WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 19,501–19,550 of 29,413 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | WP-Announcements | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.8 |
CVE-2025-23489 |
Patchstack | |
| 8.2 High | Realty Workstation | Broken Access Control No login needed |
≤ 1.0.45 |
CVE-2025-23477 |
Patchstack | |
| 5.9 Medium | Related Post Shortcode | Cross-Site Scripting |
≤ 1.2 |
CVE-2025-22276 |
Patchstack | |
| 6.5 Medium | Weaver Themes Shortcode Compatibility | Cross-Site Scripting |
≤ 1.0.4 |
CVE-2025-22267 |
Patchstack | |
| 7.1 High | Social2Blog | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.2.990 |
CVE-2025-23461 |
Patchstack | |
| 7.1 High | Nature FlipBook | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.7 |
CVE-2025-23454 |
Patchstack | |
| 7.1 High | PPO Call To Actions | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 0.1.3 |
CVE-2025-24001 |
Patchstack | |
| 7.1 High | UltraLight | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-23998 |
Patchstack | |
| 6.5 Medium | Tamara Checkout | Cross-Site Scripting |
≤ 1.9.9.1 Fixed in 1.9.9.1 |
CVE-2025-23997 |
Patchstack | |
| 6.5 Medium | Flexible PDF Coupons | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.10.3 Fixed in 1.10.3 |
CVE-2025-22825 |
Patchstack | |
| 7.1 High | My auctions allegro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.6.18 Fixed in 3.6.19 |
CVE-2025-22733 |
Patchstack | |
| 6.5 Medium | Ad Blocking Detector | Cross-Site Scripting |
≤ 3.6.0 |
CVE-2025-22732 |
Patchstack | |
| 6.5 Medium | MailChimp Subscribe Forms | Cross-Site Scripting |
≤ 4.1 Fixed in 4.2 |
CVE-2025-22727 |
Patchstack | |
| 9.1 Critical | Barcode Scanner with Inventory & Order Manager | Arbitrary File Upload |
≤ 1.6.7 Fixed in 1.7.0 |
CVE-2025-22723 |
Patchstack | |
| 7.1 High | VikAppointments Services Booking Calendar | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.16 Fixed in 1.2.17 |
CVE-2025-22719 |
Patchstack | |
| 6.5 Medium | FAT Event Lite | Cross-Site Scripting |
≤ 1.1 |
CVE-2025-22718 |
Patchstack | |
| 7.5 High | My Tickets | Broken Access Control No login needed |
≤ 2.0.9 Fixed in 2.0.10 |
CVE-2025-22717 |
Patchstack | |
| 8.5 High | Taskbuilder | SQL Injection |
≤ 3.0.6 Fixed in 3.0.7 |
CVE-2025-22716 |
Patchstack | |
| 7.1 High | Image Source Control | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.29.0 Fixed in 2.29.1 |
CVE-2025-22711 |
Patchstack | |
| 7.6 High | Smart Manager | SQL Injection |
≤ 8.52.0 Fixed in 8.53.0 |
CVE-2025-22710 |
Patchstack | |
| 7.1 High | Verge3D | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.8.0 Fixed in 4.8.1 |
CVE-2025-22709 |
Patchstack | |
| 7.1 High | Social Pug: Author Box | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-22706 |
Patchstack | |
| 5.9 Medium | Bonjour Bar | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-22262 |
Patchstack | |
| 9.8 Critical | Easy Real Estate | Privilege Escalation No login needed |
≤ 2.2.9 Fixed in 2.3.0 |
CVE-2024-32555 |
Patchstack | |
| 7.1 High | Brizy Pro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.1 |
CVE-2025-22763 |
Patchstack | |
| 7.1 High | WordPress Tag Cloud Plugin – Tag Groups | Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2025-22735 |
Patchstack | |
| 9.3 Critical | Multiple Carousel | SQL Injection No login needed |
≤ 2.0 |
CVE-2025-22553 |
Patchstack | |
| 7.1 High | Private Messages for UserPro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.10.0 |
CVE-2025-22322 |
Patchstack | |
| 7.5 High | Standard Box Sizes – for WooCommerce | Broken Access Control No login needed |
≤ 1.6.13 Fixed in 1.6.14 |
CVE-2025-22318 |
Patchstack | |
| 7.5 High | Private Messages for UserPro | Local File Inclusion No login needed |
≤ 4.10.0 |
CVE-2025-22311 |
Patchstack | |
| 5.3 Medium | Poll Maker | Content Injection HTML Injection No login needed |
≤ 5.5.5 Fixed in 5.5.5 |
CVE-2024-56277 |
Patchstack | |
| 9.0 Critical | Fancy Product Designer | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 6.4.3 Fixed in 6.4.4 |
CVE-2024-51919 |
Patchstack | |
| 9.8 Critical | Homey Login Register | Privilege Escalation No login needed |
≤ 2.4.0 |
CVE-2024-51888 |
Patchstack | |
| 9.3 Critical | Fancy Product Designer | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.4.3 Fixed in 6.4.4 |
CVE-2024-51818 |
Patchstack | |
| 7.1 High | ARPrice | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49700 |
Patchstack | |
| 8.8 High | ARPrice | PHP Object Injection |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49699 |
Patchstack | |
| 9.8 Critical | ARPrice | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49688 |
Patchstack | |
| 8.5 High | ARPrice | SQL Injection |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49666 |
Patchstack | |
| 9.3 Critical | ARPrice | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 4.1.3 Fixed in 4.2 |
CVE-2024-49655 |
Patchstack | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49333 |
Patchstack | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49303 |
Patchstack | |
| 7.1 High | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-49300 |
Patchstack | |
| 6.1 Medium | wp-greet | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 6.2 |
CVE-2024-13444 |
Wordfence | |
| 5.3 Medium | Social Share, Social Login and Social Comments Plugin – Super Socializer | SQL Injection Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' No login needed |
≤ 7.14 |
CVE-2024-13230 |
Wordfence | |
| 6.4 Medium | FireCask Like & Share Button | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 1.2 |
CVE-2024-11226 |
Wordfence | |
| 6.4 Medium | Betheme | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS |
≤ 27.6.1 |
CVE-2025-0450 |
Wordfence | |
| 6.1 Medium | Link Library | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.7.2 |
CVE-2024-13404 |
Wordfence | |
| 5.3 Medium | Visual Website Collaboration, Feedback & Project Management – Atarim | Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed |
≤ 4.0.9 |
CVE-2024-12104 |
Wordfence | |
| 6.1 Medium | WP-BibTeX | Cross-Site Request Forgery Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting No login needed |
≤ 3.0.1 |
CVE-2024-12005 |
Wordfence | |
| 6.4 Medium | Jet Elements | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.7.2.1 |
CVE-2025-0371 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.