WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 151–200 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 7
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg_radio_player_addon_visual_composer Cross-Site Scripting WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.5.2 CVE-2025-53564 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.11.1 Fixed in 3.12.0 CVE-2025-54750 Patchstack
7.5 High JS Archive List Plugin jquery-archive-list-widget SQL Injection Unauthenticated SQL Injection via build_sql_where Function No login needed ≤ 6.1.5 CVE-2025-7670 Wordfence
7.1 High WooCommerce Shop Page Builder Plugin dzs-wootable Cross-Site Scripting No login needed ≤ 2.27.7 CVE-2025-28999 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-30626 Patchstack
7.5 High Bricks Builder Theme SQL Injection Unauthenticated SQL Injection via `p` Parameter No login needed ≤ 1.12.4 CVE-2025-6495 Wordfence
7.5 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg-cleverbakery Path Traversal WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download No login needed ≤ 2.5 Fixed in 2.5.3 CVE-2025-31070 Patchstack
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.10.2 Fixed in 3.11.0 CVE-2025-49034 Patchstack
7.2 High JetFormBuilder Plugin jetformbuilder PHP Object Injection ≤ 3.5.1.2 Fixed in 3.5.2 CVE-2025-53990 Patchstack
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms PHP Object Injection Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6742 Wordfence
8.1 High SureForms – Drag and Drop Form Builder Plugin sureforms Arbitrary File Deletion Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6691 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator PHP Object Injection Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6464 Wordfence
8.8 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Arbitrary File Deletion Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6463 Wordfence
7.2 High Ninja Tables – Easy Data Table Builder Plugin ninja-tables Server-Side Request Forgery Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery No login needed ≤ 5.0.18 CVE-2025-2940 Wordfence
7.2 High Beaver Builder Plugin (Starter Version) Plugin Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.9.1 CVE-2025-4102 Wordfence
7.1 High eForm - WordPress Form Builder Plugin wp-fsqm-pro Cross-Site Scripting WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) No login needed ≤ 4.19.1 Fixed in 4.19.1 CVE-2025-48333 Patchstack
7.6 High Team Builder Plugin a-team-showcase Broken Access Control ≤ 1.5.7 CVE-2025-32308 Patchstack
8.8 High Offsprout Page Builder Plugin offsprout-page-builder Privilege Escalation Authenticated (Contributor+) Privilege Escalation via permission_callback Function 2.2.1 – 2.15.2 CVE-2025-4672 Wordfence
7.1 High Visual Builder Plugin visual-builder Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-46488 Patchstack
8.8 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.1 Fixed in 3.2 CVE-2025-47690 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-39449 Patchstack
7.2 High Taskbuilder Plugin taskbuilder SQL Injection Admin+ SQL Injection < 3.0.9 Fixed in 3.0.9 CVE-2024-9831 WPScan
8.8 High WordPress Review Plugin: The Ultimate Solution for Building a Review Website Plugin wp-review Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Custom Fields ≤ 5.3.5 CVE-2025-2158 Wordfence
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
7.5 High Slider & Popup Builder by Depicter Plugin depicter SQL Injection Unauthenticated SQL Injection via 's' Parameter No login needed ≤ 3.6.1 CVE-2025-2011 Wordfence
8.8 High BM Content Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.16.2.1 CVE-2025-1279 Wordfence
7.5 High Popup Builder Plugin easy-notify-lite Local File Inclusion ≤ 1.1.35 Fixed in 1.1.37 CVE-2025-46230 Patchstack
8.8 High Greenshift Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload 11.4 – 11.4.5 CVE-2025-3616 Wordfence
7.1 High Rebuild Permalinks Plugin rebuild-permalinks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-27346 Patchstack
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-39569 Patchstack
7.1 High WP Table Builder Plugin wp-table-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-32598 Patchstack
7.6 High Easy Query – WP Query Builder Plugin easy-query SQL Injection WP Query Builder plugin <= 2.0.4 - SQL Injection ≤ 2.0.4 CVE-2025-32120 Patchstack
8.1 High Countdown, Coming Soon, Maintenance – Countdown & Clock Plugin countdown-builder Local File Inclusion Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion No login needed ≤ 2.8.9.1 CVE-2025-2270 Wordfence
7.1 High Team Builder Plugin team-display Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-31907 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Local File Inclusion ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-31016 Patchstack
8.5 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm SQL Injection ≤ 3.0.1 Fixed in 3.1 CVE-2025-30810 Patchstack
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
7.1 High Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26994 Patchstack
7.1 High Zigaform Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26989 Patchstack
8.8 High SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile ≤ 1.12.17 CVE-2024-12544 Wordfence
7.1 High Bricksbuilder Theme Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave ≤ 1.9.6.1 CVE-2024-2297 Wordfence
7.1 High Custom Block Builder – Lazy Blocks Plugin lazy-blocks Cross-Site Scripting Lazy Blocks < 3.8.3 - Reflected XSS No login needed < 3.8.3 Fixed in 3.8.3 CVE-2024-12878 WPScan
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2025-26979 Patchstack
7.1 High Responsive Modal Builder for High Conversion – Easy Popups Plugin easy-popups Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-26774 Patchstack
7.5 High Calculator Builder Plugin calculator-builder Local File Inclusion No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-26760 Patchstack
7.5 High Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2024-13592 Wordfence
7.2 High FormCraft - Premium WordPress Form Builder Plugin Cross-Site Scripting Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.9.11 CVE-2025-0817 Wordfence
7.1 High Uix Page Builder Plugin uix-page-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.5 CVE-2025-24616 Patchstack
7.1 High Scroll Top Plugin scroll-to-top-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23651 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only