WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 251–300 of 425 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Esselink.nu Settings Plugin esselinknu-settings Cross-Site Request Forgery No login needed ≤ 4.5 CVE-2025-52793 Patchstack
7.1 High WP User Stylesheet Switcher Plugin wp-user-stylesheet-switcher Cross-Site Request Forgery No login needed ≤ v2.2.0 CVE-2025-52792 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Request Forgery No login needed ≤ 5.0.6 CVE-2025-52795 Patchstack
7.1 High Creative Contact Form Plugin sexy-contact-form Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-52794 Patchstack
8.8 High Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-52825 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
7.1 High Konami Easter Egg Plugin konami-easter-egg Cross-Site Request Forgery No login needed ≤ v0.4 CVE-2025-49425 Patchstack
7.1 High BP Profile as Homepage Plugin bp-profile-as-homepage Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1 CVE-2025-49453 Patchstack
7.1 High Post Author Plugin post-author Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28950 Patchstack
7.1 High Free WP Mail SMTP Plugin free-wp-mail-smtp Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-28974 Patchstack
7.1 High Recent Posts Slider Responsive Plugin recent-posts-slider-responsive Cross-Site Request Forgery No login needed ≤ 1.0.1 CVE-2025-28966 Patchstack
7.1 High WP Mail Options Plugin wp-mail-options Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.2.3 CVE-2025-28981 Patchstack
7.1 High Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.0 CVE-2025-30995 Patchstack
7.1 High AWcode Toolkit Plugin awcode-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-48238 Patchstack
7.1 High Affiliates Manager Google reCAPTCHA Integration Plugin affiliates-manager-google-recaptcha-integration Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-48233 Patchstack
7.1 High ShayanWeb Admin FontChanger Plugin shayanweb-admin-fontchanger Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.9.1 Fixed in 1.10 CVE-2025-48114 Patchstack
7.1 High WP2LEADS Plugin wp2leads Cross-Site Request Forgery No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-32922 Patchstack
7.1 High Contribuinte Checkout Plugin contribuinte-checkout Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.03 Fixed in 2.0.04 CVE-2025-47685 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.1 High Martins Free Monetized Ad Exchange Network Plugin martins-free-and-easy-ad-network-get-more-visitors Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-47620 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47546 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
7.1 High ELI's Related Posts Footer Links and Widget Plugin spostarbust Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.04.20 Fixed in 1.2.04.25 CVE-2025-47514 Patchstack
7.4 High Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47491 Patchstack
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed ≤ 0.2.5.4 CVE-2025-1305 Wordfence
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High PayPal Express Checkout Plugin paypal-express-checkout Cross-Site Request Forgery No login needed ≤ 2.1.2 CVE-2025-46499 Patchstack
7.1 High Navegg Analytics Plugin navegg Cross-Site Request Forgery No login needed ≤ 3.3.3 CVE-2025-46497 Patchstack
7.1 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.3.0 CVE-2025-46450 Patchstack
7.5 High WP Headers And Footers Plugin wp-headers-and-footers Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.1.1 CVE-2025-2111 Wordfence
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
7.1 High WP Twitter Button Plugin wp-twitter-button Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-39420 Patchstack
7.1 High WP Social Bookmarking Plugin wp-social-bookmarking Cross-Site Request Forgery No login needed ≤ 3.6 CVE-2025-39422 Patchstack
7.1 High WP Sticky Side Buttons Plugin wp-sticky-side-buttons Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-39421 Patchstack
7.1 High mLanguage Plugin mlanguage Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-39430 Patchstack
7.1 High Bknewsticker Plugin bknewsticker Cross-Site Request Forgery No login needed ≤ 1.0.5 CVE-2025-39433 Patchstack
7.1 High Review Wave – Google Places Reviews Plugin review-wave-google-places-reviews Cross-Site Request Forgery Google Places Reviews plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.4.7 CVE-2025-39442 Patchstack
7.1 High Site Search 360 Plugin site-search-360 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to stored XSS No login needed ≤ 2.1.8 CVE-2025-39530 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-27009 Patchstack
7.1 High Rentsyst Plugin rentsyst Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.92 Fixed in 2.0.93 CVE-2025-32501 Patchstack
7.1 High REVE Chat Plugin revechat Cross-Site Request Forgery No login needed ≤ 6.4.4 CVE-2025-32559 Patchstack
7.1 High Nimbata Call Tracking Plugin nimbata-call-tracking Cross-Site Request Forgery No login needed ≤ 1.7.4 CVE-2025-32616 Patchstack
7.1 High Epeken All Kurir Plugin epeken-all-kurir Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-32673 Patchstack
7.1 High Mergado Pack Plugin mergado-marketing-pack Cross-Site Request Forgery No login needed ≤ 4.2.1 CVE-2025-32669 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only