WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 425 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Flytedesk Digital Plugin flytedesk-digital Cross-Site Request Forgery No login needed ≤ 20181101 CVE-2025-60172 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High HTACCESS IP Blocker Plugin htaccess-ip-blocker Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-60170 Patchstack
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
7.1 High NewsmanApp Plugin newsmanapp Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 3.0.0 CVE-2025-60164 Patchstack
8.8 High Javo Core Plugin javo-core Cross-Site Request Forgery No login needed ≤ 3.0.0.266 CVE-2025-60111 Patchstack
7.1 High WP Attractive Donations System Plugin wp-attractive-donations-system-easy-stripe-paypal-donations Cross-Site Request Forgery No login needed ≤ 1.29 Fixed in 1.29 CVE-2025-58956 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery No login needed ≤ 1.7.06 Fixed in 1.7.06 CVE-2025-59572 Patchstack
7.1 High LinkedInclude Plugin linkedinclude Cross-Site Request Forgery No login needed ≤ 3.0.4 CVE-2025-57918 Patchstack
7.1 High Flexible PDF Invoices for WooCommerce & Plugin flexible-invoices Cross-Site Request Forgery No login needed ≤ 6.0.13 Fixed in 6.0.14 CVE-2025-57977 Patchstack
8.8 High CouponXxL Plugin couponxxl Cross-Site Request Forgery No login needed ≤ 4.5.0 CVE-2025-58013 Patchstack
8.8 High Constructo Plugin constructo Cross-Site Request Forgery No login needed ≤ 4.3.9 CVE-2025-58244 Patchstack
8.8 High Findgo Plugin fingo Cross-Site Request Forgery No login needed ≤ 1.3.55 Fixed in 1.3.60.1 CVE-2025-58250 Patchstack
7.1 High Nokri Theme nokri Cross-Site Request Forgery No login needed ≤ 1.6.4 CVE-2025-58259 Patchstack
7.1 High Mavis HTTPS to HTTP Redirection Plugin mavis-https-to-http-redirect Cross-Site Request Forgery No login needed ≤ 1.4.3 CVE-2025-58261 Patchstack
7.1 High Sweet Energy Efficiency Plugin sweet-energy-efficiency Cross-Site Request Forgery No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-58262 Patchstack
7.1 High WPMK PDF Generator Plugin wpmk-pdf-generator Cross-Site Request Forgery No login needed ≤ 1.0.1 CVE-2025-58268 Patchstack
7.1 High Stock Message Plugin stock-message Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-58267 Patchstack
7.1 High NIX Anti-Spam Light Plugin nix-anti-spam-light Cross-Site Request Forgery No login needed ≤ 0.0.4 CVE-2025-58270 Patchstack
7.1 High Grid Plugin grid Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-58657 Patchstack
7.1 High Auction Feed Plugin auction-feed Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-58671 Patchstack
7.1 High WP Content Protection Plugin wp-content-protection Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-58670 Patchstack
7.1 High HORIZONTAL SLIDER Plugin horizontal-slider Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-58676 Patchstack
7.1 High ShrinkTheWeb (STW) Website Previews Plugin shrinktheweb-website-preview-plugin Cross-Site Request Forgery No login needed ≤ 2.8.5 CVE-2025-58677 Patchstack
7.1 High Current Age Plugin current-age Cross-Site Request Forgery No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-58687 Patchstack
7.1 High Casengo Live Chat Support Plugin the-casengo-chat-widget Cross-Site Request Forgery No login needed ≤ 2.1.4 CVE-2025-58688 Patchstack
7.1 High Doliconnect Plugin doliconnect Cross-Site Request Forgery No login needed ≤ 9.5.7 Fixed in 9.6.2 CVE-2025-58690 Patchstack
7.1 High WooCommerce Booking Bundle Hours Plugin woo-booking-bundle-hours Cross-Site Request Forgery No login needed ≤ 0.7.4 Fixed in 0.7.5 CVE-2025-58991 Patchstack
7.2 High Ultimate Video Player Plugin fwduvp Server-Side Request Forgery No login needed ≤ 10.1 CVE-2025-49430 Patchstack
7.1 High Floating Window Music Player Plugin floating-window-music-player Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.4.2 CVE-2025-48104 Patchstack
7.1 High Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-58861 Patchstack
7.1 High Enable Latex Plugin enable-latex Cross-Site Request Forgery No login needed ≤ 1.2.16 CVE-2025-58860 Patchstack
7.1 High Add to Feedly Plugin add-to-feedly Cross-Site Request Forgery No login needed ≤ 1.2.11 CVE-2025-58859 Patchstack
7.1 High Table of content Plugin content-table Cross-Site Request Forgery No login needed ≤ 1.5.3.1 CVE-2025-58857 Patchstack
7.1 High AP HoneyPot Plugin ap-honeypot Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-58855 Patchstack
7.1 High Ultimate AJAX Login Plugin ultimate-ajax-login Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-58854 Patchstack
7.1 High Popping Sidebars and Widgets Light Plugin popping-sidebars-and-widgets-light Cross-Site Request Forgery No login needed ≤ 1.27 CVE-2025-58853 Patchstack
7.1 High MSTW League Manager Plugin mstw-league-manager Cross-Site Request Forgery No login needed ≤ 2.10 CVE-2025-58852 Patchstack
7.1 High Hide Real Download Path Plugin hide-real-download-path Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58849 Patchstack
7.1 High WP likes Plugin wp-likes Cross-Site Request Forgery No login needed ≤ 3.1.1 CVE-2025-58848 Patchstack
7.1 High WN Flipbox Pro Plugin wn-flipbox-pro Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-58847 Patchstack
7.1 High WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule Plugin buffer-my-post Cross-Site Request Forgery HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule Plugin <= 2020.1.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2020.1.0 CVE-2025-58846 Patchstack
7.1 High Bulk Watermark Plugin bulk-watermark Cross-Site Request Forgery No login needed ≤ 1.6.10 CVE-2025-58845 Patchstack
7.1 High Database to Excel Plugin database-to-excel Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-58844 Patchstack
7.1 High Auto Last Youtube Video Plugin auto-last-youtube-video Cross-Site Request Forgery No login needed ≤ 1.0.7 CVE-2025-58843 Patchstack
8.8 High Invelity MyGLS connect Plugin invelity-mygls-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-58833 Patchstack
7.1 High To Lead For Salesforce Plugin salesforce-wordpress-to-lead Cross-Site Request Forgery No login needed ≤ 2.7.3.9 CVE-2025-58809 Patchstack
7.1 High Purge Varnish Cache Plugin purge-varnish Cross-Site Request Forgery No login needed ≤ 2.6 CVE-2025-58807 Patchstack
7.1 High WordPress Error Monitoring by Bugsnag Plugin bugsnag Cross-Site Request Forgery No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-58806 Patchstack
7.1 High ATT YouTube Widget Plugin att-youtube Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48359 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only