WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,001–3,050 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 61 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Mail Subscribe List Plugin mail-subscribe-list Cross-Site Scripting ≤ 2.1.10 CVE-2025-58018 Patchstack
6.5 Medium Theater Plugin theatre Cross-Site Scripting ≤ 0.18.8 Fixed in 0.19 CVE-2025-58020 Patchstack
6.5 Medium ShortCode Plugin shortcode Cross-Site Scripting ≤ 0.8.1 CVE-2025-58022 Patchstack
6.5 Medium List Child Pages Shortcode Plugin list-child-pages-shortcode Cross-Site Scripting ≤ 1.3.1 Fixed in 1.4.0 CVE-2025-58021 Patchstack
6.5 Medium Genealogical Tree Plugin genealogical-tree Cross-Site Scripting ≤ 2.2.7 CVE-2025-58023 Patchstack
6.5 Medium Termageddon: Cookie Consent & Privacy Compliance Plugin termageddon-usercentrics Cross-Site Scripting ≤ 1.8.1 Fixed in 1.8.2 CVE-2025-58026 Patchstack
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.11.0 CVE-2025-58025 Patchstack
6.5 Medium NGG Smart Image Search Plugin ngg-smart-image-search Cross-Site Scripting ≤ 3.4.3 CVE-2025-58027 Patchstack
6.5 Medium Designil PDPA Thailand Plugin pdpa-thailand Cross-Site Scripting ≤ 2.0.1 CVE-2025-58028 Patchstack
6.5 Medium Page-list Plugin page-list Cross-Site Scripting ≤ 5.8 Fixed in 5.9 CVE-2025-58030 Patchstack
5.3 Medium Classic Widgets with Block-based Widgets Plugin classic-widgets-with-block-based-widgets Broken Access Control No login needed ≤ 1.0.1 CVE-2025-58029 Patchstack
6.5 Medium Nextend Facebook Connect Plugin nextend-facebook-connect Cross-Site Scripting ≤ 3.1.19 Fixed in 3.1.20 CVE-2025-58031 Patchstack
5.9 Medium Draft Plugin website-builder Cross-Site Scripting ≤ 3.0.9 CVE-2025-58033 Patchstack
4.3 Medium WP Compiler Plugin wp-compiler Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-58032 Patchstack
4.3 Medium Fastly Plugin fastly Cross-Site Request Forgery No login needed ≤ 1.2.28 Fixed in 1.2.29 CVE-2025-58199 Patchstack
4.3 Medium Flexible FAQ Plugin flexible-faq Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-58200 Patchstack
6.5 Medium Card Elements for WPBakery Plugin card-elements-for-wpbakery Cross-Site Scripting ≤ 1.0.8 CVE-2025-58220 Patchstack
4.3 Medium Show Pages List Plugin show-pages-list Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-58219 Patchstack
4.3 Medium PilotPress Plugin pilotpress Broken Access Control ≤ 2.0.36 CVE-2025-58221 Patchstack
5.3 Medium Team Manager Plugin wp-team-manager Broken Access Control No login needed ≤ 2.6.8 CVE-2025-58222 Patchstack
5.4 Medium Printeers Print & Ship Plugin invition-print-ship Cross-Site Request Forgery No login needed ≤ 1.17.0 CVE-2025-58224 Patchstack
5.9 Medium VoucherPress Plugin voucherpress Cross-Site Scripting ≤ 1.5.7 CVE-2025-58223 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure No login needed ≤ 1.16.16 Fixed in 1.16.17 CVE-2025-58226 Patchstack
6.5 Medium Quick View for WooCommerce Plugin woo-quickview Cross-Site Scripting ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-58228 Patchstack
6.5 Medium Podlove Subscribe button Plugin podlove-subscribe-button Cross-Site Scripting ≤ 1.3.11 Fixed in 1.3.12 CVE-2025-58227 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 2.0 CVE-2025-58229 Patchstack
6.5 Medium ZoloBlocks Plugin zoloblocks Cross-Site Scripting ≤ 2.3.12 Fixed in 2.3.13 CVE-2025-58230 Patchstack
6.5 Medium Bitly Plugin wp-bitly Cross-Site Scripting ≤ 2.8.0 CVE-2025-58231 Patchstack
6.5 Medium SQL Chart Builder Plugin sql-chart-builder Cross-Site Scripting ≤ 2.3.7.2 CVE-2025-58233 Patchstack
6.5 Medium Image Editor by Pixo Plugin image-editor-by-pixo Cross-Site Scripting ≤ 2.3.8 CVE-2025-58232 Patchstack
6.5 Medium JS Job Manager Plugin js-jobs Cross-Site Scripting ≤ 2.0.2 CVE-2025-58234 Patchstack
4.3 Medium Force Update Translations Plugin force-update-translations Cross-Site Request Forgery No login needed ≤ 0.5 Fixed in 0.6.0 CVE-2025-58236 Patchstack
6.5 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting ≤ 3.2.35 CVE-2025-58235 Patchstack
6.5 Medium LC Wizard Plugin ghl-wizard Cross-Site Scripting ≤ 2.2.4 CVE-2025-58237 Patchstack
6.5 Medium WP Category Dropdown Plugin wp-category-dropdown Cross-Site Scripting ≤ 1.9 CVE-2025-58239 Patchstack
6.5 Medium PilotPress Plugin pilotpress Cross-Site Scripting ≤ 2.0.36 CVE-2025-58238 Patchstack
6.5 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting ≤ 1.12.06 CVE-2025-58240 Patchstack
6.5 Medium SnapWidget Social Photo Feed Widget Plugin snapwidget-wp-instagram-widget Cross-Site Scripting ≤ 1.1.0 CVE-2025-58241 Patchstack
6.5 Medium Bg Church Memos Plugin bg-church-memos Cross-Site Scripting ≤ 1.1 CVE-2025-58242 Patchstack
5.9 Medium Portfolio Plugin portfolio Cross-Site Scripting ≤ 2.58 CVE-2025-58245 Patchstack
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-58247 Patchstack
4.3 Medium Qubely Plugin qubely Information Disclosure Sensitive Data Exposure ≤ 1.8.14 CVE-2025-58249 Patchstack
6.5 Medium Pinterest Pinboard Widget Plugin pinterest-pinboard-widget Cross-Site Scripting ≤ 1.0.7 CVE-2025-58248 Patchstack
4.3 Medium Sticky Header Effects for Elementor Plugin sticky-header-effects-for-elementor Broken Access Control ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-58251 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Scripting ≤ 7.3 CVE-2025-58253 Patchstack
4.3 Medium Getwid Plugin getwid Information Disclosure Sensitive Data Exposure ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-58252 Patchstack
6.5 Medium StylePress for Elementor Plugin full-site-builder-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2025-58254 Patchstack
6.5 Medium Verowa Connect Plugin verowa-connect Cross-Site Scripting ≤ 3.2.3 Fixed in 3.3.0 CVE-2025-58257 Patchstack
5.9 Medium DOAJ Export Plugin doaj-export Cross-Site Scripting ≤ 1.0.4 CVE-2025-58256 Patchstack
4.3 Medium Lazy Blocks Plugin lazy-blocks Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-58258 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only