WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,751–2,800 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 56 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Auto Bulb Finder Plugin auto-bulb-finder-for-wp-wc Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2025-9858 Wordfence
6.1 Medium LockerPress – WordPress Security Plugin lockerpress-wordpress-security Cross-Site Request Forgery WordPress Security Plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9946 Wordfence
6.4 Medium WeedMaps Menu Plugin weedmaps-menu-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via weedmaps_menu Shortcode ≤ 1.2.0 CVE-2025-8623 Wordfence
5.9 Medium Google+ Comments Plugin google-plus-comments Cross-Site Scripting ≤ 1.0 CVE-2025-60186 Patchstack
5.9 Medium kontur Admin Style Plugin kontur-admin-style Cross-Site Scripting ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-60185 Patchstack
5.9 Medium SEO Search Permalink Plugin seo-search-permalink Cross-Site Scripting ≤ 1.0.3 CVE-2025-60184 Patchstack
5.4 Medium Silencesoft RSS Reader Plugin external-rss-reader Server-Side Request Forgery No login needed ≤ 0.6 CVE-2025-60181 Patchstack
5.9 Medium Click & Tweet Plugin click-tweet Cross-Site Scripting ≤ 0.8.9 CVE-2025-60179 Patchstack
5.9 Medium Recaptcha – wp Plugin recaptcha-wp Cross-Site Scripting wp Plugin <= 0.2.6 - Cross Site Scripting (XSS) ≤ 0.2.6 CVE-2025-60177 Patchstack
4.3 Medium Page Manager for Elementor Plugin page-manager-for-elementor Information Disclosure Sensitive Data Exposure ≤ 2.0.5 CVE-2025-60167 Patchstack
4.3 Medium WP Subscription Forms PRO Plugin wp-subscription-forms-pro Broken Access Control Arbitrary Content Deletion ≤ 2.0.5 CVE-2025-60166 Patchstack
4.3 Medium Frames Plugin frames Broken Access Control ≤ 1.5.7 CVE-2025-60165 Patchstack
6.5 Medium bbp topic count Plugin bbp-topic-count Cross-Site Scripting ≤ 3.2 CVE-2025-60163 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.61 CVE-2025-60162 Patchstack
5.4 Medium ZoloBlocks Plugin zoloblocks Server-Side Request Forgery No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-60161 Patchstack
5.9 Medium Smart Related Products Plugin ai-related-products Cross-Site Scripting ≤ 2.0.8 CVE-2025-60160 Patchstack
4.3 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Broken Access Control ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60159 Patchstack
5.9 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Cross-Site Scripting ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60158 Patchstack
6.5 Medium WP Ticket Customer Service Software & Support Ticket System Plugin wp-ticket Cross-Site Scripting ≤ 6.0.2 Fixed in 6.0.3 CVE-2025-60157 Patchstack
5.3 Medium WP Virtual Assistant Plugin virtualassistant Broken Access Control No login needed ≤ 3.0 CVE-2025-60155 Patchstack
5.9 Medium MWW Disclaimer Buttons Plugin mww-disclaimer-buttons Cross-Site Scripting ≤ 3.41 Fixed in 3.5 CVE-2025-60154 Patchstack
4.3 Medium Subscribe To Unlock Plugin subscribe-to-unlock Broken Access Control ≤ 1.1.5 CVE-2025-60152 Patchstack
5.9 Medium Notely Plugin notely Cross-Site Scripting ≤ 1.8.0 Fixed in 1.9.0 CVE-2025-60149 Patchstack
4.3 Medium Subscribe to Download Plugin subscribe-to-download Broken Access Control ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60148 Patchstack
6.5 Medium HT Feed Plugin ht-instagram Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-60147 Patchstack
5.9 Medium Map Categories to Pages Plugin map-categories-to-pages Cross-Site Scripting ≤ 1.3.2 CVE-2025-60146 Patchstack
4.3 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60145 Patchstack
5.9 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Scripting ≤ 1.2 CVE-2025-60144 Patchstack
4.3 Medium Netgsm Plugin netgsm Broken Access Control ≤ 2.9.69 CVE-2025-60143 Patchstack
6.5 Medium Simple Meta Tags Plugin simple-meta-tags Cross-Site Scripting ≤ 1.5 CVE-2025-60142 Patchstack
5.9 Medium The Tribal Plugin the-tech-tribe Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-60141 Patchstack
5.3 Medium The Tribal Plugin the-tech-tribe Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-60140 Patchstack
4.3 Medium Sendle Shipping Plugin official-sendle-shipping-method Cross-Site Request Forgery No login needed ≤ 6.02 Fixed in 6.03 CVE-2025-60139 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting ≤ 2.6 CVE-2025-60138 Patchstack
4.3 Medium Post Featured Video Plugin post-featured-video Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-60137 Patchstack
5.9 Medium User Notes Plugin user-notes Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-60136 Patchstack
5.9 Medium PE Easy Slider Plugin pe-easy-slider Cross-Site Scripting ≤ 1.1.0 CVE-2025-60133 Patchstack
5.3 Medium WEDOS Global Plugin wgpwpp Broken Access Control No login needed ≤ 1.2.2 CVE-2025-60130 Patchstack
5.3 Medium Yext Plugin yext Broken Access Control No login needed ≤ 1.1.3 CVE-2025-60129 Patchstack
4.3 Medium Delisho Plugin dr-widgets-blocks Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60128 Patchstack
5.4 Medium CopySafe Web Protection Plugin wp-copysafe-web Broken Access Control ≤ 5.1 Fixed in 5.2 CVE-2025-60127 Patchstack
5.3 Medium FoodBook Plugin foodbook Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.6 Fixed in 4.7.7 CVE-2025-60125 Patchstack
6.5 Medium Simple Colorbox Plugin simple-colorbox Cross-Site Scripting ≤ 1.6.1 CVE-2025-60124 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60123 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.4 CVE-2025-60122 Patchstack
5.3 Medium WooEvents Plugin woo-events Broken Access Control No login needed ≤ 4.1.7 Fixed in 4.1.8 CVE-2025-60121 Patchstack
5.3 Medium CoSchedule Plugin coschedule-by-todaymade Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.11 Fixed in 3.4.0 CVE-2025-60119 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-60120 Patchstack
4.3 Medium Vehica Core Plugin vehica-core Cross-Site Request Forgery No login needed ≤ 1.0.100 Fixed in 1.0.101 CVE-2025-60117 Patchstack
5.4 Medium Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Broken Access Control ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-60116 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only