WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 345 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-30639 Patchstack
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure No login needed ≤ 4.6.0 CVE-2025-8620 Wordfence
6.5 Medium IDonate Plugin idonate Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function 2.0.0 – 2.1.9 CVE-2025-4523 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting ≤ 4.5.0 CVE-2025-7205 Wordfence
4.3 Medium Bonanza – WooCommerce Free Gifts Lite Plugin bonanza-woocommerce-free-gifts-lite Broken Access Control WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Opt In Success ≤ 1.0.0 CVE-2025-6730 Wordfence
8.1 High Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) Plugin extensions-for-cf7 Arbitrary File Deletion Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission Deletion No login needed ≤ 3.2.8 CVE-2025-7645 Wordfence
7.1 High Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.22 Fixed in 1.23 CVE-2025-53271 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting No login needed ≤ 2.12.5.2 CVE-2025-52778 Patchstack
8.1 High National Weather Service Alerts Plugin national-weather-service-alerts Local File Inclusion No login needed ≤ 1.3.5 CVE-2025-52809 Patchstack
6.4 Medium WP-PhotoNav Plugin wp-photonav Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via photonav Shortcode ≤ 1.2.2 CVE-2025-6383 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification ≤ 4.3.0 CVE-2025-4571 Wordfence
4.7 Medium FunnelKit Automations Plugin wp-marketing-automations Open Redirect No login needed ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-49868 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting ≤ 1.9.3.1 Fixed in 1.9.3.2 CVE-2025-49875 Patchstack
7.1 High Konami Easter Egg Plugin konami-easter-egg Cross-Site Request Forgery No login needed ≤ v0.4 CVE-2025-49425 Patchstack
5.3 Medium Interactive Regional Map of Florida Plugin interactive-map-of-florida Broken Access Control No login needed ≤ 1.0 CVE-2025-49441 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
7.1 High Personal Favicon Plugin personal-favicon Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28964 Patchstack
6.4 Medium Bold Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via additional_settings Parameter ≤ 5.3.6 CVE-2025-5286 Wordfence
6.4 Medium Raisely Donation Form Plugin raisely-donation-form Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via raisely_donation_form Shortcode ≤ 1.1 CVE-2025-3781 Wordfence
7.1 High Total Donations Plugin total-donations Cross-Site Scripting No login needed ≤ 3.0.8 CVE-2025-43837 Patchstack
5.3 Medium Rootspersona Plugin rootspersona Broken Access Control No login needed ≤ 3.7.5 CVE-2025-39368 Patchstack
5.4 Medium Rootspersona Plugin rootspersona Cross-Site Request Forgery No login needed ≤ 3.7.5 CVE-2025-48344 Patchstack
6.5 Medium Additional Custom Emails & Recipients for WooCommerce Plugin custom-emails-for-woocommerce Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-48251 Patchstack
5.4 Medium If-So Dynamic Content Personalization Plugin Cross-Site Scripting Contributor+ Shortcode Stored XSS < 1.8.0.3 Fixed in 1.8.0.3 CVE-2024-5440 WPScan
7.1 High Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2025-47517 Patchstack
4.3 Medium FundEngine Plugin wp-fundraising-donation Cross-Site Request Forgery No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-47459 Patchstack
5.9 Medium COVID-19 (Coronavirus) Update Your Customers Plugin covid-19-alert Cross-Site Scripting ≤ 1.5.1 CVE-2025-46523 Patchstack
7.1 High WP Donate Plugin wp-donate Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-32637 Patchstack
6.5 Medium Conditional Payments for WooCommerce Plugin conditional-payments-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-39563 Patchstack
6.5 Medium Conditional Shipping for WooCommerce Plugin conditional-shipping-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-39564 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-26749 Patchstack
8.1 High IDonate Plugin idonate Local File Inclusion No login needed ≤ 2.1.18 CVE-2025-32519 Patchstack
6.4 Medium Link Library Plugin link-library Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Link Additional Parameters ≤ 7.7.3 CVE-2025-2889 Wordfence
4.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar plugin <= 5.9.4 - Broken Access Control ≤ 5.9.4 Fixed in 5.9.5 CVE-2025-32235 Patchstack
6.5 Medium Donate Me Plugin donate-me Cross-Site Scripting Stored Cross-Site Scripting ≤ 1.2.5 CVE-2025-31778 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.5 Fixed in 2.12.5.1 CVE-2025-30840 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
5.9 Medium Paytm Payment Donation Plugin paytm-donation Cross-Site Scripting ≤ 2.3.3 CVE-2025-22640 Patchstack
4.7 Medium FunnelKit Automations Plugin wp-marketing-automations Open Redirect No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-30795 Patchstack
7.2 High WP Church Donation Plugin wp-church-donation Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.7 CVE-2024-13690 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure No login needed ≤ 3.22.1 CVE-2025-2331 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
4.8 Medium Coronavirus (COVID-19) Notice Message Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.1.2 CVE-2025-0629 WPScan
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
9.8 Critical HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.6.5 CVE-2025-1661 Wordfence
5.3 Medium Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More Plugin content-control Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.5.0 CVE-2024-11153 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.4 CVE-2025-0912 Wordfence
7.1 High 4 author cheer up donate Plugin 4-author-cheer-up-donate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23670 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only