WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,951–3,000 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 60 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Library Bookshelves Plugin library-bookshelves Cross-Site Scripting ≤ 5.11 CVE-2025-57964 Patchstack
6.5 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.41 Fixed in 1.0.0.43 CVE-2025-57966 Patchstack
6.5 Medium WP Proposals Plugin wp-proposals Cross-Site Scripting ≤ 2.3 CVE-2025-57965 Patchstack
6.5 Medium WPB Quick View for WooCommerce Plugin woocommerce-lightbox Cross-Site Scripting ≤ 2.1.8 Fixed in 2.2 CVE-2025-57967 Patchstack
4.3 Medium Hide WP Toolbar Plugin hide-wp-toolbar Broken Access Control ≤ 2.7 CVE-2025-57969 Patchstack
4.3 Medium SALESmanago & Leadoo Plugin salesmanago Cross-Site Request Forgery No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-57970 Patchstack
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-57972 Patchstack
5.3 Medium SALESmanago & Leadoo Plugin salesmanago Broken Access Control No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-57971 Patchstack
5.5 Medium WP-Members Plugin wp-members Cross-Site Scripting ≤ 3.5.4.2 Fixed in 3.5.4.3 CVE-2025-57973 Patchstack
5.9 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Scripting ≤ 1.5.5 CVE-2025-57974 Patchstack
5.3 Medium CardCom Payment Gateway Plugin woo-cardcom-payment-gateway Broken Access Control No login needed ≤ 3.5.0.7 CVE-2025-57976 Patchstack
4.3 Medium Team Plugin tlp-team Broken Access Control ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-57975 Patchstack
5.9 Medium AuthorSure Plugin authorsure Cross-Site Scripting ≤ 2.3 CVE-2025-57979 Patchstack
4.3 Medium Advanced Appointment Booking & Scheduling Plugin advanced-appointment-booking-scheduling Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-57978 Patchstack
5.9 Medium Safety Exit Plugin safety-exit Cross-Site Scripting ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-57980 Patchstack
5.9 Medium Advance Portfolio Grid Plugin advance-portfolio-grid Cross-Site Scripting ≤ 1.07.6 Fixed in 1.07.7 CVE-2025-57982 Patchstack
6.5 Medium WP Social Widget Plugin wp-social-widget Cross-Site Scripting ≤ 2.3.1 CVE-2025-57981 Patchstack
6.5 Medium BP Disable Activation Reloaded Plugin bp-disable-activation-reloaded Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-57983 Patchstack
4.3 Medium Ultimate Watermark Plugin ultimate-watermark Broken Access Control ≤ 1.1 Fixed in 1.1.1 CVE-2025-57985 Patchstack
4.4 Medium MakeStories (for Google Web Stories) Plugin makestories-helper Server-Side Request Forgery ≤ 3.0.4 CVE-2025-57984 Patchstack
6.5 Medium WP Subtitle Plugin wp-subtitle Cross-Site Scripting ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-57986 Patchstack
5.3 Medium WP Events Manager Plugin wp-events-manager Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-57987 Patchstack
6.5 Medium Uncanny Toolkit for LearnDash Plugin uncanny-learndash-toolkit Cross-Site Scripting ≤ 3.7.0.3 Fixed in 3.7.0.4 CVE-2025-57988 Patchstack
6.5 Medium WordPress Widgets Shortcode Plugin wp-widgets-shortcode Cross-Site Scripting ≤ 1.0.3 CVE-2025-57989 Patchstack
5.4 Medium Clariti Plugin clariti Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-57991 Patchstack
5.4 Medium Blog Designer Plugin blog-designer Broken Access Control ≤ 3.1.8 CVE-2025-57990 Patchstack
4.3 Medium Mail Baby SMTP Plugin mail-baby-smtp Cross-Site Request Forgery No login needed ≤ 2.8 Fixed in 3.2.12 CVE-2025-57992 Patchstack
5.4 Medium Upcoming Events Lists Plugin upcoming-events-lists Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.0 CVE-2025-57994 Patchstack
6.5 Medium Geolocation IP Detection Plugin geoip-detect Cross-Site Scripting ≤ 5.5.0 Fixed in 5.6.0 CVE-2025-57993 Patchstack
4.3 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Broken Access Control ≤ 2.1.10 CVE-2025-57995 Patchstack
6.5 Medium Buckets Plugin buckets Cross-Site Scripting ≤ 0.3.9 CVE-2025-57996 Patchstack
5.9 Medium E-namad & Shamed Logo Manager Plugin e-namad-shamed-logo-manager Cross-Site Scripting ≤ 2.2 CVE-2025-57998 Patchstack
4.3 Medium Trustpilot Reviews Plugin trustpilot-reviews Broken Access Control ≤ 2.5.925 Fixed in 3.6.0 CVE-2025-57997 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-57999 Patchstack
6.5 Medium Compact Archives Plugin compact-archives Cross-Site Scripting ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-58001 Patchstack
5.3 Medium Memberful - Membership Plugin memberful-wp Broken Access Control No login needed ≤ 1.75.0 Fixed in 1.76.0 CVE-2025-58000 Patchstack
6.5 Medium GD bbPress Tools Plugin gd-bbpress-tools Cross-Site Scripting ≤ 3.5.3 CVE-2025-58002 Patchstack
5.3 Medium DriCub Plugin dricub-driving-school Broken Access Control No login needed ≤ 2.9 CVE-2025-58004 Patchstack
5.3 Medium Javo Core Plugin javo-core Broken Access Control No login needed ≤ 3.0.0.266 CVE-2025-58003 Patchstack
5.4 Medium DriCub Plugin dricub-driving-school Server-Side Request Forgery No login needed ≤ 2.9 CVE-2025-58005 Patchstack
4.7 Medium WP Gravity Forms Keap/Infusionsoft Plugin gf-infusionsoft Open Redirect No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58006 Patchstack
6.5 Medium Participants Database Plugin participants-database Cross-Site Scripting ≤ 2.7.6.3 Fixed in 2.7.7 CVE-2025-58008 Patchstack
4.3 Medium Hubbub Lite Plugin social-pug Information Disclosure Sensitive Data Exposure ≤ 1.35.2 Fixed in 1.36.0 CVE-2025-58007 Patchstack
6.4 Medium Content Mask Plugin content-mask Server-Side Request Forgery ≤ 1.8.5.2 Fixed in 1.8.5.3 CVE-2025-58011 Patchstack
4.3 Medium SV Proven Expert Plugin sv-provenexpert Cross-Site Request Forgery No login needed ≤ 2.0.06 CVE-2025-58010 Patchstack
5.3 Medium Quiz Maker Plugin quiz-maker Information Disclosure Sensitive Data Exposure No login needed ≤ 6.7.0.65 Fixed in 6.7.0.66 CVE-2025-58015 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.64 Fixed in 6.7.0.65 CVE-2025-58014 Patchstack
4.3 Medium CF7 Submissions Plugin cf7-submissions Broken Access Control ≤ 0.26 CVE-2025-58016 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-58017 Patchstack
6.5 Medium Search Atlas SEO Plugin metasync Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-58019 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only