WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 251–300 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Best Posts Summary Plugin best-posts-summary Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-39374 Patchstack
7.1 High AWcode Toolkit Plugin awcode-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-48238 Patchstack
7.1 High Affiliates Manager Google reCAPTCHA Integration Plugin affiliates-manager-google-recaptcha-integration Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-48233 Patchstack
7.1 High CSS3 Accordions Plugin css3_accordions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-31922 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) ≤ 1.25 CVE-2025-32245 Patchstack
8.8 High QuickCal - Appointment Booking Calendar Plugin quickcal Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32310 Patchstack
7.1 High SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.1 Fixed in 3.0.0 CVE-2025-48146 Patchstack
7.1 High Import Export For WooCommerce Plugin import-export-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.2 CVE-2025-48144 Patchstack
7.1 High ShayanWeb Admin FontChanger Plugin shayanweb-admin-fontchanger Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.9.1 Fixed in 1.10 CVE-2025-48114 Patchstack
7.1 High Marketing Twitter Bot Plugin Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed ≤ 1.11 CVE-2023-7197 WPScan
7.1 High aBitGone CommentSafe Plugin Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2023-7174 WPScan
7.3 High Travelpayouts Plugin travelpayouts Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.1.13 Fixed in 1.1.13 CVE-2023-5934 WPScan
8.1 High Offload Videos – Bunny.net, AWS S3 Plugin offload-videos-bunny-netaws-s3 Cross-Site Request Forgery Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF No login needed < 1.0.1 Fixed in 1.0.1 CVE-2024-6719 WPScan
7.1 High WP2LEADS Plugin wp2leads Cross-Site Request Forgery No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-32922 Patchstack
7.1 High Contribuinte Checkout Plugin contribuinte-checkout Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.03 Fixed in 2.0.04 CVE-2025-47685 Patchstack
7.1 High theMarketer Plugin themarketer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47655 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.1 High Supertext Translation and Proofreading Plugin polylang-supertext Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.26 CVE-2025-47639 Patchstack
7.1 High Martins Free Monetized Ad Exchange Network Plugin martins-free-and-easy-ad-network-get-more-visitors Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-47620 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47546 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
7.1 High Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2025-47517 Patchstack
7.1 High ELI's Related Posts Footer Links and Widget Plugin spostarbust Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.04.20 Fixed in 1.2.04.25 CVE-2025-47514 Patchstack
7.4 High Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47491 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
7.1 High Loan Calculator Plugin repayment-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-46442 Patchstack
7.1 High Wp Custom CMS Block Plugin wp-custom-cms-block Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-46457 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High Milat jQuery Automatic Popup Plugin milat-jquery-automatic-popup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2025-46514 Patchstack
7.1 High Custom Functions Plugin custom-functions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-46512 Patchstack
7.1 High Contact Form 7 Calendar Plugin cf7-calendar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.1 CVE-2025-46510 Patchstack
7.1 High Advanced lazy load Plugin advanced-lazy-load Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.0 CVE-2025-46508 Patchstack
7.1 High WpZon – Amazon Affiliate Plugin wpzon Cross-Site Request Forgery Amazon Affiliate Plugin plugin <= 1.3 - CSRF to XSS No login needed ≤ 1.3 CVE-2025-46506 Patchstack
7.1 High Vasaio QR Code Plugin vasaio-qr-code Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.2.5 CVE-2025-46504 Patchstack
7.1 High LSD Custom taxonomy and category meta Plugin custom-taxonomy-category-and-term-fields Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.2 CVE-2025-46502 Patchstack
7.1 High PayPal Express Checkout Plugin paypal-express-checkout Cross-Site Request Forgery No login needed ≤ 2.1.2 CVE-2025-46499 Patchstack
7.1 High Navegg Analytics Plugin navegg Cross-Site Request Forgery No login needed ≤ 3.3.3 CVE-2025-46497 Patchstack
7.1 High Call Now PHT Blog Plugin call-now-coccoc-pht-blog Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.4.1 CVE-2025-46492 Patchstack
7.1 High Modern Polls Plugin modern-polls Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.10 CVE-2025-46466 Patchstack
7.1 High Print Science Designer Plugin print-science-designer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.155 CVE-2025-46465 Patchstack
7.1 High Google News Plugin google-news Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-46452 Patchstack
7.1 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.3.0 CVE-2025-46450 Patchstack
7.4 High Plugin Central Plugin plugin-central Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.5.1 CVE-2025-46439 Patchstack
7.1 High Time Based Greeting Plugin time-based-greeting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-46435 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only