WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 201–250 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.3 Low Sticky Side Buttons Plugin sticky-side-buttons Cross-Site Scripting Admin+ Stored XSS < 2.0.0 Fixed in 2.0.0 CVE-2023-3666 WPScan
3.8 Low Quttera Web Malware Scanner Plugin quttera-web-malware-scanner Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 3.5.1.41 CVE-2025-8013 Wordfence
3.4 Low Advanced Custom Fields Plugin Content Injection An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page… prior to 6.4.3 CVE-2025-54940 jpcert
3.7 Low Soumettre.fr Plugin soumettre-fr Broken Access Control Improper Authorization to Unauthenticated Soumettre Posts Creation/Modification/Deletion No login needed ≤ 2.1.5 CVE-2025-4654 Wordfence
3.5 Low Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Cross-Site Scripting Admin+ Stored XSS < 2.3.8 Fixed in 2.3.8 CVE-2024-6711 WPScan
3.5 Low Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS < 2.3.15 Fixed in 2.3.15 CVE-2024-4091 WPScan
3.5 Low Advanced Cron Manager Plugin advanced-cron-manager Cross-Site Scripting Admin+ Stored XSS < 2.5.7 Fixed in 2.5.7 CVE-2024-4004 WPScan
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Editor+ Stored XSS < 2.6.9 Fixed in 2.6.9 CVE-2024-4002 WPScan
3.5 Low Post Grid, Post Carousel, & List Category Posts Plugin Cross-Site Scripting Editor+ Stored XSS < 2.4.28 Fixed in 2.4.28 CVE-2024-3996 WPScan
3.5 Low BuddyBoss platform Plugin Broken Access Control Private Comment Exposure via IDOR < 2.7.60 Fixed in 2.7.60 CVE-2024-12767 WPScan
3.5 Low TwitterPosts Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 1.0.2 CVE-2023-7297 WPScan
3.7 Low Simple Job Board Plugin simple-job-board Other Unauthenticated Resumes Download No login needed < 2.12.6 Fixed in 2.12.6 CVE-2024-7762 WPScan
3.5 Low Real WP Shop Lite Ajax eCommerce Shopping Cart Plugin real-wp-shop-lite Cross-Site Scripting Admin+ Stored XSS ≤ 2.0.8 CVE-2024-11140 WPScan
2.7 Low ApplyOnline – Application Form Builder and Manager Plugin apply-online Broken Access Control Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access < 2.6.3 Fixed in 2.6.3 CVE-2024-10098 WPScan
3.5 Low Newsletter Plugin newsletter Cross-Site Scripting Admin+ Stored XSS < 8.7.1 Fixed in 8.7.1 CVE-2025-3583 WPScan
3.5 Low SureForms Plugin sureforms Cross-Site Scripting Admin+ Stored XSS < 1.4.4 Fixed in 1.4.4 CVE-2025-3514 WPScan
3.5 Low SureForms Plugin sureforms Cross-Site Scripting Admin+ Stored XSS < 1.4.4 Fixed in 1.4.4 CVE-2025-3513 WPScan
3.5 Low WP Maps Plugin wp-google-map-plugin Cross-Site Scripting Admin+ Stored XSS < 4.7.2 Fixed in 4.7.2 CVE-2025-3504 WPScan
3.5 Low WP Maps Plugin wp-google-map-plugin Cross-Site Scripting Admin+ Stored XSS < 4.7.2 Fixed in 4.7.2 CVE-2025-3502 WPScan
3.5 Low Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Admin+ Stored XSS < 5.2.62 Fixed in 5.2.62 CVE-2024-13381 WPScan
3.5 Low Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Admin+ Stored XSS < 5.2.62 Fixed in 5.2.62 CVE-2024-12273 WPScan
3.5 Low AI Autotagger Plugin Cross-Site Scripting Admin+ Stored XSS < 3.30.0 Fixed in 3.30.0 CVE-2025-0627 WPScan
3.5 Low WP-Recall Plugin Cross-Site Scripting Admin+ Stored XSS < 16.26.12 Fixed in 16.26.12 CVE-2024-9771 WPScan
3.5 Low Ultimate Dashboard Plugin ultimate-dashboard Cross-Site Scripting Admin+ Stored XSS < 3.8.6 Fixed in 3.8.6 CVE-2025-1525 WPScan
3.5 Low Ultimate Dashboard Plugin ultimate-dashboard Cross-Site Scripting Admin+ Stored XSS < 3.8.6 Fixed in 3.8.6 CVE-2025-1524 WPScan
3.5 Low Ultimate Dashboard Plugin ultimate-dashboard Cross-Site Scripting Admin+ Stored XSS < 3.8.6 Fixed in 3.8.6 CVE-2025-1523 WPScan
3.5 Low Email Subscribers Plugin Cross-Site Scripting Admin+ Stored XSS < 5.7.52 Fixed in 5.7.52 CVE-2024-11924 WPScan
2.7 Low Piotnet Forms Plugin piotnetforms Path Traversal ≤ 1.0.30 CVE-2025-32205 Patchstack
2.7 Low Squeeze Plugin squeeze Information Disclosure Full Path Disclosure (FPD) ≤ 1.6 Fixed in 1.6.1 CVE-2025-31003 Patchstack
2.7 Low Quiz Cat Plugin quiz-cat Broken Access Control ≤ 3.0.8 Fixed in 3.0.9 CVE-2025-30877 Patchstack
2.7 Low Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.5.0 CVE-2025-1911 Wordfence
3.5 Low Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Scripting Admin+ Stored XSS < 1.5.2 Fixed in 1.5.2 CVE-2024-12683 WPScan
3.5 Low Favorites Plugin favorites Cross-Site Scripting Admin+ Stored XSS < 2.3.5 Fixed in 2.3.5 CVE-2025-1452 WPScan
3.5 Low AFI Plugin Cross-Site Scripting Admin+ Stored XSS < 1.100.0 Fixed in 1.100.0 CVE-2024-13123 WPScan
3.5 Low AFI Plugin Cross-Site Scripting Admin+ Stored XSS < 1.100.0 Fixed in 1.100.0 CVE-2024-13122 WPScan
3.5 Low Simple Banner Plugin simple-banner Cross-Site Scripting Admin+ Stored XSS < 3.0.4 Fixed in 3.0.4 CVE-2024-12769 WPScan
3.5 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.30 Fixed in 1.15.30 CVE-2024-10560 WPScan
3.5 Low WP-Advanced-Search Plugin Cross-Site Scripting Admin+ Stored XSS < 3.3.9.3 Fixed in 3.3.9.3 CVE-2024-10554 WPScan
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1203 WPScan
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1062 WPScan
3.5 Low Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.33 Fixed in 1.8.33 CVE-2024-13124 WPScan
3.5 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.30 Fixed in 1.15.30 CVE-2024-10558 WPScan
2.7 Low Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.2 CVE-2025-1972 Wordfence
2.7 Low Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.0 CVE-2024-13922 Wordfence
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.9 Fixed in 4.15.9 CVE-2025-1624 WPScan
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.9 Fixed in 4.15.9 CVE-2025-1623 WPScan
3.5 Low GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Scripting Admin+ Stored XSS < 4.15.7 Fixed in 4.15.7 CVE-2025-1622 WPScan
3.5 Low Social Media Plugin by Social Snap Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.3.6 CVE-2024-13615 WPScan
3.5 Low easy-broken-link-checker Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 9.0.2 CVE-2025-1363 WPScan
3.8 Low Filebird Plugin filebird Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.2.1 Fixed in 6.4.6 CVE-2025-26977 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only