WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,501–2,550 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 51 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Togo Plugin togo Broken Access Control ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62037 Patchstack
6.5 Medium Togo Plugin togo Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62033 Patchstack
6.5 Medium tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.2 CVE-2025-62032 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62030 Patchstack
4.3 Medium Salient Plugin salient Broken Access Control ≤ 17.4.0 Fixed in 17.4.0 CVE-2025-62028 Patchstack
5.3 Medium KALLYAS Theme kallyas Broken Access Control No login needed ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62018 Patchstack
5.4 Medium KALLYAS Theme kallyas Broken Access Control ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62017 Patchstack
6.5 Medium TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62012 Patchstack
6.5 Medium TheGem Plugin thegem Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62011 Patchstack
6.5 Medium Bux Woocommerce Plugin bux-woocommerce Broken Access Control No login needed ≤ 1.2.3 CVE-2025-60247 Patchstack
4.8 Medium Atarim Plugin atarim-visual-collaboration Arbitrary File Upload No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60187 Patchstack
6.5 Medium Jock On Air Now (JOAN) Plugin joan Broken Access Control ≤ 6.0.4 Fixed in 6.0.5 CVE-2025-58986 Patchstack
5.3 Medium All In One Login Plugin change-wp-admin-login Authentication Bypass Bypass Vulnerability No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-58595 Patchstack
5.3 Medium imEvent Plugin imevent Broken Access Control No login needed ≤ 3.4.0 CVE-2025-58243 Patchstack
5.3 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Broken Access Control No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-5803 Patchstack
6.5 Medium Backup and Move Plugin backup-and-move Broken Access Control ≤ 0.1 CVE-2025-53246 Patchstack
6.5 Medium Sertifier Certificate & Badge Maker Plugin sertifier-certificates-open-badges Broken Access Control ≤ 1.21 CVE-2025-53214 Patchstack
6.5 Medium Easy Appointments Plugin easy-appointments Content Injection No login needed ≤ 3.12.14 Fixed in 3.12.14.1 CVE-2025-49398 Patchstack
5.5 Medium Ajax Search Lite Plugin ajax-search-lite PHP Object Injection ≤ 4.13.3 Fixed in 4.13.4 CVE-2025-48086 Patchstack
4.3 Medium Advanced Google Maps Plugin wp-google-map-gold Broken Access Control ≤ 5.8.4 Fixed in 5.8.5 CVE-2025-39465 Patchstack
4.1 Medium Smush Image Compression and Optimization Plugin wp-smushit Path Traversal Directory Traversal ≤ 3.17.0 Fixed in 3.17.1 CVE-2025-22288 Patchstack
4.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 3.6.4.1 CVE-2025-12469 Wordfence
5.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.6.4.1 CVE-2025-12468 Wordfence
6.1 Medium SMS Plugin sms4wp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2025-12580 Wordfence
4.4 Medium Multi-language Responsive Portfolio Plugin bootstrap-multi-language-responsive-portfolio Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11753 Wordfence
6.4 Medium TablePress – Tables in WordPress made easy Plugin tablepress Cross-Site Scripting Tables in WordPress made easy <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.2.4 CVE-2025-12324 Wordfence
5.3 Medium WP Snow Effect Plugin wp-snow-effect Broken Access Control No login needed ≤ 1.1.19 CVE-2025-64294 Patchstack
4.9 Medium Import WP – Export and Import CSV and XML files to Plugin jc-importer Path Traversal Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read ≤ 2.14.16 CVE-2025-12137 Wordfence
5.3 Medium Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages Plugin wplegalpages Broken Access Control Missing Authorization to Unauthenticated API Disconnect No login needed ≤ 3.5.1 CVE-2025-11816 Wordfence
5.4 Medium Bard Theme bardwp Cross-Site Request Forgery No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64368 Patchstack
6.5 Medium Groundhogg Plugin groundhogg Cross-Site Scripting ≤ 4.2.6 Fixed in 4.2.6.1 CVE-2025-64367 Patchstack
6.5 Medium Ohio Extra Plugin ohio-extra Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-64365 Patchstack
6.5 Medium K Elements Plugin k-elements Cross-Site Scripting ≤ 5.5.0 Fixed in 5.5.0 CVE-2025-64362 Patchstack
6.5 Medium Consulting Elementor Widgets Plugin consulting-elementor-widgets Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-64361 Patchstack
4.3 Medium Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-64358 Patchstack
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-64357 Patchstack
4.3 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Broken Access Control ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64356 Patchstack
6.5 Medium Gutenberg Plugin gutenberg Cross-Site Scripting ≤ 21.8.2 Fixed in 21.9.0 CVE-2025-64354 Patchstack
4.3 Medium Rank Math SEO Plugin seo-by-rank-math Information Disclosure Sensitive Data Exposure ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64351 Patchstack
5.3 Medium OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) Plugin oopspam-anti-spam Other Unauthenticated IP Header Spoofing No login needed ≤ 1.2.53 CVE-2025-12094 Wordfence
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Broken Access Control WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation ≤ 1.1.23.0 CVE-2025-11975 Wordfence
5.3 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Broken Access Control Weglot <= 5.1 - Missing Authorization to Unauthenticated Limited Transient Deletion No login needed ≤ 5.1 CVE-2025-10008 Wordfence
5.9 Medium Premmerce User Roles Plugin premmerce-user-roles Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-64291 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-64283 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-64234 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only