WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,201–3,250 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 65 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ibtana – Ecommerce Product Addons Plugin ibtana-ecommerce-product-addons Cross-Site Scripting Ecommerce Product Addons plugin <= 0.4.7.6 - Cross Site Scripting (XSS) ≤ 0.4.7.6 CVE-2025-58786 Patchstack
5.4 Medium Ray Enterprise Translation Plugin lingotek-translation Broken Access Control ≤ 1.7.2 CVE-2025-58785 Patchstack
6.5 Medium ARI Fancy Lightbox Plugin ari-fancy-lightbox Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58784 Patchstack
4.3 Medium Gutentor Plugin gutentor Broken Access Control ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-58783 Patchstack
5.4 Medium Exit Intent Popup Plugin exitintentpopup Server-Side Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.3 CVE-2025-58641 Patchstack
6.5 Medium Document Engine Plugin document-engine Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2025-58640 Patchstack
5.4 Medium Contact Form By Mega Forms Plugin mega-forms Broken Access Control ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-58639 Patchstack
5.3 Medium Support Genix Plugin support-genix-lite Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2025-58635 Patchstack
5.3 Medium PeachPay Payments Plugin peachpay-for-woocommerce Broken Access Control No login needed ≤ 1.117.4 Fixed in 1.117.5 CVE-2025-58634 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.21 Fixed in 1.1.22 CVE-2025-58633 Patchstack
6.5 Medium Dadevarzan WordPress Common Plugin dadevarzan-common Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-58632 Patchstack
5.9 Medium IssueM Plugin issuem Cross-Site Scripting ≤ 2.9.0 Fixed in 2.9.1 CVE-2025-58631 Patchstack
5.9 Medium Simple Matomo Tracking Code Plugin simple-matomo-tracking-code Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-58630 Patchstack
6.5 Medium RumbleTalk Live Group Chat Plugin rumbletalk-chat-a-chat-with-themes Cross-Site Scripting ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-58626 Patchstack
5.9 Medium WP Flow Plus Plugin wp-imageflow2 Cross-Site Scripting ≤ 5.2.5 Fixed in 5.2.6 CVE-2025-58625 Patchstack
6.5 Medium Exchange Rates Plugin exchange-rates Cross-Site Scripting ≤ 1.2.5 Fixed in 1.3.0 CVE-2025-58624 Patchstack
6.5 Medium Event Feed for Eventbrite Plugin event-feed-for-eventbrite Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-58623 Patchstack
4.3 Medium Mobile Contact Line Plugin mobile-contact-line Broken Access Control ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-58622 Patchstack
6.5 Medium PuzzleMe Plugin puzzleme Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-58621 Patchstack
6.5 Medium PDF for WPForms Plugin pdf-for-wpforms Cross-Site Scripting ≤ 6.2.1 Fixed in 6.3.0 CVE-2025-58620 Patchstack
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-58618 Patchstack
4.3 Medium F4 Media Taxonomies Plugin f4-media-taxonomies Broken Access Control ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-58617 Patchstack
6.5 Medium Frisbii Pay Plugin reepay-checkout-gateway Broken Access Control ≤ 1.8.2.1 Fixed in 1.8.3 CVE-2025-58616 Patchstack
4.4 Medium WP Bannerize Pro Plugin wp-bannerize-pro Server-Side Request Forgery ≤ 1.10.0 Fixed in 1.11.0 CVE-2025-58615 Patchstack
6.5 Medium Tooltipy Plugin bluet-keywords-tooltip-generator Cross-Site Scripting ≤ 5.5.6 Fixed in 5.5.9 CVE-2025-58614 Patchstack
5.3 Medium Posts Table with Search & Sort Plugin posts-data-table Broken Access Control No login needed ≤ 1.4.10 Fixed in 1.4.11 CVE-2025-58613 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-58612 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery No login needed ≤ 3.5.5.6 Fixed in 3.5.5.8 CVE-2025-58611 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-58610 Patchstack
6.5 Medium Latest Post Shortcode Plugin latest-post-shortcode Cross-Site Scripting ≤ 14.0.3 Fixed in 14.10 CVE-2025-58609 Patchstack
6.5 Medium Cookie Notice & Consent Banner for GDPR & CCPA Compliance Plugin cookie-notice-and-consent-banner Cross-Site Scripting ≤ 1.7.11 Fixed in 1.7.12 CVE-2025-58607 Patchstack
5.0 Medium SaasLauncher Plugin saaslauncher Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-58606 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-58605 Patchstack
5.3 Medium Surfer Plugin surferseo Broken Access Control No login needed ≤ 1.6.4.574 Fixed in 1.6.5.584 CVE-2025-58603 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting ≤ 1.9.4 Fixed in 1.9.4.1 CVE-2025-58602 Patchstack
4.3 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-58601 Patchstack
5.3 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control No login needed ≤ 2.15.9 Fixed in 2.16.0 CVE-2025-58600 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Broken Access Control ≤ 4.1.0 Fixed in 4.2.0 CVE-2025-58599 Patchstack
6.6 Medium Klarna Order Management for WooCommerce Plugin klarna-order-management-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.9.8 Fixed in 1.9.9 CVE-2025-58598 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-58597 Patchstack
5.9 Medium MailOptin Plugin mailoptin Cross-Site Scripting ≤ 1.2.75.0 Fixed in 1.2.75.1 CVE-2025-58596 Patchstack
4.3 Medium Brizy Plugin brizy Broken Access Control ≤ 2.7.12 Fixed in 2.7.13 CVE-2025-58594 Patchstack
6.5 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 3.0.0 Fixed in 3.0.1 CVE-2025-58593 Patchstack
4.3 Medium Malcure Malware Scanner Plugin wp-malware-removal Broken Access Control ≤ 16.8 Fixed in 16.9 CVE-2025-3701 Patchstack
5.3 Medium Makeaholic Plugin makeaholic Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.7 CVE-2025-58210 Patchstack
4.3 Medium Pro Bulk Watermark Plugin pro-watermark Path Traversal ≤ 2.0 CVE-2025-4956 Patchstack
5.8 Medium B Slider Plugin b-slider Broken Access Control No login needed ≤ 1.1.30 Fixed in 2.0.0 CVE-2025-54734 Patchstack
6.5 Medium All Bootstrap Blocks Plugin all-bootstrap-blocks Broken Access Control No login needed ≤ 1.3.28 Fixed in 1.3.29 CVE-2025-54733 Patchstack
5.4 Medium LifePress Plugin lifepress Broken Access Control ≤ 2.1.3 Fixed in 2.2 CVE-2025-53337 Patchstack
6.4 Medium Chartbeat Plugin chartbeat Server-Side Request Forgery ≤ 2.0.7 CVE-2025-53250 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only