WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,301–2,350 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 47 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium BERTHA AI Plugin bertha-ai-free Broken Access Control No login needed ≤ 1.13 CVE-2025-62085 Patchstack
6.5 Medium Generic Elements Plugin generic-elements-for-elementor Cross-Site Scripting ≤ 1.2.9 CVE-2025-62082 Patchstack
4.3 Medium Duplicate Content Cure Plugin duplicate-content-cure Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-59132 Patchstack
4.3 Medium Actionwear products sync Plugin actionwear-products-sync Broken Access Control ≤ 2.3.3 CVE-2025-49350 Patchstack
5.3 Medium Hype Plugin pico Broken Access Control No login needed ≤ 1.0.5 CVE-2025-49348 Patchstack
4.3 Medium WebToffee eCommerce Marketing Automation Plugin decorator-woocommerce-email-customizer Broken Access Control ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-67599 Patchstack
4.3 Medium SupportCandy Plugin supportcandy Cross-Site Request Forgery No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-67598 Patchstack
4.3 Medium Fluent Booking Plugin fluent-booking Broken Access Control ≤ 1.9.11 Fixed in 1.10.0 CVE-2025-67597 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Cross-Site Request Forgery No login needed ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-67596 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.82 Fixed in 6.7.0.83 CVE-2025-67595 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67594 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.48 Fixed in 1.2.49 CVE-2025-67593 Patchstack
4.3 Medium My Calendar Plugin my-calendar Broken Access Control ≤ 3.6.16 Fixed in 3.6.17 CVE-2025-67592 Patchstack
4.3 Medium JNews Paywall Plugin jnews-paywall Cross-Site Request Forgery No login needed ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67591 Patchstack
4.3 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67590 Patchstack
4.3 Medium WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control ≤ 4.9.1 Fixed in 5.0.0 CVE-2025-67589 Patchstack
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.33.0 Fixed in 3.33.1 CVE-2025-67588 Patchstack
4.7 Medium WP Gravity Forms FreshDesk Plugin gf-freshdesk Open Redirect No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-67587 Patchstack
4.7 Medium Highlight and Share Plugin highlight-and-share Broken Access Control No login needed ≤ 5.2.0 Fixed in 5.3.0 CVE-2025-67586 Patchstack
4.7 Medium Flexmls® IDX Plugin flexmls-idx Open Redirect No login needed ≤ 3.15.7 Fixed in 3.15.8 CVE-2025-67585 Patchstack
5.3 Medium GoDAM Plugin godam Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-67584 Patchstack
5.3 Medium IDonate Plugin idonate Broken Access Control No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-67583 Patchstack
5.3 Medium Wbcom Designs Plugin lock-my-bp Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-67582 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-67581 Patchstack
5.3 Medium Constant Contact + WooCommerce Plugin constant-contact-woocommerce Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-67580 Patchstack
5.3 Medium User Extra Fields Plugin wp-user-extra-fields Broken Access Control No login needed ≤ 16.8 Fixed in 16.9 CVE-2025-67579 Patchstack
5.3 Medium WP Email Capture Plugin wp-email-capture Broken Access Control No login needed ≤ 3.12.4 Fixed in 3.12.5 CVE-2025-67578 Patchstack
5.3 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control No login needed ≤ 3.8.20 Fixed in 3.8.21 CVE-2025-67577 Patchstack
5.3 Medium Simple Link Directory Plugin simple-link-directory Broken Access Control No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67576 Patchstack
5.3 Medium Sitewide Notice WP Plugin sitewide-notice-wp Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-67575 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-67574 Patchstack
5.3 Medium Sailing Theme sailing Broken Access Control No login needed ≤ 4.4.6 Fixed in 4.4.6 CVE-2025-67573 Patchstack
5.3 Medium PenNews Plugin pennews Broken Access Control No login needed ≤ 6.7.4 Fixed in 6.7.4 CVE-2025-67572 Patchstack
5.3 Medium WPFunnels Plugin wpfunnels Broken Access Control No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-67571 Patchstack
5.3 Medium WPForms Google Sheet Connector Plugin gsheetconnector-wpforms Broken Access Control No login needed ≤ 4.0.0 Fixed in 4.0.1 CVE-2025-67570 Patchstack
5.3 Medium AdForest Theme adforest Broken Access Control No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2025-67569 Patchstack
5.3 Medium Basel Theme basel Broken Access Control No login needed ≤ 5.9.1 Fixed in 5.9.2 CVE-2025-67568 Patchstack
5.3 Medium Sober Plugin sober Information Disclosure Sensitive Data Exposure No login needed ≤ 3.5.11 Fixed in 3.5.12 CVE-2025-67567 Patchstack
5.3 Medium Woffice Core Plugin woffice-core Broken Access Control No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67566 Patchstack
5.3 Medium Rehub Plugin rehub-theme Information Disclosure Sensitive Data Exposure No login needed ≤ 19.9.9.1 Fixed in 19.9.9.2 CVE-2025-67565 Patchstack
5.3 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Sensitive Data Exposure No login needed ≤ 1.51.1 Fixed in 1.52.0 CVE-2025-67564 Patchstack
5.3 Medium Post SMTP Plugin post-smtp Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-67563 Patchstack
5.4 Medium Image Caption Hover Pro Plugin image-caption-hover-pro Broken Access Control ≤ 20.0 Fixed in 20.0 CVE-2025-67562 Patchstack
5.4 Medium Debug Log Viewer Plugin debug-log-viewer Broken Access Control ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-67561 Patchstack
5.4 Medium Listdom Plugin listdom Broken Access Control ≤ 5.0.1 Fixed in 5.1.0 CVE-2025-67560 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67559 Patchstack
5.9 Medium Rencontre Plugin rencontre Cross-Site Scripting ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67558 Patchstack
5.9 Medium WP eBay Product Feeds Plugin ebay-feeds-for-wordpress Cross-Site Scripting ≤ 3.4.9 Fixed in 3.4.10 CVE-2025-67557 Patchstack
5.9 Medium Advanced FAQ Manager Plugin advanced-faq-manager Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67556 Patchstack
5.9 Medium UseStrict's Calendly Embedder Plugin cal-embedder-lite Cross-Site Scripting ≤ 1.1.7.2 Fixed in 1.2 CVE-2025-67555 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only