WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,901–2,950 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 59 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Editor Custom Color Palette Plugin editor-custom-color-palette Broken Access Control ≤ 3.5.6 CVE-2025-57909 Patchstack
6.5 Medium AnyClip Luminous Studio Plugin anyclip-media Cross-Site Scripting ≤ 1.3.3 CVE-2025-57910 Patchstack
5.9 Medium Dialogity Free Live Chat Plugin dialogity-website-chat Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-57912 Patchstack
6.5 Medium Adverts Plugin adverts-click-tracker Cross-Site Scripting ≤ 1.4 CVE-2025-57911 Patchstack
6.5 Medium Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Scripting ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-57913 Patchstack
4.3 Medium TOCHAT.BE Plugin tochat-be Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-57915 Patchstack
4.3 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-57914 Patchstack
4.3 Medium WP System Information Plugin wp-system-info Information Disclosure Sensitive Data Exposure ≤ 1.5 CVE-2025-57916 Patchstack
4.3 Medium Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Broken Access Control ≤ 2.4.8 CVE-2025-57917 Patchstack
5.9 Medium Category Featured Images Extended Plugin category-featured-images-extended Cross-Site Scripting ≤ 1.52 CVE-2025-57920 Patchstack
5.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control No login needed ≤ 23.3 Fixed in 23.4 CVE-2025-57921 Patchstack
5.3 Medium Envíos Coordinadora Woocommerce Plugin coordinadora Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.32 CVE-2025-57922 Patchstack
4.3 Medium Developer Plugin developer Cross-Site Request Forgery No login needed ≤ 1.2.6 CVE-2025-57924 Patchstack
5.3 Medium UK Address Postcode Validation Plugin uk-address-postcode-validation Information Disclosure Sensitive Data Exposure No login needed ≤ 3.9.2 Fixed in 3.10.0 CVE-2025-57923 Patchstack
6.5 Medium Passster Plugin content-protector Cross-Site Scripting ≤ 4.2.18 Fixed in 4.2.19 CVE-2025-57926 Patchstack
5.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Content Injection No login needed ≤ 4.4.3 Fixed in 4.4.4 CVE-2025-57928 Patchstack
4.3 Medium Dashboard Notepad Plugin dashboard-notepad Cross-Site Request Forgery No login needed ≤ 1.42 CVE-2025-57927 Patchstack
5.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57929 Patchstack
4.3 Medium Double the Donation Plugin double-the-donation Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57930 Patchstack
4.3 Medium Piotnet Forms Plugin piotnetforms Cross-Site Request Forgery No login needed ≤ 1.0.30 CVE-2025-57933 Patchstack
6.5 Medium PowerFolio Plugin portfolio-elementor Cross-Site Scripting ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-57932 Patchstack
4.3 Medium LWS Affiliation Plugin lws-affiliation Cross-Site Request Forgery No login needed ≤ 2.3.6 CVE-2025-57934 Patchstack
5.9 Medium Bot Block – Stop Spam Referrals in Google Analytics Plugin bot-block-stop-spam-google-analytics-referrals Cross-Site Scripting Stop Spam Referrals in Google Analytics Plugin <= 2.6 - Cross Site Scripting (XSS) ≤ 2.6 CVE-2025-57935 Patchstack
4.3 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Information Disclosure Sensitive Data Exposure ≤ 2.8.10 Fixed in 2.8.11 CVE-2025-57937 Patchstack
4.3 Medium Subresource Integrity (SRI) Manager Plugin wp-sri Broken Access Control ≤ 0.4.0 CVE-2025-57936 Patchstack
6.5 Medium Easy Hotel Booking Plugin easy-hotel Cross-Site Scripting ≤ 1.9.0 CVE-2025-57938 Patchstack
5.9 Medium Append extensions on Pages Plugin append-extensions-on-pages Cross-Site Scripting ≤ 1.1.2 CVE-2025-57940 Patchstack
5.3 Medium Image Hover Effects – Elementor Addon Plugin image-hover-effects-addon-for-elementor Broken Access Control Elementor Addon Plugin <= 1.4.4 - Broken Access Control No login needed ≤ 1.4.4 CVE-2025-57939 Patchstack
5.9 Medium Append Link on Copy Plugin append-link-on-copy Cross-Site Scripting ≤ 0.2 CVE-2025-57941 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 9.3 Fixed in 9.4 CVE-2025-57942 Patchstack
5.3 Medium Skimlinks Affiliate Marketing Tool Plugin skimlinks Broken Access Control No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-57944 Patchstack
4.4 Medium Skimlinks Affiliate Marketing Tool Plugin skimlinks Server-Side Request Forgery ≤ 1.3.1 CVE-2025-57943 Patchstack
5.9 Medium WP Advanced PDF Plugin wp-advanced-pdf Cross-Site Scripting ≤ 1.1.7 CVE-2025-57945 Patchstack
6.5 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting ≤ 6.3.8 Fixed in 6.3.9 CVE-2025-57947 Patchstack
5.4 Medium payOS Plugin payos Cross-Site Request Forgery No login needed ≤ 1.0.73 CVE-2025-57946 Patchstack
6.5 Medium Directory Pro Plugin directory-pro Cross-Site Scripting ≤ 2.5.5 CVE-2025-57948 Patchstack
5.9 Medium Plugin Security Scanner Plugin plugin-security-scanner Cross-Site Scripting ≤ 2.0.2 CVE-2025-57950 Patchstack
5.4 Medium Ongkoskirim.id Plugin ongkoskirim-id Broken Access Control ≤ 1.0.6 CVE-2025-57949 Patchstack
5.9 Medium SiteNarrator Text-to-Speech Widget Plugin sitespeaker-widget Cross-Site Scripting ≤ 1.9 CVE-2025-57951 Patchstack
5.9 Medium Maps for WP Plugin maps-for-wp Cross-Site Scripting ≤ 1.2.5 CVE-2025-57952 Patchstack
6.5 Medium Poll Maker Plugin poll-maker Cross-Site Scripting ≤ 6.0.2 Fixed in 6.0.3 CVE-2025-57954 Patchstack
6.5 Medium Open User Map Plugin open-user-map Cross-Site Scripting ≤ 1.4.14 Fixed in 1.4.15 CVE-2025-57953 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control ≤ 1.7.0 CVE-2025-57955 Patchstack
5.9 Medium WooMS Plugin wooms Cross-Site Scripting ≤ 9.12 CVE-2025-57956 Patchstack
5.3 Medium WooMS Plugin wooms Broken Access Control No login needed ≤ 9.12 CVE-2025-57957 Patchstack
5.9 Medium Slightly troublesome permalink Plugin slightly-troublesome-permalink Cross-Site Scripting ≤ 1.2.0 CVE-2025-57959 Patchstack
4.3 Medium Travel Map Plugin travelmap-blog Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-57960 Patchstack
5.9 Medium VikRestaurants Plugin vikrestaurants Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-57962 Patchstack
4.3 Medium CoDesigner Plugin woolementor Broken Access Control ≤ 4.29 CVE-2025-57961 Patchstack
6.5 Medium Zoho Billing Plugin zoho-subscriptions Cross-Site Scripting ≤ 4.1 CVE-2025-57963 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only