WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 251–300 of 1,491 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63012 Patchstack
4.9 Medium Hercules Core Plugin hercules-core Server-Side Request Forgery ≤ 7.4 CVE-2025-63010 Patchstack
4.3 Medium WP Flashy Marketing Automation Plugin wp-flashy-marketing-automation Cross-Site Request Forgery No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-62873 Patchstack
4.3 Medium Social Photo Fetcher Plugin facebook-photo-fetcher Cross-Site Request Forgery No login needed ≤ 3.0.4 CVE-2025-62872 Patchstack
4.3 Medium Just TinyMCE Custom Styles Plugin just-tinymce-styles Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-62871 Patchstack
4.3 Medium Auto Alt Text Plugin auto-alt-text Cross-Site Request Forgery No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-62866 Patchstack
4.3 Medium SMTP Mail Plugin smtp-mail Cross-Site Request Forgery No login needed ≤ 1.3.51 CVE-2025-62762 Patchstack
6.5 Medium Add Custom Codes Plugin add-custom-codes Cross-Site Request Forgery No login needed ≤ 4.80 Fixed in 5.0 CVE-2025-62739 Patchstack
4.3 Medium Media Library Downloader Plugin media-library-downloader Cross-Site Request Forgery No login needed ≤ 1.4.0 CVE-2025-62734 Patchstack
4.3 Medium Custom Sidebars by ProteusThemes Plugin custom-sidebars-by-proteusthemes Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-62733 Patchstack
4.3 Medium Media Library File Download Plugin media-download Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62103 Patchstack
4.3 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Request Forgery No login needed ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-62102 Patchstack
4.3 Medium Duplicate Content Cure Plugin duplicate-content-cure Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-59132 Patchstack
4.3 Medium SupportCandy Plugin supportcandy Cross-Site Request Forgery No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-67598 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Cross-Site Request Forgery No login needed ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-67596 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.82 Fixed in 6.7.0.83 CVE-2025-67595 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.48 Fixed in 1.2.49 CVE-2025-67593 Patchstack
4.3 Medium JNews Paywall Plugin jnews-paywall Cross-Site Request Forgery No login needed ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67591 Patchstack
4.3 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67590 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
6.5 Medium Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.6.2 CVE-2025-10144 Wordfence
4.3 Medium TNC Toolbox: Web Performance Plugin tnc-toolbox Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66108 Patchstack
4.3 Medium I Order Terms Plugin i-order-terms Cross-Site Request Forgery No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-66097 Patchstack
4.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Request Forgery No login needed ≤ 1.12.20 Fixed in 1.12.21 CVE-2025-66064 Patchstack
4.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Request Forgery No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66061 Patchstack
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion ≤ 4.8.9 CVE-2025-12847 Wordfence
4.3 Medium WP Plugin Manager Plugin wp-plugin-manager Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-64271 Patchstack
6.5 Medium Auto Prune Posts Plugin auto-prune-posts Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64262 Patchstack
4.4 Medium MembershipWorks Plugin memberfindme Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 6.14 CVE-2025-12018 Wordfence
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
5.4 Medium Bard Theme bardwp Cross-Site Request Forgery No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64368 Patchstack
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-64357 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
4.3 Medium Stockie Extra Plugin stockie-extra Cross-Site Request Forgery No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64226 Patchstack
4.3 Medium PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.13.12 Fixed in 11.14 CVE-2025-64201 Patchstack
4.3 Medium Super Store Finder Plugin superstorefinder-wp Cross-Site Request Forgery No login needed ≤ 7.5 CVE-2025-58939 Patchstack
5.3 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2025-57931 Patchstack
4.3 Medium Entrada Theme entrada Cross-Site Request Forgery No login needed ≤ 5.7.7 CVE-2025-58918 Patchstack
4.9 Medium Slider Templates Plugin slider-templates Server-Side Request Forgery ≤ 1.0.3 CVE-2025-62988 Patchstack
4.3 Medium Raychat Plugin raychat Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-62975 Patchstack
4.3 Medium Simple Content Templates for Blog Posts & Pages Plugin simple-post-template Cross-Site Request Forgery No login needed ≤ 2.2.61 CVE-2025-62958 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only