WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,151–3,200 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 64 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Zoomify embed for WP Plugin zoom-image-shortcode Cross-Site Scripting ≤ 1.5.2 CVE-2025-58863 Patchstack
6.5 Medium WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Scripting connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 CVE-2025-58862 Patchstack
6.5 Medium WPB Image Widget Plugin wpb-image-widget Cross-Site Scripting ≤ 1.1 CVE-2025-58858 Patchstack
6.5 Medium Woocommerce Notify Updated Product Plugin woocommerce-notify-updated-product Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58856 Patchstack
6.5 Medium Boxed Content Plugin boxed-content Cross-Site Scripting ≤ 1.0 CVE-2025-58851 Patchstack
6.5 Medium Showpass WordPress Extension Plugin showpass Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-58850 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
5.5 Medium Media Author Plugin media-author Broken Access Control ≤ 1.0.4 CVE-2025-58841 Patchstack
6.5 Medium Custom Team Manager Plugin custom-team-manager Cross-Site Scripting ≤ 2.4.2 CVE-2025-58840 Patchstack
6.5 Medium Smooth Accordion Plugin smooth-accordion Cross-Site Scripting ≤ 2.1 CVE-2025-58838 Patchstack
6.5 Medium SS Font Awesome Icon Plugin ss-font-awesome-icon Cross-Site Scripting ≤ 4.1.3 CVE-2025-58837 Patchstack
6.5 Medium FW Anker Plugin fw-anker Cross-Site Scripting ≤ 1.2.6 CVE-2025-58836 Patchstack
5.3 Medium Bonus for Woo Plugin bonus-for-woo Other Other vulnerability Type No login needed ≤ 7.6.6 Fixed in 7.6.7 CVE-2025-58835 Patchstack
6.5 Medium short.io Plugin wp-shortcm Cross-Site Scripting ≤ 2.4.2 CVE-2025-58834 Patchstack
5.9 Medium Search by Google Plugin search-google Cross-Site Scripting ≤ 1.9 CVE-2025-58832 Patchstack
4.3 Medium Parallax Scrolling Enllax.js Plugin parallax-scrolling-enllax-js Cross-Site Request Forgery No login needed ≤ 0.0.6 CVE-2025-58831 Patchstack
6.5 Medium Parallax Scrolling Enllax.js Plugin parallax-scrolling-enllax-js Cross-Site Scripting ≤ 0.0.6 CVE-2025-58830 Patchstack
4.9 Medium Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin ai-auto-tool Server-Side Request Forgery ≤ 2.3.3 CVE-2025-58829 Patchstack
6.5 Medium 코드엠샵 소셜톡 Plugin mshop-naver-talktalk Cross-Site Scripting ≤ 1.2.2 CVE-2025-58828 Patchstack
6.5 Medium WP Publication Archive Plugin wp-publication-archive Cross-Site Scripting ≤ 3.0.1 CVE-2025-58826 Patchstack
5.9 Medium Comment Form WP – Customize Default Comment Form Plugin comment-form-wp Cross-Site Scripting Customize Default Comment Form plugin <= 2.0.1 - Cross Site Scripting (XSS) ≤ 2.0.1 CVE-2025-58825 Patchstack
4.3 Medium Shk Corporate Plugin shk-corporate Broken Access Control ≤ 2.4.1.1 CVE-2025-58824 Patchstack
6.5 Medium Get Cash Plugin get-cash Cross-Site Scripting ≤ 3.2.3 CVE-2025-58823 Patchstack
6.5 Medium WP Mail Plugin wp-mail Cross-Site Scripting ≤ 1.3 CVE-2025-58822 Patchstack
5.9 Medium WP Notification Bell Plugin wp-notification-bell Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-58821 Patchstack
5.9 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58820 Patchstack
5.4 Medium Developer Tools Blocker Plugin swiftninjapro-inspect-element-console-blocker Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-58818 Patchstack
4.3 Medium SoftMe Plugin softme Broken Access Control ≤ 1.1.27 CVE-2025-58817 Patchstack
6.5 Medium Stagtools Plugin stagtools Cross-Site Scripting ≤ 2.3.8 CVE-2025-58814 Patchstack
4.3 Medium Consultstreet Plugin consultstreet Broken Access Control ≤ 3.0.0 CVE-2025-58813 Patchstack
6.5 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Cross-Site Scripting ≤ 1.4.3 CVE-2025-58812 Patchstack
5.9 Medium Ultimate Client Dash Plugin ulimate-client-dash Cross-Site Scripting ≤ 4.7 CVE-2025-58811 Patchstack
5.9 Medium Simple Link List Widget Plugin simple-link-list-widget Cross-Site Scripting ≤ 0.3.2 CVE-2025-58810 Patchstack
6.5 Medium prettyPhoto Plugin prettyphoto Cross-Site Scripting ≤ 1.2.5 CVE-2025-58808 Patchstack
5.9 Medium Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Scripting ≤ 3.0 CVE-2025-58805 Patchstack
4.3 Medium WooCommerce Single Page Checkout Plugin woo-single-page-checkout Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-58804 Patchstack
4.3 Medium TrustMate.io – WooCommerce integration Plugin trustmate-io-integration-for-woocommerce Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.16.0 CVE-2025-58802 Patchstack
5.4 Medium Responder Plugin responder Cross-Site Request Forgery No login needed ≤ 4.3.8 Fixed in 4.4.0 CVE-2025-58801 Patchstack
4.3 Medium WP Email Template Plugin wp-email-template Cross-Site Request Forgery No login needed ≤ 2.8.5 CVE-2025-58800 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-58799 Patchstack
4.3 Medium BCM Duplicate Menu Plugin bcm-duplicate-menu Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-58798 Patchstack
5.3 Medium Ninja Charts Plugin ninja-charts Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-58797 Patchstack
6.5 Medium Elementor Element Condition Plugin ele-conditions Cross-Site Scripting ≤ 1.0.5 CVE-2025-58796 Patchstack
4.3 Medium Payoneer Checkout Plugin payoneer-checkout Content Injection Content Spoofing No login needed ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-58795 Patchstack
4.3 Medium Notification for Telegram Plugin notification-for-telegram Cross-Site Request Forgery No login needed ≤ 3.5 CVE-2025-58794 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.7 CVE-2025-58793 Patchstack
4.3 Medium Authors List Plugin authors-list Cross-Site Request Forgery No login needed ≤ 2.0.6.2 CVE-2025-58792 Patchstack
5.9 Medium SEO Auto Linker Plugin wpa-seo-auto-linker Cross-Site Scripting ≤ 1.5.3 CVE-2025-58791 Patchstack
6.5 Medium Kiwi Plugin kiwi-social-share Cross-Site Scripting ≤ 2.1.8 CVE-2025-58790 Patchstack
6.5 Medium Themify Popup Plugin themify-popup Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-58787 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only