WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,201–2,250 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 45 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Sell Downloads Plugin sell-downloads Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.2.0 CVE-2025-68850 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-68547 Patchstack
8.6 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68044 Patchstack
7.5 High Custom Related Posts Plugin custom-related-posts Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-68033 Patchstack
8.8 High Themify Edmin Theme edmin PHP Object Injection ≤ 2.0.0 CVE-2025-31047 Patchstack
8.5 High Premium SEO Pack Plugin premium-seo-pack SQL Injection ≤ 3.3.2 CVE-2025-31044 Patchstack
8.1 High FreeAgent Theme freeagent Local File Inclusion No login needed ≤ 2.1.2 CVE-2025-69087 Patchstack
7.1 High Easy Social Plugin easy-social-media Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-53235 Patchstack
7.1 High Sala Theme sala Cross-Site Scripting No login needed ≤ 1.1.3 CVE-2025-52739 Patchstack
7.1 High Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin yournewsapp Cross-Site Scripting Your native, mobile iPhone App and Android App Plugin <= 0.8.8.8 - Cross Site Scripting (XSS) No login needed ≤ 0.8.8.8 CVE-2025-50053 Patchstack
7.1 High ZoomSounds Plugin dzs-zoomsounds Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.91 CVE-2025-47566 Patchstack
7.1 High Bloggie Theme bloggie Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2025-31054 Patchstack
8.5 High Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) Plugin azon-addon-js-composer SQL Injection ≤ 1.2 CVE-2025-30628 Patchstack
8.5 High Mediabay - WordPress Media Library Folders Plugin mediabay SQL Injection WordPress Media Library Folders <= 1.4 - SQL Injection ≤ 1.4 CVE-2025-28949 Patchstack
7.1 High ZD Scribd iPaper Plugin zd-scribd-ipaper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23757 Patchstack
7.1 High ZhinaTwitterWidget Plugin zhina-twitter-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23719 Patchstack
7.1 High En Masse Plugin en-masse-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23707 Patchstack
7.1 High Zielke Design Project Gallery Plugin zielke-design-project-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23705 Patchstack
7.1 High custom-post-edit Plugin front-end-post-edit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-23667 Patchstack
7.1 High LIVE TV Plugin live-tv Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23608 Patchstack
7.1 High Zoho ZeptoMail Plugin transmail Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-49028 Patchstack
7.1 High Custom Style Plugin custom-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49342 Patchstack
7.1 High Noindex by Path Plugin noindex-by-path Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49353 Patchstack
7.1 High Custom Post Status Plugin custom-post-status Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.0 CVE-2025-68885 Patchstack
7.1 High Recent Posts From Each Category Plugin recent-posts-from-each-category Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-49354 Patchstack
7.1 High Social Profilr Plugin social-profilr-display-social-network-profile Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49343 Patchstack
7.1 High SensitiveTagCloud Plugin sensitive-tag-cloud Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-49344 Patchstack
7.1 High WP-EasyArchives Plugin wp-easyarchives Cross-Site Request Forgery No login needed ≤ 3.1.2 CVE-2025-49345 Patchstack
7.1 High Simple Archive Generator Plugin simple-archive-generator Cross-Site Request Forgery No login needed ≤ 5.2 CVE-2025-49346 Patchstack
7.1 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Request Forgery No login needed ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-59137 Patchstack
7.1 High WP-CalDav2ICS Plugin wp-caldav2ics Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-59131 Patchstack
7.5 High MAS Videos Plugin masvideos Local File Inclusion ≤ 1.3.4 CVE-2025-62753 Patchstack
7.6 High Appointify Plugin appointify SQL Injection ≤ 1.0.8 CVE-2025-59129 Patchstack
8.1 High Lekker Theme lekker Local File Inclusion No login needed ≤ 1.8 CVE-2025-69034 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.1 CVE-2025-68996 Patchstack
8.5 High BWL Pro Voting Manager Plugin bwl-pro-voting-manager SQL Injection ≤ 1.4.9 CVE-2025-68990 Patchstack
7.5 High Cinerama Theme cinerama Local File Inclusion ≤ 2.9 CVE-2025-68987 Patchstack
7.5 High Aora Theme aora Local File Inclusion ≤ 1.3.15 CVE-2025-68985 Patchstack
7.5 High Puca Plugin puca Local File Inclusion ≤ 2.6.39 CVE-2025-68984 Patchstack
7.5 High Greenmart Plugin greenmart Local File Inclusion ≤ 4.2.11 CVE-2025-68983 Patchstack
7.1 High Off Page SEO Plugin off-page-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.3 CVE-2025-23554 Patchstack
7.1 High Product Puller Plugin product-puller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23550 Patchstack
7.1 High Sleekplan Plugin sleekplan Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.0 CVE-2025-23469 Patchstack
7.1 High Ads24 Lite Plugin wp-ad-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23458 Patchstack
7.5 High CubeWP Plugin cubewp-framework Broken Access Control No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2025-68036 Patchstack
7.1 High Plugin Optimizer Plugin plugin-optimizer Broken Access Control ≤ 1.3.7 CVE-2025-68861 Patchstack
7.5 High CookieHint WP Plugin cookiehint-wp Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-68870 Patchstack
7.1 High Invelity SPS connect Plugin invelity-sps-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 CVE-2025-68876 Patchstack
7.5 High CedCommerce Integration for Good Market Plugin ced-good-market-integration Local File Inclusion No login needed ≤ 1.0.6 CVE-2025-68877 Patchstack
7.1 High Advanced Custom CSS Plugin advanced-custom-css Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-68878 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only