WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,801–2,850 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 57 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Yext Plugin yext Broken Access Control No login needed ≤ 1.1.3 CVE-2025-60129 Patchstack
4.3 Medium Delisho Plugin dr-widgets-blocks Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60128 Patchstack
5.4 Medium CopySafe Web Protection Plugin wp-copysafe-web Broken Access Control ≤ 5.1 Fixed in 5.2 CVE-2025-60127 Patchstack
5.3 Medium FoodBook Plugin foodbook Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.6 Fixed in 4.7.7 CVE-2025-60125 Patchstack
6.5 Medium Simple Colorbox Plugin simple-colorbox Cross-Site Scripting ≤ 1.6.1 CVE-2025-60124 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60123 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.4 CVE-2025-60122 Patchstack
5.3 Medium WooEvents Plugin woo-events Broken Access Control No login needed ≤ 4.1.7 Fixed in 4.1.8 CVE-2025-60121 Patchstack
5.3 Medium CoSchedule Plugin coschedule-by-todaymade Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.11 Fixed in 3.4.0 CVE-2025-60119 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-60120 Patchstack
4.3 Medium Vehica Core Plugin vehica-core Cross-Site Request Forgery No login needed ≤ 1.0.100 Fixed in 1.0.101 CVE-2025-60117 Patchstack
5.4 Medium Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Broken Access Control ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-60116 Patchstack
4.3 Medium Instapage Plugin instapage Cross-Site Request Forgery No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2025-60115 Patchstack
6.6 Medium YayCurrency Plugin yaycurrency Remote Code Execution ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-60114 Patchstack
4.3 Medium Groovy Menu Plugin groovy-menu-free Cross-Site Request Forgery No login needed ≤ 1.4.3 CVE-2025-60113 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-60112 Patchstack
4.9 Medium EmailKit Plugin emailkit Broken Access Control Arbitrary Content Deletion ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-60106 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.58 Fixed in 3.1.59 CVE-2025-60105 Patchstack
5.9 Medium Gallery Custom Links Plugin gallery-custom-links Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-60104 Patchstack
5.4 Medium ListingPro Plugin listingpro-plugin Broken Access Control ≤ 2.9.8 CVE-2025-60103 Patchstack
6.5 Medium WPFront User Role Editor Plugin wpfront-user-role-editor Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-60102 Patchstack
6.5 Medium Embed Any Document Plugin embed-any-document Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-60099 Patchstack
5.3 Medium XStore Theme xstore Content Injection No login needed ≤ 9.6 Fixed in 9.6 CVE-2025-60100 Patchstack
5.9 Medium Woostify Plugin woostify Cross-Site Scripting ≤ 2.4.2 CVE-2025-60101 Patchstack
6.5 Medium Theme My Login Plugin theme-my-login Broken Access Control No login needed ≤ 7.1.12 Fixed in 7.1.13 CVE-2025-60098 Patchstack
5.4 Medium TheGem Plugin thegem Broken Access Control ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-60097 Patchstack
5.4 Medium TheGem (Elementor) Plugin thegem-elementor Broken Access Control ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-60096 Patchstack
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Information Disclosure Sensitive Data Exposure ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60095 Patchstack
4.3 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Broken Access Control ≤ 3.18.1 Fixed in 3.19.0 CVE-2025-60094 Patchstack
4.3 Medium Download Manager Plugin download-manager Cross-Site Request Forgery No login needed ≤ 3.3.24 Fixed in 3.3.25 CVE-2025-60093 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.25 Fixed in 3.3.26 CVE-2025-60092 Patchstack
6.5 Medium wp-mpdf Plugin wp-mpdf Cross-Site Scripting ≤ 3.9.1 Fixed in 3.9.2 CVE-2025-60040 Patchstack
6.5 Medium Authorsy Plugin authorsy Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-27006 Patchstack
4.3 Medium Di Themes Demo Site Importer Plugin di-themes-demo-site-importer Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Plugin Activation No login needed ≤ 1.2 CVE-2025-58914 Patchstack
6.5 Medium Acclectic Media Organizer Plugin acclectic-media-organizer Broken Access Control ≤ 1.4 CVE-2025-48326 Patchstack
5.3 Medium Wide Banner Plugin wide-banner Broken Access Control No login needed ≤ 1.0.4 CVE-2025-58919 Patchstack
6.5 Medium Quantities and Units for WooCommerce Plugin quantities-and-units-for-woocommerce Cross-Site Scripting ≤ 1.0.13 CVE-2025-58917 Patchstack
5.9 Medium WordPress Core Cross-Site Scripting (Author+) Cross Site Scripting (XSS) 6.8 – 6.8.2, 6.7 – 6.7.3, 6.6 – 6.6.3, … Fixed in 6.8.3 CVE-2025-58674 Patchstack
4.3 Medium WordPress Core Information Disclosure (Contributor+) Sensitive Data Exposure 6.8 – 6.8.2, 6.7 – 6.7.3, 6.6 – 6.6.3, … Fixed in 6.8.3 CVE-2025-58246 Patchstack
6.5 Medium Request a Quote Plugin request-a-quote Cross-Site Scripting ≤ 2.5.0 Fixed in 2.5.1 CVE-2025-58915 Patchstack
4.3 Medium VPSUForm Plugin v-form Broken Access Control ≤ 3.2.20 Fixed in 3.2.21 CVE-2025-58957 Patchstack
6.4 Medium Publitio Plugin publitio Server-Side Request Forgery ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-58962 Patchstack
5.9 Medium IP Based Login Plugin ip-based-login Cross-Site Scripting ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-58960 Patchstack
6.5 Medium Fusion Page Builder : Extension – Gallery Plugin fusion-extension-gallery Cross-Site Scripting Gallery Plugin <= 1.7.6 - Cross Site Scripting (XSS) ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-58965 Patchstack
5.0 Medium MaxiBlocks Plugin maxi-blocks Broken Access Control ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-58968 Patchstack
5.3 Medium Custom Login URL Plugin custom-login-url Broken Access Control No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-58969 Patchstack
6.5 Medium WPComplete Plugin wpcomplete Cross-Site Scripting ≤ 2.9.5.2 Fixed in 2.9.5.3 CVE-2025-58974 Patchstack
6.5 Medium Product Catalog Simple Plugin post-type-x Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-58992 Patchstack
4.3 Medium Revive.so Plugin revive-so Broken Access Control ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-59551 Patchstack
6.5 Medium GetResponse Forms Plugin getresponse Cross-Site Scripting ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-59549 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only