WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 1,491 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium RealPress Plugin realpress Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-27050 Patchstack
4.4 Medium TS Poll Plugin poll-wp Server-Side Request Forgery ≤ 2.5.5 CVE-2026-25428 Patchstack
5.4 Medium Popularis Extra Plugin popularis-extra Cross-Site Request Forgery No login needed ≤ 1.2.10 CVE-2026-25422 Patchstack
4.3 Medium Revision Manager TMC Plugin revision-manager-tmc Cross-Site Request Forgery No login needed ≤ 2.8.22 CVE-2026-25411 Patchstack
5.5 Medium URL Shortify Plugin url-shortify Server-Side Request Forgery ≤ 1.12.3 Fixed in 1.12.4 CVE-2026-25385 Patchstack
5.4 Medium Coachify Plugin coachify Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-25337 Patchstack
5.4 Medium PublishPress Revisions Plugin revisionary Cross-Site Request Forgery No login needed ≤ 3.7.22 Fixed in 3.7.23 CVE-2026-25322 Patchstack
4.3 Medium Zita Elementor Site Library Plugin zita-site-library Cross-Site Request Forgery No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-25319 Patchstack
4.9 Medium Extend Link Plugin extend-link Server-Side Request Forgery ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-25310 Patchstack
6.4 Medium Simple Wp colorfull Accordion Plugin simple-wp-colorfull-accordion Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via 'title' Shortcode Attribute ≤ 1.0 CVE-2026-1904 Wordfence
6.4 Medium WaveSurfer-WP Plugin wavesurfer-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute ≤ 2.8.3 CVE-2026-1909 Wordfence
5.4 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Request Forgery No login needed ≤ 3.11.9 Fixed in 3.11.10 CVE-2026-25024 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.53 Fixed in 1.2.54 CVE-2026-25015 Patchstack
4.3 Medium Enter Addons Plugin enteraddons Cross-Site Request Forgery No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-25014 Patchstack
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.41 Fixed in 7.42 CVE-2026-25011 Patchstack
5.4 Medium Simple Membership WP user Import Plugin simple-membership-wp-user-import Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24986 Patchstack
4.3 Medium Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24966 Patchstack
4.3 Medium Sigmize Plugin sigmize Cross-Site Request Forgery No login needed ≤ 0.0.9 Fixed in 0.0.10 CVE-2026-24962 Patchstack
5.4 Medium Grand Blog Theme grandblog Server-Side Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-24961 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-24942 Patchstack
4.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed < 2.7.9 Fixed in 2.7.9 CVE-2026-0658 WPScan
4.3 Medium Related Posts Thumbnails Plugin related-posts-thumbnails Cross-Site Request Forgery No login needed ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-24596 Patchstack
4.3 Medium GeoDirectory Plugin geodirectory Cross-Site Request Forgery No login needed ≤ 2.8.149 Fixed in 2.8.150 CVE-2026-24549 Patchstack
5.4 Medium Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.91 CVE-2026-24548 Patchstack
4.3 Medium WP Term Order Plugin wp-term-order Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2026-24542 Patchstack
4.3 Medium Kama Thumbnail Plugin kama-thumbnail Cross-Site Request Forgery No login needed ≤ 3.5.1 CVE-2026-24521 Patchstack
4.3 Medium Wordpress Movies Bulk Importer Plugin movies Cross-Site Request Forgery No login needed ≤ <= 1.0 CVE-2026-22359 Patchstack
5.4 Medium Merge + Minify + Refresh Plugin merge-minify-refresh Cross-Site Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-24384 Patchstack
5.4 Medium PhotoMe Theme photome Server-Side Request Forgery No login needed ≤ 5.7.2 Fixed in 5.7.2 CVE-2026-24381 Patchstack
5.4 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 6.0.6.9 Fixed in 6.0.7.0 CVE-2026-24374 Patchstack
5.4 Medium Stock Manager for WooCommerce Plugin woocommerce-stock-manager Cross-Site Request Forgery No login needed ≤ 3.6.0 Fixed in 3.6.0 CVE-2026-24365 Patchstack
4.4 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Server-Side Request Forgery ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-24360 Patchstack
6.5 Medium Penci Shortcodes & Performance Plugin penci-shortcodes Cross-Site Scripting ≤ 6.1 Fixed in 6.2 CVE-2026-24354 Patchstack
5.4 Medium teachPress Plugin teachpress Cross-Site Request Forgery No login needed ≤ 9.0.12 CVE-2026-22483 Patchstack
4.9 Medium IMGspider Plugin imgspider Server-Side Request Forgery ≤ 2.3.12 CVE-2026-22482 Patchstack
4.3 Medium Add Polylang support for Customizer Plugin add-polylang-support-for-customizer Cross-Site Request Forgery No login needed ≤ 1.4.5 CVE-2026-22462 Patchstack
5.4 Medium PawFriends - Pet Shop and Veterinary Theme pawfriends Cross-Site Request Forgery Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2026-22382 Patchstack
4.3 Medium SearchAzon Plugin searchazon Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2026-22360 Patchstack
5.4 Medium Electrician - Electrical Service Plugin electrician Server-Side Request Forgery Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) No login needed ≤ 5.6 CVE-2026-22358 Patchstack
6.4 Medium WPO365 Plugin wpo365-login Server-Side Request Forgery ≤ 40.0 Fixed in 40.1 CVE-2025-67961 Patchstack
4.3 Medium WP SEO Search Plugin wp-seo-search Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-67626 Patchstack
4.9 Medium ANAC XML Viewer Plugin anac-xml-viewer Server-Side Request Forgery ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-64252 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Request Forgery No login needed ≤ 8.3.13 Fixed in 8.3.14 CVE-2025-31413 Patchstack
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure ≤ 4.9.2 CVE-2025-14384 Wordfence
5.3 Medium Perfit WooCommerce Plugin perfit-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 1.0.1 CVE-2025-14173 Wordfence
4.3 Medium Clearfy Plugin clearfy Cross-Site Request Forgery Cross-Site Request Forgery to Update Notification Tampering No login needed ≤ 2.4.0 CVE-2025-13749 Wordfence
6.4 Medium nK Themes Helper Plugin nk-themes-helper Server-Side Request Forgery ≤ 1.7.9 CVE-2025-22726 Patchstack
4.9 Medium External Media Plugin external-media Server-Side Request Forgery ≤ 1.0.36 CVE-2025-49335 Patchstack
4.3 Medium Thim Core Plugin thim-core Cross-Site Request Forgery No login needed ≤ 2.3.3 CVE-2025-53344 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only