WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 151–200 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Auction Feed Plugin auction-feed Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2025-58671 Patchstack
7.1 High WP Content Protection Plugin wp-content-protection Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-58670 Patchstack
7.1 High HORIZONTAL SLIDER Plugin horizontal-slider Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-58676 Patchstack
7.1 High ShrinkTheWeb (STW) Website Previews Plugin shrinktheweb-website-preview-plugin Cross-Site Request Forgery No login needed ≤ 2.8.5 CVE-2025-58677 Patchstack
8.5 High Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-58686 Patchstack
7.1 High Current Age Plugin current-age Cross-Site Request Forgery No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-58687 Patchstack
7.1 High Casengo Live Chat Support Plugin the-casengo-chat-widget Cross-Site Request Forgery No login needed ≤ 2.1.4 CVE-2025-58688 Patchstack
7.1 High Doliconnect Plugin doliconnect Cross-Site Request Forgery No login needed ≤ 9.5.7 Fixed in 9.6.2 CVE-2025-58690 Patchstack
8.8 High StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More Plugin storeengine Arbitrary File Upload Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.5.0 CVE-2025-9216 Wordfence
7.1 High WooCommerce Booking Bundle Hours Plugin woo-booking-bundle-hours Cross-Site Request Forgery No login needed ≤ 0.7.4 Fixed in 0.7.5 CVE-2025-58991 Patchstack
7.2 High Ultimate Video Player Plugin fwduvp Server-Side Request Forgery No login needed ≤ 10.1 CVE-2025-49430 Patchstack
8.6 High Ditty Plugin ditty-news-ticker Server-Side Request Forgery Unauthenticated SSRF No login needed < 3.1.58 Fixed in 3.1.58 CVE-2025-8085 WPScan
7.1 High Floating Window Music Player Plugin floating-window-music-player Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.4.2 CVE-2025-48104 Patchstack
7.1 High Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-58861 Patchstack
7.1 High Enable Latex Plugin enable-latex Cross-Site Request Forgery No login needed ≤ 1.2.16 CVE-2025-58860 Patchstack
7.1 High Add to Feedly Plugin add-to-feedly Cross-Site Request Forgery No login needed ≤ 1.2.11 CVE-2025-58859 Patchstack
7.1 High Table of content Plugin content-table Cross-Site Request Forgery No login needed ≤ 1.5.3.1 CVE-2025-58857 Patchstack
7.1 High AP HoneyPot Plugin ap-honeypot Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-58855 Patchstack
7.1 High Ultimate AJAX Login Plugin ultimate-ajax-login Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-58854 Patchstack
7.1 High Popping Sidebars and Widgets Light Plugin popping-sidebars-and-widgets-light Cross-Site Request Forgery No login needed ≤ 1.27 CVE-2025-58853 Patchstack
7.1 High MSTW League Manager Plugin mstw-league-manager Cross-Site Request Forgery No login needed ≤ 2.10 CVE-2025-58852 Patchstack
7.1 High Hide Real Download Path Plugin hide-real-download-path Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58849 Patchstack
7.1 High WP likes Plugin wp-likes Cross-Site Request Forgery No login needed ≤ 3.1.1 CVE-2025-58848 Patchstack
7.1 High WN Flipbox Pro Plugin wn-flipbox-pro Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-58847 Patchstack
7.1 High WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule Plugin buffer-my-post Cross-Site Request Forgery HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule Plugin <= 2020.1.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2020.1.0 CVE-2025-58846 Patchstack
7.1 High Bulk Watermark Plugin bulk-watermark Cross-Site Request Forgery No login needed ≤ 1.6.10 CVE-2025-58845 Patchstack
7.1 High Database to Excel Plugin database-to-excel Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-58844 Patchstack
7.1 High Auto Last Youtube Video Plugin auto-last-youtube-video Cross-Site Request Forgery No login needed ≤ 1.0.7 CVE-2025-58843 Patchstack
8.8 High Invelity MyGLS connect Plugin invelity-mygls-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-58833 Patchstack
7.1 High To Lead For Salesforce Plugin salesforce-wordpress-to-lead Cross-Site Request Forgery No login needed ≤ 2.7.3.9 CVE-2025-58809 Patchstack
7.1 High Purge Varnish Cache Plugin purge-varnish Cross-Site Request Forgery No login needed ≤ 2.6 CVE-2025-58807 Patchstack
7.1 High WordPress Error Monitoring by Bugsnag Plugin bugsnag Cross-Site Request Forgery No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-58806 Patchstack
7.1 High ATT YouTube Widget Plugin att-youtube Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48359 Patchstack
7.1 High Clickbank WordPress Plugin (Niche Storefront) Plugin clickbank-niche-storefronts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3.5 CVE-2025-48353 Patchstack
7.1 High Kento Splash Screen Plugin kento-splash-screen Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-48351 Patchstack
7.1 High WPMU Ldap Authentication Plugin wpmuldap Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 5.0.1 Fixed in 5.1 CVE-2025-48343 Patchstack
7.1 High WP Admin Plugin wp-admin-theme Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48325 Patchstack
7.1 High Ultimate twitter profile widget Plugin ultimate-twitter-profile-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-48321 Patchstack
7.1 High 百度分享按钮 Plugin baidushare-wp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.6 CVE-2025-48320 Patchstack
7.1 High Invisible Optin Plugin invisible-optin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48311 Patchstack
7.1 High BetPress Plugin betpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Lite CVE-2025-48309 Patchstack
7.1 High Newsletter subscription optin module Plugin newsletter-subscription-widget-for-sendblaster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.9 CVE-2025-48308 Patchstack
7.1 High SEO For Images Plugin seo-for-images Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.0 CVE-2025-48307 Patchstack
7.1 High Savyour Affiliate Partner Plugin savyour-affiliate-partner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.4 CVE-2025-48306 Patchstack
7.1 High Google XML News Sitemap Plugin gn-xml-sitemap Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.02 CVE-2025-48304 Patchstack
7.1 High XM-Backup Plugin xm-backup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.9.1 CVE-2025-48109 Patchstack
7.1 High Instant Breaking News Plugin instant-breaking-news Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.0.1 CVE-2025-58217 Patchstack
8.8 High JobZilla - Job Board Theme jobzilla Cross-Site Request Forgery Job Board WordPress Theme Theme <= 2.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2025-49382 Patchstack
8.8 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Request Forgery No login needed ≤ 9.1.3 Fixed in 9.1.4 CVE-2025-49399 Patchstack
7.1 High NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52765 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only