WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,401–2,450 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 49 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action ≤ 3.3.2 CVE-2025-13534 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification ≤ 2.9.4 CVE-2025-11726 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
6.5 Medium Visualizer: Tables and Charts Manager Plugin visualizer SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.11.12 CVE-2025-12483 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute ≤ 2.2.13 CVE-2025-13697 Wordfence
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.20 CVE-2025-13835 Patchstack
6.5 Medium AI Engine for WordPress: ChatGPT, GPT Content Generator Plugin liquid-chatgpt Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.0.1 CVE-2025-13380 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
6.6 Medium Easy Invoice Plugin easy-invoice Local File Inclusion ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-66115 Patchstack
5.3 Medium Show Variations as Single Products Woocommerce Plugin woo-show-single-variations-shop-category Broken Access Control No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-66114 Patchstack
5.3 Medium Better Chat Support for Messenger Plugin better-chat-support Broken Access Control No login needed ≤ 1.2.18 Fixed in 1.2.19 CVE-2025-66113 Patchstack
4.3 Medium Accessibility Toolkit by WebYes Plugin accessibility-plus Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66112 Patchstack
6.5 Medium Nelio Popups Plugin nelio-popups Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-66111 Patchstack
5.3 Medium Tiktok Feed Plugin b-tiktok-feed Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2025-66110 Patchstack
5.3 Medium Cart Weight for WooCommerce Plugin woo-cart-weight Broken Access Control No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66109 Patchstack
4.3 Medium TNC Toolbox: Web Performance Plugin tnc-toolbox Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66108 Patchstack
5.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-66107 Patchstack
4.3 Medium Featured Post Creative Plugin featured-post-creative Broken Access Control ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-66106 Patchstack
4.3 Medium CBX Bookmark & Favorite Plugin cbxwpbookmark Broken Access Control ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-66101 Patchstack
5.3 Medium Chat Help Plugin chat-help Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-66099 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-66098 Patchstack
4.3 Medium I Order Terms Plugin i-order-terms Cross-Site Request Forgery No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-66097 Patchstack
4.3 Medium Table Block by Tableberg Plugin tableberg Broken Access Control ≤ 0.6.9 Fixed in 0.6.10 CVE-2025-66096 Patchstack
6.5 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting ≤ 4.8 Fixed in 4.9 CVE-2025-66093 Patchstack
6.5 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting ≤ 1.9.13 Fixed in 1.9.14 CVE-2025-66092 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.1.5 Fixed in 8.1.6 CVE-2025-66091 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.5 Fixed in 2.6 CVE-2025-66090 Patchstack
4.3 Medium Product Feed for WooCommerce Plugin webtoffee-product-feed Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-66089 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66087 Patchstack
5.3 Medium SMS Alert Order Notifications Plugin sms-alert Broken Access Control No login needed ≤ 3.8.8 Fixed in 3.8.9 CVE-2025-66086 Patchstack
4.3 Medium Arconix Shortcodes Plugin arconix-shortcodes Broken Access Control ≤ 2.1.18 Fixed in 2.1.19 CVE-2025-66085 Patchstack
4.3 Medium FluentCommunity Plugin fluent-community Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-66084 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66083 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66082 Patchstack
5.9 Medium Head Meta Data Plugin head-meta-data Cross-Site Scripting ≤ 20250327 Fixed in 20251118 CVE-2025-66081 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.2.0 Fixed in 2.3.0 CVE-2025-66079 Patchstack
5.3 Medium Legal Pages Plugin legal-pages Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-66077 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-66075 Patchstack
5.3 Medium UsersWP Plugin userswp Broken Access Control No login needed ≤ 1.2.47 Fixed in 1.2.48 CVE-2025-66072 Patchstack
5.3 Medium Custom Order Numbers for WooCommerce Plugin custom-order-numbers-for-woocommerce Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2025-66071 Patchstack
4.3 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control ≤ 33.0.16 Fixed in 33.0.17 CVE-2025-66069 Patchstack
6.5 Medium Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting ≤ 3.13.1.2 Fixed in 3.13.1.3 CVE-2025-66067 Patchstack
6.5 Medium Envo Extra Plugin envo-extra Cross-Site Scripting ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66066 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Broken Access Control ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-66065 Patchstack
4.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Request Forgery No login needed ≤ 1.12.20 Fixed in 1.12.21 CVE-2025-66064 Patchstack
5.4 Medium WP Google Review Slider Plugin wp-google-places-review-slider Broken Access Control ≤ 17.4 Fixed in 17.6 CVE-2025-66063 Patchstack
4.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Request Forgery No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66061 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Broken Access Control No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66060 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Information Disclosure Sensitive Data Exposure No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66059 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.5.2 Fixed in 5.5.3 CVE-2025-66057 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only