WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,451–2,500 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 50 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Uncanny Automator Plugin uncanny-automator Information Disclosure Sensitive Data Exposure ≤ 6.10.0 Fixed in 6.10.0 CVE-2025-66056 Patchstack
6.5 Medium Enfold Plugin enfold Cross-Site Scripting ≤ 7.1.2 Fixed in 7.1.3 CVE-2025-66053 Patchstack
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client' ≤ 3.2.9 CVE-2025-10039 Wordfence
6.4 Medium FluentCRM - Marketing Automation Plugin fluent-crm Cross-Site Scripting Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode ≤ 2.9.84 CVE-2025-12935 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Role Removal ≤ 3.3.1 CVE-2025-10054 Wordfence
5.3 Medium Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure No login needed ≤ 2.14.17 CVE-2025-12894 Wordfence
6.4 Medium BrightTALK WordPress Shortcode Plugin brighttalk-wp-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2025-11770 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion ≤ 3.3.0 CVE-2025-12169 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Restore ≤ 3.3.1 CVE-2025-12022 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Empty ≤ 3.3.1 CVE-2025-12085 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Ticket Restore ≤ 3.3.1 CVE-2025-12023 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure No login needed ≤ 4.2.9.4 CVE-2025-11368 Wordfence
4.3 Medium WSChat – WordPress Live Chat Plugin wschat-live-chat Broken Access Control WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 3.1.6 CVE-2025-12751 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions ≤ 1.12.0 CVE-2025-12377 Wordfence
5.3 Medium JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-64384 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64383 Patchstack
4.3 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-64382 Patchstack
6.5 Medium Booking Calendar Plugin booking Cross-Site Scripting ≤ 10.14.7 Fixed in 10.14.8 CVE-2025-64381 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting ≤ 7.3.2 Fixed in 7.4.0 CVE-2025-64380 Patchstack
4.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control ≤ 7.4.0 Fixed in 7.5.0 CVE-2025-64379 Patchstack
5.3 Medium YOP Poll Plugin yop-poll Broken Access Control No login needed ≤ 6.5.38 Fixed in 6.5.39 CVE-2025-64370 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control ≤ 1.3.58 Fixed in 1.3.59 CVE-2025-64369 Patchstack
6.5 Medium Analytics Germanized for Google Analytics Plugin ga-germanized Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-64292 Patchstack
5.3 Medium ChatBot Plugin chatbot Broken Access Control No login needed ≤ 7.3.9 Fixed in 7.4.0 CVE-2025-64277 Patchstack
6.5 Medium Survey Maker Plugin survey-maker Broken Access Control ≤ 5.1.9.4 Fixed in 5.1.9.5 CVE-2025-64276 Patchstack
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.17 Fixed in 2.1.18 CVE-2025-64275 Patchstack
4.3 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Broken Access Control ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-64274 Patchstack
4.3 Medium WP Plugin Manager Plugin wp-plugin-manager Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-64271 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Broken Access Control ≤ 1.2.150 Fixed in 1.2.151 CVE-2025-64269 Patchstack
4.3 Medium WooCommerce Ultimate Points And Rewards Plugin woocommerce-ultimate-points-and-rewards Information Disclosure Sensitive Data Exposure ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-64267 Patchstack
4.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control ≤ 23.2 Fixed in 23.3 CVE-2025-64265 Patchstack
5.9 Medium Popup addon for Ninja Forms Plugin popup-addon-for-ninja-forms Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-64264 Patchstack
5.4 Medium WP Content Pilot Plugin wp-content-pilot Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2025-64263 Patchstack
6.5 Medium Auto Prune Posts Plugin auto-prune-posts Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64262 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack
5.3 Medium Theater Plugin theatre Broken Access Control No login needed ≤ 0.18.8 Fixed in 0.19 CVE-2025-64259 Patchstack
6.4 Medium WordPress Content Flipper Plugin wp-flipper Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11769 Wordfence
6.4 Medium Angel – Fashion Model Agency WordPress CMS Theme Cross-Site Scripting Fashion Model Agency WordPress CMS Theme <= 3.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.2.3 CVE-2025-10295 Wordfence
4.3 Medium WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer Broken Access Control Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure ≤ 7.33 CVE-2025-12732 Wordfence
6.4 Medium Live Photos on Plugin live-photos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.1 CVE-2025-12651 Wordfence
6.4 Medium Nonaki – Drag and Drop Email Template builder and Newsletter Plugin nonaki-email-template-customizer Cross-Site Scripting Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields ≤ 1.0.11 CVE-2025-12644 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion ≤ 1.11.0 CVE-2025-11448 Wordfence
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Broken Access Control ≤ 1.2.1 CVE-2025-62914 Patchstack
6.5 Medium UDesign Core Plugin u-design-core Cross-Site Scripting ≤ 4.14.1 Fixed in 4.14.2 CVE-2025-62051 Patchstack
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control No login needed ≤ 3.5.32 Fixed in 3.5.33 CVE-2025-62049 Patchstack
6.5 Medium TheGem Demo Import (for WPBakery) Plugin thegem-importer Broken Access Control Arbitrary Content Deletion ≤ 5.10.5 Fixed in 5.10.5.2 CVE-2025-62046 Patchstack
6.5 Medium TheGem Theme Elements (for WPBakery) Plugin thegem-elements Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62044 Patchstack
6.5 Medium MeetingHub Plugin meetinghub Information Disclosure Sensitive Data Exposure ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62038 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only