WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,101–2,150 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 43 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Tuturn Plugin tuturn Path Traversal Arbitrary File Download < 3.6 Fixed in 3.6 CVE-2025-64235 Patchstack
4.3 Medium Radius Blocks Plugin radius-blocks Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.2.1 CVE-2025-64282 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12 Fixed in 2.7.12.1 CVE-2025-64355 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
6.5 Medium WP ERP Plugin erp Information Disclosure Sensitive Data Exposure ≤ 1.16.6 Fixed in 1.16.7 CVE-2025-67546 Patchstack
6.5 Medium Offload, AI & Optimize with Cloudflare Images Plugin cf-images Broken Access Control ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-66104 Patchstack
6.5 Medium RestroPress Plugin restropress Broken Access Control ≤ 3.2.3.5 Fixed in 3.2.3.6 CVE-2025-66100 Patchstack
6.5 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.1.9 Fixed in 0.1.2.0 CVE-2025-66068 Patchstack
6.5 Medium WP Social Ninja Plugin wp-social-reviews Broken Access Control No login needed ≤ 3.20.1 Fixed in 3.20.2 CVE-2025-64375 Patchstack
6.5 Medium All In One SEO Pack Plugin all-in-one-seo-pack Information Disclosure Sensitive Data Exposure ≤ 4.8.6.1 Fixed in 4.8.7 CVE-2025-64295 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64273 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Information Disclosure Sensitive Data Exposure ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64272 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
6.5 Medium Stockie Extra Plugin stockie-extra Content Injection No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64225 Patchstack
6.3 Medium XStore Theme xstore Broken Access Control ≤ 9.6 Fixed in 9.6 CVE-2025-64192 Patchstack
6.5 Medium ListingPro Theme listingpro Broken Access Control ≤ 2.9.9 CVE-2025-63039 Patchstack
6.5 Medium WebinarIgnition Plugin webinar-ignition Broken Access Control ≤ 4.06.04 Fixed in 4.06.05 CVE-2025-60088 Patchstack
6.5 Medium Molla Plugin molla Remote Code Execution Multipurpose Responsive Shopify theme <= 1.5.13 - Arbitrary Code Execution No login needed ≤ 1.5.13 CVE-2025-60070 Patchstack
6.5 Medium Javo Core Plugin javo-core Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.0.0.266 CVE-2025-60068 Patchstack
6.5 Medium MapSVG Plugin mapsvg Path Traversal Arbitrary File Download ≤ 8.6.12 Fixed in 8.6.12 CVE-2025-54748 Patchstack
6.5 Medium miniOrange's Google Authenticator Plugin miniorange-2-factor-authentication Broken Access Control ≤ 6.1.1 Fixed in 6.1.2 CVE-2025-54745 Patchstack
5.8 Medium Download After Email Plugin download-after-email Broken Access Control Other Vulnerability Type No login needed ≤ 2.1.5-2.1.6 Fixed in 2.1.7 CVE-2025-54743 Patchstack
6.5 Medium Super Blank Plugin super-blank Broken Access Control Arbitrary Content Deletion ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-54741 Patchstack
5.8 Medium eRoom Plugin eroom-zoom-meetings-webinar Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2025-49919 Patchstack
5.9 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-49918 Patchstack
6.5 Medium Restaurant Menu by MotoPress Plugin mp-restaurant-menu Information Disclosure Sensitive Data Exposure ≤ 2.4.7 Fixed in 2.4.8 CVE-2025-49914 Patchstack
6.5 Medium Login Page Customizer – Customizer Login Page, Admin Page, Custom Design Plugin customizer-login-page Broken Access Control Customizer Login Page, Admin Page, Custom Design plugin <= 2.1.1 - Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-49902 Patchstack
6.5 Medium Get Cash Plugin get-cash Broken Access Control No login needed ≤ 3.2.3 CVE-2025-49041 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.3.60 Fixed in 1.3.61 CVE-2025-10019 Patchstack
6.4 Medium Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder Cross-Site Scripting Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.2 CVE-2025-13537 Wordfence
6.1 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.10.2 CVE-2025-14154 Wordfence
6.1 Medium HTML Forms – Simple WordPress Forms Plugin html-forms Cross-Site Scripting Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2025-13861 Wordfence
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
5.4 Medium Huger for Elementor Plugin huger-elementor Broken Access Control ≤ 1.1.5 CVE-2025-68088 Patchstack
5.4 Medium Modalier for Elementor Plugin modalier-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68087 Patchstack
5.4 Medium Reformer for Elementor Plugin reformer-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68086 Patchstack
5.4 Medium Buttoner for Elementor Plugin buttoner-elementor Broken Access Control Settings Change ≤ 1.0.6 CVE-2025-68085 Patchstack
5.4 Medium Ultimate Auction Plugin ultimate-auction Broken Access Control ≤ 4.3.3 CVE-2025-68084 Patchstack
5.4 Medium Meks Quick Plugin Disabler Plugin meks-quick-plugin-disabler Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-68083 Patchstack
5.4 Medium Semrush Content Toolkit Plugin semrush-contentshake Cross-Site Request Forgery No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68082 Patchstack
6.5 Medium User Avatar - Reloaded Plugin user-avatar-reloaded Cross-Site Scripting Reloaded plugin <= 1.2.2 - Cross Site Scripting (XSS) ≤ 1.2.2 CVE-2025-68080 Patchstack
6.5 Medium Salient Shortcodes Plugin salient-shortcodes Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-68079 Patchstack
6.5 Medium Salient Portfolio Theme salient-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-68078 Patchstack
6.5 Medium Stockholm Plugin stockholm Cross-Site Scripting ≤ 9.14.1 CVE-2025-68077 Patchstack
6.5 Medium Stockholm Core Plugin stockholm-core Cross-Site Scripting ≤ 2.4.6 CVE-2025-68076 Patchstack
6.5 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.3.2 CVE-2025-68071 Patchstack
6.5 Medium VK Google Job Posting Manager Plugin vk-google-job-posting-manager Cross-Site Scripting ≤ 1.2.22 Fixed in 1.2.23 CVE-2025-68070 Patchstack
5.4 Medium Kerge Theme kerge Server-Side Request Forgery No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-67989 Patchstack
5.9 Medium Document Library Lite Plugin document-library-lite Cross-Site Scripting ≤ 1.1.7 Fixed in 1.2.0 CVE-2025-67986 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only