WpDevTool Plugin wpdevtool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1 CVE-2025-23624 Patchstack
7.1 High WP Social Broadcast Plugin wp-social-broadcast Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23545 Patchstack
7.1 High StatPressCN Plugin statpresscn Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23544 Patchstack
7.1 High Download, Downloads Plugin ydn-download Cross-Site Scripting No login needed ≤ 1.4.2 CVE-2025-23541 Patchstack
7.1 High Rocket Media Library Mime Type Plugin rocket-media-library-mime-type Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-22768 Patchstack
7.1 High WP Query Creator Plugin wp-query-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22264 Patchstack
7.1 High WP Front-end login and register Plugin wp-front-end-login-and-register Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-23540 Patchstack
6.4 Medium MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting Meta Data and Taxonomies Filter <= 1.3.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.3.6 CVE-2024-13340 Wordfence
6.4 Medium Cliptakes Plugin cliptakes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 CVE-2024-13389 Wordfence
6.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.9.0 CVE-2024-12118 Wordfence
6.1 Medium SEO Blogger to WordPress Migration using 301 Redirection Plugin seo-blogger-to-wordpress-301-redirector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.4.8 CVE-2024-13422 Wordfence
6.5 Medium Tainacan Plugin tainacan SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 0.21.12 CVE-2024-13236 Wordfence
6.4 Medium Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP Plugin Cross-Site Scripting Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.9 CVE-2024-12504 Wordfence
7.5 High Product Table by WBW Plugin SQL Injection Unuthenticated SQL Injection No login needed ≤ 2.1.2 CVE-2024-13234 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.16.5 CVE-2024-12043 Wordfence
7.5 High BMLT Meeting Map Plugin bmlt-meeting-map Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 2.6.0 CVE-2024-13593 Wordfence
4.3 Medium Variation Swatches for WooCommerce Plugin th-variation-swatches Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Reset No login needed 1.0.8 – 1.3.2 CVE-2024-13511 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets ≤ 3.11.11 CVE-2024-12477 Wordfence
9.8 Critical Muzaara Google Ads Report Plugin muzaara-adwords-optimize-dashboard PHP Object Injection No login needed ≤ 3.1 CVE-2025-23914 Patchstack
7.1 High Blue Wrench Video Widget Plugin blue-wrench-videos-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-23809 Patchstack
5.9 Medium Toocheke Companion Plugin toocheke-companion Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.166 Fixed in 1.167 CVE-2025-23992 Patchstack
7.1 High WP Download Codes Plugin wp-download-codes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 CVE-2025-23882 Patchstack
7.1 High Flexible Blogtitle Plugin flexible-blogtitle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23846 Patchstack
7.1 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23812 Patchstack
7.1 High InFunding Plugin infunding Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23768 Patchstack
7.1 High CMC MIGRATE Plugin cmc-migrate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.3 CVE-2025-23746 Patchstack
7.1 High Formatted post Plugin formatted-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.01 CVE-2025-23709 Patchstack
7.1 High ReadMe Creator Plugin readme-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23643 Patchstack
7.1 High WP IMAP Auth Plugin wp-imap-authentication Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.1 CVE-2025-23506 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only