WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 151–200 of 404 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | PixelYourSite | Cross-Site Request Forgery Cross-Site Request Forgery to GDPR Options Modification No login needed |
≤ 11.1.2 |
CVE-2025-10588 |
Wordfence | |
| 5.3 Medium | Login with YourMembership - YM SSO Login | Broken Access Control YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes' No login needed |
≤ 1.1.7 |
CVE-2025-10648 |
Wordfence | |
| 6.4 Medium | X Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field |
≤ 1.0.16 |
CVE-2025-9204 |
Wordfence | |
| 7.5 High | Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App | SQL Injection Your native, mobile iPhone App and Android App <= 0.8.8.8 - Unauthenticated SQL Injection No login needed |
≤ 0.8.8.8 |
CVE-2025-9200 |
Wordfence | |
| 6.4 Medium | Yoast SEO Premium | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
25.7 – 25.9 |
CVE-2025-11241 |
Wordfence | |
| 6.4 Medium | Yoga Schedule Momoyoga | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.9.0 |
CVE-2025-9852 |
Wordfence | |
| 4.3 Medium | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed |
≤ 3.12.0 |
CVE-2025-10498 |
Wordfence | |
| 4.3 Medium | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 3.12.0 |
CVE-2025-10499 |
Wordfence | |
| 7.1 High | Conditional Cart Messages for WooCommerce – YourPlugins.com | Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.10 |
CVE-2025-60171 |
Patchstack | |
| 5.4 Medium | payOS | Cross-Site Request Forgery No login needed |
≤ 1.0.73 |
CVE-2025-57946 |
Patchstack | |
| 4.3 Medium | Interact: Embed A Quiz On Your Site | Cross-Site Request Forgery No login needed |
≤ 3.1 Fixed in 3.2 |
CVE-2025-58675 |
Patchstack | |
| 9.8 Critical | BeyondCart Connector | Privilege Escalation Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter No login needed |
≤ 3.0.1 |
CVE-2025-8570 |
Wordfence | |
| 6.5 Medium | CatFolders – Tame Your WordPress Media Library by Category | SQL Injection Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Injection via CSV Import |
≤ 2.5.2 |
CVE-2025-9776 |
Wordfence | |
| 7.1 High | Auto Last Youtube Video | Cross-Site Request Forgery No login needed |
≤ 1.0.7 |
CVE-2025-58843 |
Patchstack | |
| 4.3 Medium | Payoneer Checkout | Content Injection Content Spoofing No login needed |
≤ 3.4.0 Fixed in 3.5.0 |
CVE-2025-58795 |
Patchstack | |
| 8.1 High | YouTube Showcase | PHP Object Injection No login needed |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2025-54731 |
Patchstack | |
| 7.1 High | ATT YouTube Widget | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.0 |
CVE-2025-48359 |
Patchstack | |
| 6.5 Medium | Video Gallery – Vimeo and YouTube Gallery | Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2025-48349 |
Patchstack | |
| 7.1 High | Savyour Affiliate Partner | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1.4 |
CVE-2025-48306 |
Patchstack | |
| 7.1 High | Multimedia Playlist Slider Addon for WPBakery Page Builder | Cross-Site Scripting No login needed |
≤ 2.1 Fixed in 2.2 |
CVE-2025-48154 |
Patchstack | |
| 7.1 High | Youtube Vimeo Video Player and Slider WP | Cross-Site Scripting No login needed |
≤ 3.8 Fixed in 3.9 |
CVE-2025-48159 |
Patchstack | |
| 7.1 High | Youtube Vimeo Video Player and Slider | Cross-Site Scripting No login needed |
≤ 3.8 Fixed in 3.9 |
CVE-2025-53563 |
Patchstack | |
| 8.8 High | Soledad | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'header_layout' |
≤ 8.6.7 |
CVE-2025-8142 |
Wordfence | |
| 6.5 Medium | Masteriyo - LMS | Cross-Site Scripting LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) |
≤ 1.18.3 Fixed in 1.18.4 |
CVE-2025-54699 |
Patchstack | |
| 7.1 High | Multimedia Playlist Slider Addon for WPBakery Page Builder | Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2025-30626 |
Patchstack | |
| 6.5 Medium | Thank You Page Customizer for WooCommerce | Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-30993 |
Patchstack | |
| 7.2 High | Use-your-Drive | Google Drive | Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed |
≤ 3.3.1 |
CVE-2025-7050 |
Wordfence | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.1.0 |
CVE-2025-7725 |
Wordfence | |
| 6.4 Medium | Appzend | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter |
≤ 1.2.6 |
CVE-2025-5587 |
Wordfence | |
| 6.4 Medium | YouTube Embed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via instance Parameter |
≤ 10.3 |
CVE-2025-6692 |
Wordfence | |
| 6.4 Medium | StreamWeasels YouTube Integration | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.0 |
CVE-2025-7811 |
Wordfence | |
| 9.8 Critical | ONLYOFFICE Docs | Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via callback Function No login needed |
1.1.0 – 2.2.0 |
CVE-2025-6380 |
Wordfence | |
| 6.4 Medium | Get Youtube Subs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via subscribe_link_att Function |
≤ 3.5 |
CVE-2025-7966 |
Wordfence | |
| 6.4 Medium | Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery | Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.7 |
CVE-2025-7644 |
Wordfence | |
| 8.8 High | Yogi | PHP Object Injection |
≤ 2.9.3 Fixed in 2.9.3 |
CVE-2025-24779 |
Patchstack | |
| 6.5 Medium | Profiler - What Slowing Down Your WP | Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed |
≤ 1.0.0 |
CVE-2025-48339 |
Patchstack | |
| 4.3 Medium | Real Estate Property 2024 Create Your Own Fields and Search Bar WP | Broken Access Control |
≤ 4.48 Fixed in 4.49 |
CVE-2025-48150 |
Patchstack | |
| 9.3 Critical | bSecure – Your Universal Checkout | SQL Injection Your Universal Checkout plugin <= 1.7.9 - SQL Injection No login needed |
≤ 1.7.9 |
CVE-2025-52830 |
Patchstack | |
| 4.3 Medium | WP YouTube Live | Cross-Site Request Forgery No login needed |
≤ 1.10.0 Fixed in 1.10.1 |
CVE-2025-53261 |
Patchstack | |
| 7.1 High | Bulk YouTube Post Creator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-49423 |
Patchstack | |
| 7.5 High | Import YouTube videos as WP Posts | Broken Access Control No login needed |
≤ 2.1 |
CVE-2025-52802 |
Patchstack | |
| 6.4 Medium | kk Youtube Video | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.2 |
CVE-2025-6061 |
Wordfence | |
| 4.3 Medium | Yougler Blogger Profile Page | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ v1.01 |
CVE-2025-6062 |
Wordfence | |
| 5.3 Medium | Profiler – What Slowing Down Your WP | Broken Access Control What Slowing Down Your WP <= 1.0.0 - Missing Authentication to Unauthenticated Arbitrary Plugin Reactivation via State Restoration No login needed |
≤ 1.0.0 |
CVE-2025-5814 |
Wordfence | |
| 6.5 Medium | YouTube Simple Gallery | Cross-Site Scripting |
≤ 2.2.0 |
CVE-2025-29011 |
Patchstack | |
| 4.3 Medium | Layouts for Elementor | Cross-Site Request Forgery No login needed |
≤ 1.11 |
CVE-2025-30948 |
Patchstack | |
| 8.1 High | Yozi | Local File Inclusion No login needed |
≤ 2.0.63 Fixed in 2.0.66.1 |
CVE-2025-32289 |
Patchstack | |
| 7.1 High | Tayori Form | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.9 |
CVE-2025-46437 |
Patchstack | |
| 6.4 Medium | WP YouTube Video Optimizer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2 |
CVE-2025-4217 |
Wordfence | |
| 5.3 Medium | Masteriyo - LMS | Authentication Bypass Broken Authentication No login needed |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2024-33939 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.