WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 404 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium PixelYourSite Plugin pixelyoursite Cross-Site Request Forgery Cross-Site Request Forgery to GDPR Options Modification No login needed ≤ 11.1.2 CVE-2025-10588 Wordfence
5.3 Medium Login with YourMembership - YM SSO Login Plugin login-with-yourmembership Broken Access Control YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes' No login needed ≤ 1.1.7 CVE-2025-10648 Wordfence
6.4 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field ≤ 1.0.16 CVE-2025-9204 Wordfence
7.5 High Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin yournewsapp SQL Injection Your native, mobile iPhone App and Android App <= 0.8.8.8 - Unauthenticated SQL Injection No login needed ≤ 0.8.8.8 CVE-2025-9200 Wordfence
6.4 Medium Yoast SEO Premium Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting 25.7 – 25.9 CVE-2025-11241 Wordfence
6.4 Medium Yoga Schedule Momoyoga Plugin momoyoga-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 CVE-2025-9852 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
5.4 Medium payOS Plugin payos Cross-Site Request Forgery No login needed ≤ 1.0.73 CVE-2025-57946 Patchstack
4.3 Medium Interact: Embed A Quiz On Your Site Plugin interact-quiz-embed Cross-Site Request Forgery No login needed ≤ 3.1 Fixed in 3.2 CVE-2025-58675 Patchstack
9.8 Critical BeyondCart Connector Plugin beyondcart Privilege Escalation Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter No login needed ≤ 3.0.1 CVE-2025-8570 Wordfence
6.5 Medium CatFolders – Tame Your WordPress Media Library by Category Plugin catfolders SQL Injection Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Injection via CSV Import ≤ 2.5.2 CVE-2025-9776 Wordfence
7.1 High Auto Last Youtube Video Plugin auto-last-youtube-video Cross-Site Request Forgery No login needed ≤ 1.0.7 CVE-2025-58843 Patchstack
4.3 Medium Payoneer Checkout Plugin payoneer-checkout Content Injection Content Spoofing No login needed ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-58795 Patchstack
8.1 High YouTube Showcase Plugin youtube-showcase PHP Object Injection No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-54731 Patchstack
7.1 High ATT YouTube Widget Plugin att-youtube Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48359 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
7.1 High Savyour Affiliate Partner Plugin savyour-affiliate-partner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.4 CVE-2025-48306 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-48154 Patchstack
7.1 High Youtube Vimeo Video Player and Slider WP Plugin video-player-youtube-vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-48159 Patchstack
7.1 High Youtube Vimeo Video Player and Slider Plugin video_player_youtube_vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-53563 Patchstack
8.8 High Soledad Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'header_layout' ≤ 8.6.7 CVE-2025-8142 Wordfence
6.5 Medium Masteriyo - LMS Plugin learning-management-system Cross-Site Scripting LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) ≤ 1.18.3 Fixed in 1.18.4 CVE-2025-54699 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-30626 Patchstack
6.5 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30993 Patchstack
7.2 High Use-your-Drive | Google Drive Plugin Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed ≤ 3.3.1 CVE-2025-7050 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.1.0 CVE-2025-7725 Wordfence
6.4 Medium Appzend Theme appzend Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.2.6 CVE-2025-5587 Wordfence
6.4 Medium YouTube Embed Plugin youram-youtube-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via instance Parameter ≤ 10.3 CVE-2025-6692 Wordfence
6.4 Medium StreamWeasels YouTube Integration Plugin streamweasels-youtube-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.0 CVE-2025-7811 Wordfence
9.8 Critical ONLYOFFICE Docs Plugin onlyoffice Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via callback Function No login needed 1.1.0 – 2.2.0 CVE-2025-6380 Wordfence
6.4 Medium Get Youtube Subs Plugin get-youtube-subs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via subscribe_link_att Function ≤ 3.5 CVE-2025-7966 Wordfence
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
8.8 High Yogi Plugin yogi PHP Object Injection ≤ 2.9.3 Fixed in 2.9.3 CVE-2025-24779 Patchstack
6.5 Medium Profiler - What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed ≤ 1.0.0 CVE-2025-48339 Patchstack
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
9.3 Critical bSecure – Your Universal Checkout Plugin bsecure SQL Injection Your Universal Checkout plugin <= 1.7.9 - SQL Injection No login needed ≤ 1.7.9 CVE-2025-52830 Patchstack
4.3 Medium WP YouTube Live Plugin wp-youtube-live Cross-Site Request Forgery No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-53261 Patchstack
7.1 High Bulk YouTube Post Creator Plugin bulk-youtube-post-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-49423 Patchstack
7.5 High Import YouTube videos as WP Posts Plugin import-youtube-videos-as-wp-post Broken Access Control No login needed ≤ 2.1 CVE-2025-52802 Patchstack
6.4 Medium kk Youtube Video Plugin kk-youtube-video Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2 CVE-2025-6061 Wordfence
4.3 Medium Yougler Blogger Profile Page Plugin yougler-blogger-profile-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ v1.01 CVE-2025-6062 Wordfence
5.3 Medium Profiler – What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Missing Authentication to Unauthenticated Arbitrary Plugin Reactivation via State Restoration No login needed ≤ 1.0.0 CVE-2025-5814 Wordfence
6.5 Medium YouTube Simple Gallery Plugin youtube-simple-gallery Cross-Site Scripting ≤ 2.2.0 CVE-2025-29011 Patchstack
4.3 Medium Layouts for Elementor Plugin layouts-for-elementor Cross-Site Request Forgery No login needed ≤ 1.11 CVE-2025-30948 Patchstack
8.1 High Yozi Theme yozi Local File Inclusion No login needed ≤ 2.0.63 Fixed in 2.0.66.1 CVE-2025-32289 Patchstack
7.1 High Tayori Form Plugin tayori Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 CVE-2025-46437 Patchstack
6.4 Medium WP YouTube Video Optimizer Plugin wp-youtube-video-optimizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2025-4217 Wordfence
5.3 Medium Masteriyo - LMS Plugin learning-management-system Authentication Bypass Broken Authentication No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-33939 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only