WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 19,451–19,500 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 390 of 589
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Unique UX Plugin unique-ux Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.2 CVE-2025-23625 Patchstack
7.1 High WH Cache & Security Plugin wh-cache-and-security Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23611 Patchstack
7.1 High Ultimate Events Plugin ultimate-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23610 Patchstack
7.1 High Tagesteller Plugin tagesteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v.1.1 CVE-2025-23609 Patchstack
7.1 High CAMOO SMS Plugin camoo-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.1 CVE-2025-23607 Patchstack
7.1 High Calendi Plugin calendi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-23606 Patchstack
7.1 High Call To Action Popup Plugin call-to-action-popup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23605 Patchstack
7.1 High Rezdy Reloaded Plugin reloaded-rezdy Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23604 Patchstack
7.1 High Group category creator Plugin group-category-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0.3 CVE-2025-23603 Patchstack
7.1 High EELV Newsletter Plugin eelv-newsletter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.2 CVE-2025-23602 Patchstack
7.1 High Tab My Content Plugin tab-my-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23601 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
7.1 High dForms Plugin dforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23592 Patchstack
7.1 High ContentOptin Lite Plugin contentoptin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23589 Patchstack
7.1 High Explara Membership Plugin explara-membership Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23583 Patchstack
7.1 High Custom CSS Addons Plugin css-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23578 Patchstack
7.5 High XLSXviewer Plugin xlsx-viewer Arbitrary File Deletion No login needed ≤ 2.1.1 CVE-2025-23562 Patchstack
7.1 High Responsivity Plugin responsivity Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.6 CVE-2025-23548 Patchstack
7.1 High REAL WordPress Sidebar Plugin drag-and-drop-custom-sidebar Cross-Site Scripting No login needed ≤ 0.1 CVE-2025-23535 Patchstack
7.5 High Team 118GROUP Agent Plugin team-118group-agent Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.6.0 CVE-2025-23512 Patchstack
7.1 High HyperComments Plugin comments-with-hypercommentscom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.6 CVE-2025-23509 Patchstack
7.1 High Blrt WP Embed Plugin blrt-wp-embed Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.9 CVE-2025-23507 Patchstack
7.1 High Customizable Captcha and Contact Us Plugin customizable-captcha-and-contact-us-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23503 Patchstack
7.1 High Simple Custom post type custom field Plugin simple-content-construction-kit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23500 Patchstack
7.1 High Translation.Pro Plugin translation-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23498 Patchstack
7.1 High WooCommerce Order Search Plugin woocommerce-order-searching Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-23495 Patchstack
7.5 High GamiPress Plugin gamipress SQL Injection Unauthenticated SQL Injection via orderby Parameter No login needed ≤ 7.3.1 CVE-2024-13496 Wordfence
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Retrieval ≤ 2.1.6 CVE-2024-13447 Wordfence
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function No login needed ≤ 7.2.1 CVE-2024-13499 Wordfence
7.3 High GamiPress Plugin gamipress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function No login needed ≤ 7.2.1 CVE-2024-13495 Wordfence
7.2 High AI Power: Complete AI Pack Plugin PHP Object Injection Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_forms ≤ 1.8.96 CVE-2025-0429 Wordfence
7.2 High AI Power: Complete AI Pack Plugin PHP Object Injection Authenticated (Admin+) PHP Object Injection via wpaicg_export_prompts ≤ 1.8.96 CVE-2025-0428 Wordfence
6.1 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.6.5 CVE-2024-13319 Wordfence
5.4 Medium AI Power: Complete AI Pack Plugin Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.8.96 CVE-2024-13360 Wordfence
6.3 Medium AI Power: Complete AI Pack Plugin gpt3-ai-content-generator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.8.96 CVE-2024-13361 Wordfence
9.8 Critical AdForest Theme Authentication Bypass No login needed ≤ 5.1.8 CVE-2024-12857 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
6.1 Medium XML for Google Merchant Center Plugin xml-for-google-merchant-center Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.0.11 CVE-2024-13406 Wordfence
4.3 Medium WPBot Pro Wordpress Chatbot Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation ≤ 13.5.5 CVE-2024-12879 Wordfence
6.4 Medium Ketchup Shortcodes Plugin ketchup-shortcodes-pack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.2 CVE-2024-13590 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.19 CVE-2024-13584 Wordfence
5.4 Medium WP-Polls Plugin wp-polls SQL Injection Unauthenticated SQL Injection to Stored Cross-Site Scripting No login needed ≤ 2.77.2 CVE-2024-13426 Wordfence
9.8 Critical WPBot Pro Wordpress Chatbot Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 13.5.4 CVE-2024-13091 Wordfence
4.3 Medium AnyRoad Plugin anyguide Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-23996 Patchstack
7.1 High Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings plugin <= 5.5.0 - CSRF to Settings Update & Stored XSS No login needed ≤ 5.5.0 CVE-2025-23994 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control Broken Access Control to Notice Dimissal ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-22722 Patchstack
4.3 Medium ApplyOnline Plugin apply-online Broken Access Control ≤ 2.6.7.1 Fixed in 2.6.7.2 CVE-2025-22721 Patchstack
6.5 Medium Online Payments – Get Paid with PayPal, Square & Stripe Plugin paypal-payment-button-by-vcita Cross-Site Scripting ≤ 3.20.0 Fixed in 3.30.0 CVE-2025-22661 Patchstack
7.1 High BizLibrary Plugin bizlibrary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23580 Patchstack
7.1 High SexBundle Plugin sexbundle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23551 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only