WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,051–2,100 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Basticom Framework Plugin basticom-framework Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67629 Patchstack
5.9 Medium Review Disclaimer Plugin review-disclaimer Cross-Site Scripting ≤ 2.0.3 CVE-2025-67628 Patchstack
5.9 Medium Draft Notify Plugin draft-notify Cross-Site Scripting ≤ 1.5 CVE-2025-67627 Patchstack
4.3 Medium Trade Runner Plugin traderunner Cross-Site Request Forgery No login needed ≤ 3.14 CVE-2025-67625 Patchstack
5.4 Medium 6Storage Rentals Plugin 6storage-rentals Server-Side Request Forgery No login needed ≤ 2.22.0 CVE-2025-67623 Patchstack
4.3 Medium Eight Day Week Print Workflow Plugin eight-day-week-print-workflow Information Disclosure Sensitive Data Exposure ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-67621 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control No login needed ≤ 2.0.5.3 Fixed in 2.0.5.4.1 CVE-2023-40679 Patchstack
5.9 Medium Hostel Plugin hostel Cross-Site Scripting ≤ 1.1.5.1 Fixed in 1.1.5.2 CVE-2023-32120 Patchstack
4.3 Medium Resoto Theme resoto Broken Access Control Broken Access Control to Arbitrary Plugin Activation ≤ 1.0.8 CVE-2023-28619 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.5.7.1 Fixed in 3.5.7.2 CVE-2025-68535 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-68533 Patchstack
6.5 Medium ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68532 Patchstack
4.3 Medium WP Email Capture Plugin wp-email-capture Cross-Site Request Forgery No login needed ≤ 3.12.5 Fixed in 3.12.6 CVE-2025-68529 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-68528 Patchstack
6.5 Medium Academy LMS Plugin academy Cross-Site Scripting ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-68527 Patchstack
5.9 Medium Category Icon Plugin category-icon Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-68525 Patchstack
4.3 Medium Spiffy Calendar Plugin spiffy-calendar Broken Access Control ≤ 5.0.7 Fixed in 5.0.8 CVE-2025-68523 Patchstack
4.3 Medium WpStream Plugin wpstream Broken Access Control ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68522 Patchstack
5.3 Medium WpStream Plugin wpstream Broken Access Control No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68521 Patchstack
5.4 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68517 Patchstack
5.0 Medium Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68516 Patchstack
6.5 Medium Bold Timeline Lite Plugin bold-timeline-lite Cross-Site Scripting ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-68513 Patchstack
6.5 Medium Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 4.11.4 Fixed in 4.16.4 CVE-2025-68512 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-68511 Patchstack
4.7 Medium User Submitted Posts Plugin user-submitted-posts Open Redirect No login needed ≤ 20251121 Fixed in 20251210 CVE-2025-68509 Patchstack
5.3 Medium Brave Plugin brave-popup-builder Broken Access Control No login needed ≤ 0.8.3 Fixed in 0.8.4 CVE-2025-68508 Patchstack
5.3 Medium H5P Plugin h5p Broken Access Control No login needed ≤ 1.16.1 Fixed in 1.16.2 CVE-2025-68505 Patchstack
4.9 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) ≤ 4.0.10 Fixed in 4.1.0 CVE-2025-68500 Patchstack
5.9 Medium Astra Widgets Plugin astra-widgets Cross-Site Scripting ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-68497 Patchstack
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.11.53 Fixed in 4.11.54 CVE-2025-68494 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.0 - Broken Access Control No login needed ≤ 2.7.0 Fixed in 2.7.1 CVE-2023-52210 Patchstack
6.5 Medium Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Cross-Site Scripting ≤ 15.2 Fixed in 15.3 CVE-2025-68548 Patchstack
6.5 Medium VPSUForm Plugin v-form Information Disclosure Sensitive Data Exposure ≤ 3.2.24 Fixed in 3.2.25 CVE-2025-68551 Patchstack
5.3 Medium HAPPY Plugin happy-helpdesk-support-ticket-system Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-68556 Patchstack
4.3 Medium Chakra test Plugin chakra-test Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-68557 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68559 Patchstack
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0.1.2 CVE-2025-62094 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-62107 Patchstack
4.3 Medium Custom 404 Pro Plugin custom-404-pro Cross-Site Request Forgery No login needed ≤ 3.12.0 CVE-2025-62880 Patchstack
6.5 Medium WP Microdata Plugin wp-microdata Cross-Site Scripting ≤ 1.0 CVE-2025-62901 Patchstack
6.5 Medium TempTool [Show Current Template Info] Plugin current-template-name Cross-Site Scripting ≤ 1.3.1 CVE-2025-62926 Patchstack
4.3 Medium TempTool [Show Current Template Info] Plugin current-template-name Information Disclosure Sensitive Data Exposure ≤ 1.3.1 CVE-2025-62955 Patchstack
6.1 Medium Five Star Restaurant Reservations – WordPress Booking Plugin Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2025-11496 Wordfence
4.3 Medium WP Affiliate Disclosure Plugin wp-affiliate-disclosure Information Disclosure Broken Access Control + CSRF ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-47232 Patchstack
5.4 Medium HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25445 Patchstack
4.3 Medium Magazine Edge Theme magazine-edge Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 1.13 CVE-2023-25068 Patchstack
5.4 Medium Construction Light Plugin construction-light Broken Access Control ≤ 1.6.7 CVE-2025-62960 Patchstack
5.4 Medium Sparkle FSE Plugin sparkle-fse Broken Access Control ≤ 1.0.9 CVE-2025-62961 Patchstack
5.0 Medium WP AI CoPilot Plugin ai-co-pilot-for-wp Information Disclosure Sensitive Data Exposure ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-62998 Patchstack
5.3 Medium Sermon Manager Plugin sermon-manager-for-wordpress Broken Access Control No login needed ≤ 2.30.0 CVE-2025-63002 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only