WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,151–2,200 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 44 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Document Library Lite Plugin document-library-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.7 Fixed in 1.2.0 CVE-2025-67985 Patchstack
6.5 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting ≤ 8.3 Fixed in 8.4 CVE-2025-67983 Patchstack
6.5 Medium Watu Quiz Plugin watu Broken Access Control ≤ 3.4.5 Fixed in 3.4.5.1 CVE-2025-67976 Patchstack
5.3 Medium Homey Core Plugin homey-core Broken Access Control No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67965 Patchstack
6.5 Medium WPZOOM Addons for Elementor Plugin wpzoom-elementor-addons Cross-Site Scripting ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-67951 Patchstack
4.3 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Information Disclosure Sensitive Data Exposure ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-67948 Patchstack
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-67929 Patchstack
6.5 Medium Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Cross-Site Scripting ≤ 3.3.4 Fixed in 3.3.5 CVE-2025-67912 Patchstack
5.4 Medium Lottier Plugin lottier-gutenberg Broken Access Control ≤ 1.1.1 CVE-2025-66167 Patchstack
5.4 Medium Lottier for Elementor Plugin lottier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66166 Patchstack
5.4 Medium Lottier for WPBakery Plugin lottier-wpbakery Broken Access Control ≤ 1.1.7 CVE-2025-66165 Patchstack
5.4 Medium Laser Plugin laser Broken Access Control ≤ 1.1.1 CVE-2025-66164 Patchstack
5.4 Medium Masker for Elementor Plugin masker-elementor Broken Access Control ≤ 1.1.4 CVE-2025-66163 Patchstack
5.4 Medium Spoter for Elementor Plugin spoter-elementor Broken Access Control ≤ 1.04 CVE-2025-66162 Patchstack
5.4 Medium Grider for Elementor Plugin grider-elementor Broken Access Control ≤ 1.0.8 CVE-2025-66161 Patchstack
5.4 Medium Coder for Elementor Plugin coder-elementor Broken Access Control ≤ 1.0.13 CVE-2025-66147 Patchstack
5.4 Medium FileBird Pro Plugin filebird-pro Broken Access Control ≤ 6.5.1 Fixed in 6.5.2 CVE-2025-66134 Patchstack
5.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control No login needed ≤ 4.0.7 Fixed in 4.0.8 CVE-2025-66133 Patchstack
5.3 Medium FAPI Member Plugin fapi-member Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.30 CVE-2025-66132 Patchstack
5.3 Medium Yaad Sarig Payment Gateway For WC Plugin yaad-sarig-payment-gateway-for-wc Broken Access Control No login needed ≤ 2.2.11 CVE-2025-66131 Patchstack
5.3 Medium WP Views Counter Plugin wpecounter Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-66130 Patchstack
5.3 Medium Pochipp Plugin pochipp Broken Access Control No login needed ≤ 1.18.0 Fixed in 1.18.1 CVE-2025-66129 Patchstack
5.3 Medium Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Broken Access Control No login needed ≤ 4.0.49 Fixed in 4.0.50 CVE-2025-66128 Patchstack
5.3 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control No login needed ≤ 5.3.2 CVE-2025-66127 Patchstack
5.3 Medium Fix Media Library Plugin wow-media-library-fix Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0 CVE-2025-66126 Patchstack
5.3 Medium Ultimate Auction Plugin ultimate-auction Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.3 CVE-2025-66125 Patchstack
5.3 Medium Leaky Paywall Plugin leaky-paywall Broken Access Control No login needed ≤ 4.22.6 Fixed in 5.0 CVE-2025-66124 Patchstack
5.3 Medium Stylish Price List Plugin stylish-price-list Broken Access Control No login needed ≤ 7.2.2 Fixed in 7.2.3 CVE-2025-66122 Patchstack
5.3 Medium SiteGround Security Plugin sg-security Broken Access Control No login needed ≤ 1.5.8 Fixed in 1.5.9 CVE-2025-66121 Patchstack
5.3 Medium CatFolders Plugin catfolders Broken Access Control No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-66120 Patchstack
5.3 Medium WP Compress for MainWP Plugin wp-compress-mainwp Broken Access Control No login needed ≤ 6.50.17 CVE-2025-64639 Patchstack
5.3 Medium OnPay.io for WooCommerce Plugin onpay-io-for-woocommerce Broken Access Control No login needed ≤ 1.0.47 Fixed in 1.0.48 CVE-2025-64638 Patchstack
5.3 Medium Feeds for YouTube Plugin feeds-for-youtube Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.6.1 CVE-2025-64635 Patchstack
5.3 Medium Avada Theme avada Broken Access Control No login needed ≤ 7.13.2 Fixed in 7.13.3 CVE-2025-64634 Patchstack
5.3 Medium Norebro Extra Plugin norebro-extra Content Injection No login needed ≤ 1.6.8 CVE-2025-64633 Patchstack
5.3 Medium Google XML Sitemaps Plugin google-sitemap-generator Broken Access Control No login needed ≤ 4.1.22 Fixed in 4.1.23 CVE-2025-64632 Patchstack
4.9 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control ≤ 3.7.1 CVE-2025-64631 Patchstack
4.9 Medium Business Directory Plugin business-directory-plugin Broken Access Control ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-64630 Patchstack
4.9 Medium Health Check & Troubleshooting Plugin health-check Path Traversal ≤ 1.7.1 CVE-2025-64253 Patchstack
4.9 Medium Ultimate Learning Pro Plugin indeed-learning-pro Broken Access Control Arbitrary Content Deletion ≤ 3.9.3 CVE-2025-64251 Patchstack
4.7 Medium Directorist Plugin directorist Open Redirect No login needed ≤ 8.6.6 Fixed in 8.6.7 CVE-2025-64250 Patchstack
4.3 Medium Protect WP Admin Plugin protect-wp-admin Broken Access Control No login needed ≤ 4.1 Fixed in 4.2 CVE-2025-64249 Patchstack
4.3 Medium Request a Quote Plugin request-a-quote Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-64248 Patchstack
4.3 Medium Read More & Accordion Plugin expand-maker Broken Access Control ≤ 3.5.5.1 Fixed in 3.5.6 CVE-2025-64247 Patchstack
4.3 Medium Accessibility by AudioEye Plugin accessibility-by-audioeye Broken Access Control ≤ 1.0.49 Fixed in 1.1.0 CVE-2025-64246 Patchstack
4.3 Medium Import external attachments Plugin import-external-attachments Broken Access Control ≤ 1.5.12 CVE-2025-64245 Patchstack
4.3 Medium Restrict Elementor Widgets, Columns and Sections Plugin restrict-elementor-widgets Broken Access Control ≤ 1.12 CVE-2025-64244 Patchstack
4.3 Medium Directory Pro Plugin directory-pro Broken Access Control ≤ 2.5.6 CVE-2025-64243 Patchstack
4.3 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control ≤ 3.5.22 Fixed in 3.5.23 CVE-2025-64242 Patchstack
4.3 Medium WP Coupons and Deals Plugin wp-coupons-and-deals Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-64241 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only