WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 251–300 of 2,543 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Revision Manager TMC | Cross-Site Request Forgery No login needed |
≤ 2.8.22 |
CVE-2026-25411 |
Patchstack | |
| 5.5 Medium | URL Shortify | Server-Side Request Forgery |
≤ 1.12.3 Fixed in 1.12.4 |
CVE-2026-25385 |
Patchstack | |
| 5.4 Medium | Coachify | Cross-Site Request Forgery No login needed |
≤ 1.1.5 Fixed in 1.1.6 |
CVE-2026-25337 |
Patchstack | |
| 5.4 Medium | PublishPress Revisions | Cross-Site Request Forgery No login needed |
≤ 3.7.22 Fixed in 3.7.23 |
CVE-2026-25322 |
Patchstack | |
| 4.3 Medium | Zita Elementor Site Library | Cross-Site Request Forgery No login needed |
≤ 1.6.6 Fixed in 1.6.7 |
CVE-2026-25319 |
Patchstack | |
| 4.9 Medium | Extend Link | Server-Side Request Forgery |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2026-25310 |
Patchstack | |
| 7.2 High | Smart Auto Upload Images | Server-Side Request Forgery |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2026-23803 |
Patchstack | |
| 6.4 Medium | Simple Wp colorfull Accordion | Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via 'title' Shortcode Attribute |
≤ 1.0 |
CVE-2026-1904 |
Wordfence | |
| 8.8 High | Starfish Review Generation & Marketing | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults |
≤ 3.1.19 |
CVE-2025-15157 |
Wordfence | |
| 6.4 Medium | WaveSurfer-WP | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute |
≤ 2.8.3 |
CVE-2026-1909 |
Wordfence | |
| 5.4 Medium | ThirstyAffiliates | Cross-Site Request Forgery No login needed |
≤ 3.11.9 Fixed in 3.11.10 |
CVE-2026-25024 |
Patchstack | |
| 4.3 Medium | UsersWP | Cross-Site Request Forgery No login needed |
≤ 1.2.53 Fixed in 1.2.54 |
CVE-2026-25015 |
Patchstack | |
| 4.3 Medium | Enter Addons | Cross-Site Request Forgery No login needed |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2026-25014 |
Patchstack | |
| 4.3 Medium | WP Custom Admin Interface | Broken Access Control |
≤ 7.41 Fixed in 7.42 |
CVE-2026-25011 |
Patchstack | |
| 5.4 Medium | Simple Membership WP user Import | Cross-Site Request Forgery No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2026-24986 |
Patchstack | |
| 4.3 Medium | Copyscape Premium | Cross-Site Request Forgery No login needed |
≤ 1.4.1 Fixed in 1.4.2 |
CVE-2026-24966 |
Patchstack | |
| 4.3 Medium | Sigmize | Cross-Site Request Forgery No login needed |
≤ 0.0.9 Fixed in 0.0.10 |
CVE-2026-24962 |
Patchstack | |
| 5.4 Medium | Grand Blog | Server-Side Request Forgery No login needed |
≤ 3.1.5 Fixed in 3.1.5 |
CVE-2026-24961 |
Patchstack | |
| 4.3 Medium | WpEvently | Cross-Site Request Forgery No login needed |
≤ 5.1.1 Fixed in 5.1.2 |
CVE-2026-24942 |
Patchstack | |
| 4.3 Medium | Five Star Restaurant Reservations | Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed |
< 2.7.9 Fixed in 2.7.9 |
CVE-2026-0658 |
WPScan | |
| 7.2 High | Sell BTC - Cryptocurrency Selling Calculator | Cross-Site Scripting Cryptocurrency Selling Calculator <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'orderform_data' AJAX Action No login needed |
≤ 1.5 |
CVE-2025-14554 |
Wordfence | |
| 4.3 Medium | Related Posts Thumbnails | Cross-Site Request Forgery No login needed |
≤ 4.3.2 Fixed in 4.3.3 |
CVE-2026-24596 |
Patchstack | |
| 4.3 Medium | GeoDirectory | Cross-Site Request Forgery No login needed |
≤ 2.8.149 Fixed in 2.8.150 |
CVE-2026-24549 |
Patchstack | |
| 5.4 Medium | Radio Player | Server-Side Request Forgery No login needed |
≤ 2.0.91 |
CVE-2026-24548 |
Patchstack | |
| 4.3 Medium | WP Term Order | Cross-Site Request Forgery No login needed |
≤ 2.1.0 Fixed in 2.2.0 |
CVE-2026-24542 |
Patchstack | |
| 4.3 Medium | Kama Thumbnail | Cross-Site Request Forgery No login needed |
≤ 3.5.1 |
CVE-2026-24521 |
Patchstack | |
| 4.3 Medium | Wordpress Movies Bulk Importer | Cross-Site Request Forgery No login needed |
≤ <= 1.0 |
CVE-2026-22359 |
Patchstack | |
| 5.4 Medium | Merge + Minify + Refresh | Cross-Site Request Forgery No login needed |
≤ 2.14 Fixed in 2.15 |
CVE-2026-24384 |
Patchstack | |
| 5.4 Medium | PhotoMe | Server-Side Request Forgery No login needed |
≤ 5.7.2 Fixed in 5.7.2 |
CVE-2026-24381 |
Patchstack | |
| 5.4 Medium | RegistrationMagic | Cross-Site Request Forgery No login needed |
≤ 6.0.6.9 Fixed in 6.0.7.0 |
CVE-2026-24374 |
Patchstack | |
| 5.4 Medium | Stock Manager for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.6.0 Fixed in 3.6.0 |
CVE-2026-24365 |
Patchstack | |
| 4.4 Medium | Seriously Simple Podcasting | Server-Side Request Forgery |
≤ 3.14.1 Fixed in 3.14.2 |
CVE-2026-24360 |
Patchstack | |
| 6.5 Medium | Penci Shortcodes & Performance | Cross-Site Scripting |
≤ 6.1 Fixed in 6.2 |
CVE-2026-24354 |
Patchstack | |
| 5.4 Medium | teachPress | Cross-Site Request Forgery No login needed |
≤ 9.0.12 |
CVE-2026-22483 |
Patchstack | |
| 4.9 Medium | IMGspider | Server-Side Request Forgery |
≤ 2.3.12 |
CVE-2026-22482 |
Patchstack | |
| 4.3 Medium | Add Polylang support for Customizer | Cross-Site Request Forgery No login needed |
≤ 1.4.5 |
CVE-2026-22462 |
Patchstack | |
| 5.4 Medium | PawFriends - Pet Shop and Veterinary | Cross-Site Request Forgery Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3 |
CVE-2026-22382 |
Patchstack | |
| 4.3 Medium | SearchAzon | Cross-Site Request Forgery No login needed |
≤ 1.4 |
CVE-2026-22360 |
Patchstack | |
| 5.4 Medium | Electrician - Electrical Service | Server-Side Request Forgery Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) No login needed |
≤ 5.6 |
CVE-2026-22358 |
Patchstack | |
| 7.1 High | Simple XML Sitemap | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3 |
CVE-2026-22355 |
Patchstack | |
| 7.2 High | Frontis Blocks | Server-Side Request Forgery No login needed |
≤ 1.1.5 Fixed in 1.1.6 |
CVE-2025-68030 |
Patchstack | |
| 6.4 Medium | WPO365 | Server-Side Request Forgery |
≤ 40.0 Fixed in 40.1 |
CVE-2025-67961 |
Patchstack | |
| 4.3 Medium | WP SEO Search | Cross-Site Request Forgery No login needed |
≤ 1.1 Fixed in 1.2 |
CVE-2025-67626 |
Patchstack | |
| 4.9 Medium | ANAC XML Viewer | Server-Side Request Forgery |
≤ 1.8.2 Fixed in 1.8.3 |
CVE-2025-64252 |
Patchstack | |
| 5.4 Medium | Pool Services | Server-Side Request Forgery No login needed |
≤ 3.3 |
CVE-2025-62741 |
Patchstack | |
| 4.3 Medium | Element Pack Elementor Addons | Cross-Site Request Forgery No login needed |
≤ 8.3.13 Fixed in 8.3.14 |
CVE-2025-31413 |
Patchstack | |
| 4.3 Medium | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure |
≤ 4.9.2 |
CVE-2025-14384 |
Wordfence | |
| 5.3 Medium | Perfit WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed |
≤ 1.0.1 |
CVE-2025-14173 |
Wordfence | |
| 4.3 Medium | Clearfy | Cross-Site Request Forgery Cross-Site Request Forgery to Update Notification Tampering No login needed |
≤ 2.4.0 |
CVE-2025-13749 |
Wordfence | |
| 6.4 Medium | nK Themes Helper | Server-Side Request Forgery |
≤ 1.7.9 |
CVE-2025-22726 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.