WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 355 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Events Manager Plugin wp-events-manager Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-57987 Patchstack
5.4 Medium Upcoming Events Lists Plugin upcoming-events-lists Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.0 CVE-2025-57994 Patchstack
6.5 Medium Events Manager – OpenStreetMaps Plugin stonehenge-em-osm Cross-Site Scripting OpenStreetMaps Plugin <= 4.2.1 - Cross Site Scripting (XSS) ≤ 4.2.1 CVE-2025-58265 Patchstack
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Unauthenticated Password-Protected Information Disclosure No login needed ≤ 6.15.2 CVE-2025-9808 Wordfence
6.4 Medium Digital Events Calendar Plugin digital-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via column Parameter ≤ 1.0.8 CVE-2025-5801 Wordfence
6.4 Medium Certifica WP Plugin certifica-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via evento Parameter ≤ 3.1 CVE-2025-8316 Wordfence
6.5 Medium WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Scripting connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 CVE-2025-58862 Patchstack
6.5 Medium Event Feed for Eventbrite Plugin event-feed-for-eventbrite Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-58623 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery No login needed ≤ 3.5.5.6 Fixed in 3.5.5.8 CVE-2025-58611 Patchstack
6.4 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter and Countdown Widgets ≤ 2.2.9 CVE-2025-8150 Wordfence
6.5 Medium Prevent files / folders access Plugin prevent-file-access Path Traversal ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-53561 Patchstack
4.3 Medium EventON Lite Plugin eventon-lite Information Disclosure Authenticated (Contributor+) Information Disclosure ≤ 2.4.7 CVE-2025-8091 Wordfence
4.3 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 4.4.6 Fixed in 4.4.7 CVE-2025-54705 Patchstack
6.5 Medium Eventer Plugin eventer Content Injection No login needed ≤ 3.9.9.1 Fixed in 3.9.9.1 CVE-2025-39483 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
4.4 Medium WP Event Manager Plugin wp-event-manager Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.1.49 CVE-2025-2799 Wordfence
5.9 Medium Modern Events Calendar Lite Plugin modern-events-calendar-lite SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.3.0 CVE-2021-4458 Wordfence
6.4 Medium Events Manager Plugin events-manager Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6976 Wordfence
6.1 Medium Event Manager Plugin events-manager Cross-Site Scripting Reflected Cross-Site Scripting via `calendar_header` Parameter No login needed ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6975 Wordfence
6.3 Medium EventON Plugin eventon Broken Access Control ≤ 4.9.9 CVE-2025-47565 Patchstack
6.4 Medium Event RSVP and Simple Event Management Plugin wp-easy-events Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2025-5540 Wordfence
6.4 Medium IRM Newsroom Plugin irm-newsroom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'irmeventlist' Shortcode ≤ 1.2.19 CVE-2025-4584 Wordfence
6.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.13.2 CVE-2025-5144 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
6.4 Medium WpEvently Plugin mage-eventpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.2 CVE-2025-5568 Wordfence
5.9 Medium Next Event Calendar Plugin next-event-calendar Cross-Site Scripting ≤ 1.2 CVE-2023-26001 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
6.5 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Cross-Site Scripting ≤ 1.4.9 Fixed in 1.4.10 CVE-2025-49311 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.10.1 Fixed in 5.10.2 CVE-2025-49298 Patchstack
5.3 Medium Modern Events Calendar Plugin modern-events-calendar-lite Information Disclosure Information Exposure No login needed ≤ 7.21.9 CVE-2025-5733 Wordfence
6.5 Medium Import Social Events Plugin import-facebook-events Cross-Site Scripting ≤ 1.8.5 Fixed in 1.8.6 CVE-2025-48256 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.11.2.1 Fixed in 6.12.0 CVE-2025-48246 Patchstack
6.4 Medium EventON - WordPress Virtual Event Calendar Plugin Broken Access Control WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.9.6 CVE-2025-3527 Wordfence
4.3 Medium Eventer Plugin eventer Broken Access Control ≤ 3.11.4 Fixed in 3.11.4 CVE-2025-39482 Patchstack
5.3 Medium EventON Plugin eventon Broken Access Control No login needed ≤ 4.9.8 CVE-2025-47564 Patchstack
5.3 Medium EventON Plugin eventon-lite Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-48116 Patchstack
6.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update 3.4.9 – < 3.5.0 Fixed in 3.5.0 CVE-2024-4665 WPScan
4.8 Medium Event Calendar Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.4 CVE-2024-8701 WPScan
4.8 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Admin+ Stored XSS < 6.6.4 Fixed in 6.6.4 CVE-2024-8493 WPScan
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-47519 Patchstack
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Information Disclosure Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.8.8 CVE-2025-3923 Wordfence
5.4 Medium Prevent Direct Access Plugin prevent-direct-access Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Multiple Media Actions 2.8.6 – 2.8.8.2 CVE-2025-3861 Wordfence
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.9.11 Fixed in 5.10.0 CVE-2025-46228 Patchstack
5.3 Medium MyTicket Events Plugin myticket-events Path Traversal Non-Arbitrary File Read No login needed ≤ 1.2.4 CVE-2025-27299 Patchstack
5.3 Medium WP Event Manager Plugin wp-event-manager Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32225 Patchstack
6.5 Medium Simple WP Events Plugin simple-wp-events Cross-Site Scripting ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32193 Patchstack
6.5 Medium Tockify Events Calendar Plugin tockify-events-calendar Cross-Site Scripting ≤ 2.2.13 Fixed in 2.3.0 CVE-2025-32174 Patchstack
6.4 Medium Minimalistic Event Manager Plugin minimalistic-event-manager Broken Access Control ≤ 1.1.1 CVE-2025-31739 Patchstack
6.5 Medium Eventbee RSVP Widget Plugin eventbee-rsvp-widget Cross-Site Scripting ≤ 1.0 CVE-2025-31838 Patchstack
6.5 Medium Timeline Event History Plugin timeline-event-history Cross-Site Scripting ≤ 3.2 CVE-2025-31595 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only