WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,651–2,700 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 54 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium ACF Recent Posts Widget Plugin acf-recent-posts-widget Cross-Site Scripting ≤ 5.9.3 CVE-2025-62894 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-62892 Patchstack
4.3 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Request Forgery No login needed ≤ 0.5.8.5 Fixed in 0.5.9 CVE-2025-62891 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Broken Access Control ≤ 51.1.61 CVE-2025-62889 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.61 CVE-2025-62887 Patchstack
6.5 Medium WP VR Plugin wpvr Cross-Site Scripting ≤ 8.5.48 Fixed in 8.5.49 CVE-2025-62885 Patchstack
5.3 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control No login needed ≤ 7.2.0 Fixed in 7.2.1 CVE-2025-62884 Patchstack
4.3 Medium Premmerce User Roles Plugin premmerce-user-roles Broken Access Control ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-62883 Patchstack
4.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Broken Access Control ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-62882 Patchstack
4.3 Medium WP-Lister Lite for eBay Plugin wp-lister-for-ebay Broken Access Control ≤ 3.8.3 Fixed in 3.8.5 CVE-2025-62881 Patchstack
6.4 Medium The7 — Ultimate WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css' ≤ 12.9.1 CVE-2025-11897 Wordfence
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Cross-Site Request Forgery WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation No login needed ≤ 1.1.23.0 CVE-2025-11976 Wordfence
6.3 Medium Discussion Board – WordPress Forum Plugin Arbitrary Shortcode Execution WordPress Forum Plugin <= 2.5.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 2.5.5 CVE-2025-8483 Wordfence
6.4 Medium Widget Options – The #1 WordPress Widget & Block Control Plugin Cross-Site Scripting The #1 WordPress Widget & Block Control Plugin <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.2 CVE-2025-10580 Wordfence
6.5 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable SQL Injection Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection ≤ 1.8.8.4 CVE-2025-11893 Wordfence
4.3 Medium WP VR – 360 Panorama and Free Virtual Tour Builder Plugin wpvr Broken Access Control Improper Authorization to Authenticated (Contributor+) Plugin Settings Update ≤ 8.5.41 CVE-2025-12005 Wordfence
5.4 Medium Microsoft Azure Storage Plugin windows-azure-storage Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Media Deletion ≤ 4.5.1 CVE-2025-10749 Wordfence
6.4 Medium Time Clock – A WordPress Employee & Volunteer Time Clock Plugin time-clock Cross-Site Scripting A WordPress Employee & Volunteer Time Clock Plugin <= 1.3.1 - Authenticated (Custom+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-10701 Wordfence
6.3 Medium URL Shortener Plugin exact-links Broken Access Control Missing Authorization to Authenticated (Subscriber+) Link Manipulation ≤ 3.0.7 CVE-2025-10740 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.4.6 CVE-2025-10705 Wordfence
4.3 Medium MeetingHub Plugin meetinghub Broken Access Control ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62073 Patchstack
4.3 Medium Front End Users Plugin front-end-only-users Broken Access Control ≤ 3.2.33 Fixed in 3.2.34 CVE-2025-62072 Patchstack
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.29 Fixed in 5.30 CVE-2025-62071 Patchstack
4.3 Medium WowRevenue Plugin revenue Broken Access Control ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62070 Patchstack
6.5 Medium MDTF Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting ≤ 1.3.3.8 Fixed in 1.3.3.9 CVE-2025-62069 Patchstack
6.5 Medium e2pdf Plugin e2pdf Cross-Site Scripting ≤ 1.28.09 Fixed in 1.28.10 CVE-2025-62068 Patchstack
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-62063 Patchstack
5.3 Medium Easy Post Submission Plugin easy-post-submission Information Disclosure Sensitive Data Exposure ≤ 1.7.0 Fixed in 2.0.0 CVE-2025-62062 Patchstack
4.3 Medium Product Catalog Simple Plugin post-type-x Cross-Site Request Forgery No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-62061 Patchstack
6.5 Medium Tab Ultimate Plugin tabs-pro Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-62060 Patchstack
6.5 Medium Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62058 Patchstack
4.3 Medium One Page Express Companion Plugin one-page-express-companion Broken Access Control ≤ 1.6.43 Fixed in 1.6.44 CVE-2025-62052 Patchstack
5.4 Medium SmartCrawl Plugin smartcrawl-seo Broken Access Control ≤ 3.14.3 Fixed in 3.14.4 CVE-2025-62048 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.10.3 Fixed in 5.10.4 CVE-2025-62042 Patchstack
5.4 Medium Event Tickets Plugin event-tickets Broken Access Control ≤ 5.26.3 Fixed in 5.26.4 CVE-2025-62027 Patchstack
4.3 Medium Blockspare Plugin blockspare Information Disclosure Sensitive Data Exposure ≤ 3.2.13.2 Fixed in 3.2.14 CVE-2025-62026 Patchstack
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-62024 Patchstack
4.3 Medium Acknowledgify Plugin acknowledgify Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-62021 Patchstack
6.5 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2025-62019 Patchstack
4.3 Medium UiChemy Plugin uichemy Broken Access Control ≤ 4.0.0 Fixed in 4.0.1 CVE-2025-62013 Patchstack
4.3 Medium UPC/EAN/GTIN Code Generator Plugin upc-ean-barcode-generator Cross-Site Request Forgery No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-62009 Patchstack
5.4 Medium WP SMS Plugin wp-sms Broken Access Control ≤ 7.0.1 Fixed in 7.0.2 CVE-2025-62006 Patchstack
5.9 Medium WP Tesseract Plugin wp-tesseract Cross-Site Scripting ≤ 1.0.2 CVE-2025-60176 Patchstack
4.7 Medium WP Gravity Forms HubSpot Plugin gf-hubspot Open Redirect No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-60151 Patchstack
5.9 Medium WeShare Buttons Plugin e-mailit Cross-Site Scripting ≤ 13.0.0 CVE-2025-60135 Patchstack
4.3 Medium WP Media Categories Plugin wp-media-categories Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-60134 Patchstack
5.9 Medium Werk aan de Muur Plugin werk-aan-de-muur Cross-Site Scripting ≤ 1.5 Fixed in 1.5.1 CVE-2025-60131 Patchstack
5.9 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.334 Fixed in 1.0.334 CVE-2025-59593 Patchstack
5.8 Medium ShopMagic Plugin shopmagic-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-59578 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only