WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,351–2,400 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 48 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting ≤ 2.5.8 Fixed in 2.5.9 CVE-2025-67554 Patchstack
6.5 Medium Advanced FAQ Manager Plugin advanced-faq-manager Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67553 Patchstack
6.5 Medium Walker Core Plugin walker-core Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2025-67552 Patchstack
6.5 Medium Wappointment Plugin wappointment Cross-Site Scripting ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-67551 Patchstack
6.5 Medium Donation Thermometer Plugin donation-thermometer Cross-Site Scripting ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-67550 Patchstack
6.5 Medium oik Plugin oik Cross-Site Scripting ≤ 4.15.3 Fixed in 4.15.4 CVE-2025-67549 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Broken Access Control ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-67548 Patchstack
6.5 Medium FireBox Plugin firebox Cross-Site Scripting ≤ 3.1.0-free Fixed in 3.1.1-free CVE-2025-67545 Patchstack
6.5 Medium Shopkeeper Extender Plugin shopkeeper-extender Cross-Site Scripting ≤ 7.0 Fixed in 7.0 CVE-2025-67544 Patchstack
6.5 Medium Essential Widgets Plugin essential-widgets Cross-Site Scripting ≤ 2.2.2 Fixed in 2.3 CVE-2025-67543 Patchstack
6.5 Medium Multi-Step Checkout for WooCommerce Plugin wp-multi-step-checkout Cross-Site Scripting ≤ 2.33 Fixed in 2.34 CVE-2025-67542 Patchstack
6.5 Medium WP-ShowHide Plugin wp-showhide Cross-Site Scripting ≤ 1.05 Fixed in 1.06 CVE-2025-67541 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Broken Access Control Arbitrary Content Deletion ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-67540 Patchstack
6.5 Medium Select Core Plugin select-core Cross-Site Scripting ≤ 2.6 Fixed in 2.6 CVE-2025-67539 Patchstack
6.5 Medium JNews Gallery Plugin jnews-gallery Cross-Site Scripting ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67538 Patchstack
6.5 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Scripting ≤ 3.11.8 Fixed in 3.11.9 CVE-2025-67537 Patchstack
6.5 Medium LearnPress Plugin learnpress Cross-Site Scripting ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-67536 Patchstack
6.6 Medium WP Maps Plugin wp-google-map-plugin PHP Object Injection ≤ 4.8.6 Fixed in 4.8.7 CVE-2025-67535 Patchstack
4.3 Medium ForumWP Plugin forumwp Broken Access Control ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-67474 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium Portfolio and Projects Plugin portfolio-and-projects Information Disclosure Sensitive Data Exposure ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-67470 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-67468 Patchstack
4.3 Medium Trinity Audio Plugin trinity-audio Broken Access Control ≤ 5.23.3 Fixed in 5.24 CVE-2025-67466 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium The Aisle Theme theaisle Broken Access Control ≤ 2.9 Fixed in 2.9.1 CVE-2025-66534 Patchstack
4.3 Medium Powerlift Theme powerlift Broken Access Control ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-66532 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-66530 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Lobo Theme lobo Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-66527 Patchstack
4.3 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.34 Fixed in 1.1.35.1 CVE-2025-66526 Patchstack
4.3 Medium Elastic Email Sender Plugin elastic-email-sender Broken Access Control ≤ 1.2.20 Fixed in 1.2.21 CVE-2025-66525 Patchstack
4.3 Medium My Tickets Plugin my-tickets Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-64257 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Information Disclosure WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.9.4 CVE-2025-12558 Wordfence
6.4 Medium Yet Another WebClap Plugin yet-another-webclap-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.2 CVE-2025-13857 Wordfence
4.3 Medium Listar – Directory Listing & Classifieds Plugin listar-directory-listing Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Listing Update ≤ 3.0.0 CVE-2025-12577 Wordfence
4.3 Medium Listar – Directory Listing & Classifieds Plugin listar-directory-listing Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 3.0.0 CVE-2025-12574 Wordfence
5.3 Medium Projectopia – WordPress Project Management Plugin projectopia-core Broken Access Control WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 5.1.19 CVE-2025-12876 Wordfence
6.4 Medium Sermon Manager Plugin sermon-manager-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.30.0 CVE-2025-12368 Wordfence
4.4 Medium FitVids Plugin fitvids-for-wordpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.0.1 CVE-2025-12124 Wordfence
5.3 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed ≤ 1.1.5 CVE-2025-13006 Wordfence
6.4 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.5 CVE-2025-12417 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering ≤ 2.9.4 CVE-2025-12782 Wordfence
5.3 Medium Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed ≤ 2.3.8 CVE-2025-10304 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed ≤ 2.5.5 CVE-2025-12585 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only