WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 151–200 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.8 Low Migration, Backup, Staging – WPvivid Backup & Migration Plugin wpvivid-backuprestore Arbitrary File Deletion WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion ≤ 0.9.128 CVE-2025-12656 Wordfence
3.5 Low WP reCaptcha by WebDesignBy Plugin Cross-Site Scripting Admin+ Stored XSS < 2.0 Fixed in 2.0 CVE-2026-4512 WPScan
3.5 Low Email Encoder Plugin email-encoder-bundle Cross-Site Scripting Admin+ Stored XSS < 2.3.4 Fixed in 2.3.4 CVE-2024-7083 WPScan
3.1 Low OneSignal – Web Push Notifications Plugin onesignal-free-web-push-notifications Broken Access Control Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id' ≤ 3.8.0 CVE-2026-3155 Wordfence
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
3.8 Low Post Affiliate Pro Plugin postaffiliatepro Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'Post Affiliate Pro URL' Field ≤ 1.28.0 CVE-2026-2290 Wordfence
2.7 Low Keep Backup Daily Plugin keep-backup-daily Path Traversal Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter ≤ 2.1.1 CVE-2026-3339 Wordfence
2.7 Low Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32445 Patchstack
3.7 Low wpDiscuz Plugin wpdiscuz Other Unsanitized Cookie Email Used as wp_mail() Recipient No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22204 VulnCheck
3.8 Low Real 3D FlipBook Plugin real3d-flipbook-lite Broken Access Control ≤ 4.19.1 Fixed in 4.19.2 CVE-2026-25423 Patchstack
2.7 Low OneClick Chat to Order Plugin oneclick-whatsapp-order Broken Access Control Missing Authorization to Authenticated (Editor+) Plugin Settings Update ≤ 1.0.9 CVE-2025-14270 Wordfence
3.7 Low WP All Export Plugin wp-all-export Information Disclosure Unauthenticated Sensitive Information Exposure via PHP Type Juggling No login needed ≤ 1.4.14 CVE-2026-1582 Wordfence
2.7 Low YayMail Plugin yaymail Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation ≤ 4.3.2 CVE-2026-1831 Wordfence
2.7 Low WP-DownloadManager Plugin wp-downloadmanager Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter ≤ 1.69 CVE-2026-2419 Wordfence
3.7 Low MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Plugin metform Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value No login needed ≤ 4.1.0 CVE-2026-0633 Wordfence
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
2.2 Low Church Admin Plugin church-admin Server-Side Request Forgery Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audio_url' Parameter ≤ 5.0.28 CVE-2026-0682 Wordfence
3.7 Low Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Missing Authorization to Unauthenticated File Deletion No login needed ≤ 1.3.9.2 CVE-2025-14457 Wordfence
2.7 Low Rankology SEO and Analytics Tool Plugin rankology-seo-and-analytics-tool Broken Access Control Incorrect Authorization to Authenticated (Editor+) Header & Footer Code Creation ≤ 2.0 CVE-2025-12958 Wordfence
3.5 Low FlexTable Google Sheets Connector Plugin Cross-Site Scripting Admin+ Stored XSS < 3.19.2 Fixed in 3.19.2 CVE-2025-9543 WPScan
3.8 Low Crowdsignal Forms Plugin crowdsignal-forms Broken Access Control ≤ 1.7.2 Fixed in 1.8.0 CVE-2025-69015 Patchstack
2.7 Low WP Document Revisions Plugin wp-document-revisions Broken Access Control ≤ 3.7.2 Fixed in 3.8.0 CVE-2025-68585 Patchstack
2.7 Low Migration, Backup, Staging – WPvivid Backup & Migration Plugin wpvivid-backuprestore Path Traversal WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory Creation ≤ 0.9.120 CVE-2025-12654 Wordfence
2.7 Low WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control ≤ 6.7.24 Fixed in 6.7.25 CVE-2025-54004 Patchstack
2.7 Low Traveler Option Tree Plugin custom-option-tree Information Disclosure Sensitive Data Exposure ≤ 2.8 CVE-2025-49300 Patchstack
3.7 Low rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function No login needed 4.7.0 – 4.7.3 CVE-2025-9218 Wordfence
3.5 Low WP Fastest Cache Premium Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Blind Server-Side Request Forgery ≤ 1.7.4 CVE-2025-10583 Wordfence
2.7 Low Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Broken Access Control ≤ 8.0.8 Fixed in 8.1.0 CVE-2025-64255 Patchstack
2.7 Low Photo Block Plugin photo-block Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-64254 Patchstack
2.7 Low Timetable and Event Schedule by MotoPress Plugin mp-timetable Information Disclosure Contributor+ Event Disclosure via IDOR < 2.4.16 Fixed in 2.4.16 CVE-2025-12954 WPScan
3.4 Low WP YouTube Lyte Plugin wp-youtube-lyte Open Redirect No login needed ≤ 1.7.28 Fixed in 1.7.29 CVE-2025-66062 Patchstack
2.7 Low Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control ≤ 6.2.4 Fixed in 6.3.0 CVE-2025-64352 Patchstack
3.8 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64350 Patchstack
3.5 Low NS Maintenance Mode for WP Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.3.1 CVE-2025-10636 WPScan
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin shopengine Broken Access Control All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update ≤ 4.8.4 CVE-2025-11888 Wordfence
3.7 Low Password Protected Plugin password-protected Broken Access Control Unauthenticated Authorization Bypass via IP Address Spoofing No login needed ≤ 2.7.11 CVE-2025-11244 Wordfence
2.7 Low PixelYourSite Plugin pixelyoursite Local File Inclusion Admin+ LFI < 11.1.2 Fixed in 11.1.2 CVE-2025-10723 WPScan
3.8 Low Pz-LinkCard Plugin pz-linkcard Server-Side Request Forgery Contributor+ SSRF < 2.5.7 Fixed in 2.5.7 CVE-2025-8594 WPScan
2.4 Low GSheetConnector For Gravity Forms Plugin gsheetconnector-gravity-forms Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivation ≤ 1.3.23 CVE-2025-8606 Wordfence
3.8 Low Backup Bolt Plugin backup-bolt Path Traversal Authenticated (Admin+) Arbitrary File Download ≤ 1.4.1 CVE-2025-10306 Wordfence
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin Broken Access Control All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update ≤ 4.8.3 CVE-2025-10173 Wordfence
3.5 Low SureForms Plugin sureforms Cross-Site Scripting Admin+ Stored XSS < 1.9.1 Fixed in 1.9.1 CVE-2025-8282 WPScan
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.35 CVE-2025-58009 Patchstack
3.8 Low Content Mask Plugin content-mask Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8.5.3 CVE-2025-58012 Patchstack
3.5 Low jQuery Colorbox Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 4.6.3 CVE-2025-3650 WPScan
3.5 Low WPBOT Plugin chatbot Cross-Site Scripting Admin+ Stored XSS < 7.1.0 Fixed in 7.1.0 CVE-2025-9111 WPScan
3.8 Low Compress Then Upload Plugin Arbitrary File Upload Admin+ Arbitrary File Upload < 1.0.5 Fixed in 1.0.5 CVE-2025-8889 WPScan
2.7 Low Site Info Plugin site-info-dashboard-widget Information Disclosure Sensitive Data Exposure ≤ 1.1 CVE-2025-58866 Patchstack
3.8 Low Job Board Manager Plugin job-board-manager Content Injection ≤ 2.1.61 CVE-2025-58827 Patchstack
3.5 Low Product Carousel Slider for Elementor Plugin ecommerce-product-carousel-slider-for-elementor Broken Access Control ≤ 2.1.3 CVE-2025-58816 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only