WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,251–3,300 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 66 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Houzez Theme houzez Local File Inclusion < 4.1.4 Fixed in 4.1.4 CVE-2025-49405 Patchstack
5.9 Medium Custom Comment Plugin customcomment Cross-Site Scripting ≤ 2.1.6 CVE-2025-48365 Patchstack
4.9 Medium rajce Plugin rajce Server-Side Request Forgery ≤ 0.4.2 CVE-2025-48364 Patchstack
4.3 Medium Popup for CF7 with Sweet Alert Plugin cf7-sweet-alert-popup Cross-Site Request Forgery No login needed ≤ 1.6.5 CVE-2025-48363 Patchstack
5.4 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.2.5 CVE-2025-48362 Patchstack
5.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.2.5 CVE-2025-48361 Patchstack
5.9 Medium Varnish/Nginx Proxy Caching Plugin vcaching Cross-Site Scripting ≤ 1.8.3 CVE-2025-48360 Patchstack
5.9 Medium Risk Free Cash On Delivery (COD) – WooCommerce Plugin risk-free-cash-on-delivery-cod-woocommerce Cross-Site Scripting WooCommerce plugin <= 1.0.4 - Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-48358 Patchstack
5.4 Medium Century ToolKit Plugin century-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Activation No login needed ≤ 1.2.1 CVE-2025-48357 Patchstack
6.5 Medium Kanpress Plugin kanpress Cross-Site Scripting ≤ 1.1 CVE-2025-48356 Patchstack
6.5 Medium Better Post & Filter Widgets for Elementor Plugin better-post-filter-widgets-for-elementor Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-48354 Patchstack
5.9 Medium Yandex Site search pinger Plugin yandex-pinger Cross-Site Scripting ≤ 1.5 CVE-2025-48352 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Broken Access Control ≤ 2.2.7 CVE-2025-48350 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
4.3 Medium Site Offline Plugin site-offline Broken Access Control ≤ 1.5.7 CVE-2025-48348 Patchstack
6.5 Medium bxSlider integration Plugin bxslider-integration Cross-Site Scripting ≤ 1.7.2 CVE-2025-48347 Patchstack
5.3 Medium WP Mailgun SMTP Plugin wp-mailgun-smtp Broken Access Control No login needed ≤ 1.0.7 CVE-2025-48327 Patchstack
5.9 Medium tli.tl auto Twitter poster Plugin tlitl-auto-twitter-poster Cross-Site Scripting ≤ 3.4 CVE-2025-48324 Patchstack
5.9 Medium Advance Food Menu Plugin advance-food-menu Cross-Site Scripting ≤ 1.0 CVE-2025-48323 Patchstack
6.5 Medium Statify Widget Plugin statify-widget Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-48322 Patchstack
5.9 Medium Mesa Mesa Reservation Widget Plugin mesa-mesa-reservation-widget Cross-Site Scripting ≤ 1.0.0 CVE-2025-48319 Patchstack
4.3 Medium 多说社会化评论框 Plugin duoshuo Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-48318 Patchstack
6.5 Medium Responsive Mobile-Friendly Tooltip Plugin responsive-mobile-friendly-tooltip Cross-Site Scripting ≤ 1.6.6 CVE-2025-48316 Patchstack
6.5 Medium WordPress HTML Plugin custom-html-bodyhead Cross-Site Scripting ≤ 0.51 CVE-2025-48315 Patchstack
5.9 Medium Add Code To Head Plugin add-code-to-head Cross-Site Scripting ≤ 1.17 CVE-2025-48314 Patchstack
5.9 Medium Tripadvisor Shortcode Plugin tripadvisor-shortcode Cross-Site Scripting ≤ 2.2 CVE-2025-48313 Patchstack
6.5 Medium WPAvatar Plugin wpavatar Cross-Site Scripting ≤ 1.9.4 CVE-2025-48312 Patchstack
4.3 Medium Table Editor Plugin wp-table-editor Cross-Site Request Forgery No login needed ≤ 1.6.4 CVE-2025-48310 Patchstack
5.9 Medium Goal Tracker for Patreon Plugin goal-tracker-for-patreon Cross-Site Scripting ≤ 0.4.6 CVE-2025-48305 Patchstack
6.5 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-48110 Patchstack
5.9 Medium WP Thumbtack Review Slider Plugin wp-thumbtack-review-slider Cross-Site Scripting ≤ 2.6 Fixed in 2.7 CVE-2025-58216 Patchstack
6.5 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting ≤ 1.0.14 Fixed in 1.0.15 CVE-2025-58213 Patchstack
6.5 Medium Epeken All Kurir Plugin epeken-all-kurir Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-58212 Patchstack
6.5 Medium Chatbox Manager Plugin wa-chatbox-manager Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58211 Patchstack
6.5 Medium Transcoder Plugin transcoder Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58209 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Cross-Site Scripting ≤ 6.2.0 Fixed in 6.3.0 CVE-2025-58208 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58205 Patchstack
4.7 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Open Redirect No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-58204 Patchstack
4.4 Medium Solace Extra Plugin solace-extra Server-Side Request Forgery ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-58203 Patchstack
4.3 Medium Simple Page Access Restriction Plugin simple-page-access-restriction Cross-Site Request Forgery No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2025-58202 Patchstack
5.3 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Broken Access Control No login needed ≤ 1.17.17 Fixed in 1.17.18 CVE-2025-58201 Patchstack
6.5 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.9 Fixed in 1.2.10 CVE-2025-58198 Patchstack
6.5 Medium Simple Download Monitor Plugin simple-download-monitor Cross-Site Scripting ≤ 3.9.34 Fixed in 3.9.35 CVE-2025-58197 Patchstack
6.5 Medium UiCore Elements Plugin uicore-elements Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-58196 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.17 Fixed in 1.4.18 CVE-2025-58195 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-58194 Patchstack
4.3 Medium Uncanny Automator Plugin uncanny-automator Broken Access Control ≤ 6.7.0.1 Fixed in 6.8.0 CVE-2025-58193 Patchstack
4.3 Medium WP Bulk Delete Plugin wp-bulk-delete Broken Access Control ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58192 Patchstack
5.3 Medium Printeers Print & Ship Plugin invition-print-ship Path Traversal Directory Traversal No login needed ≤ 1.17.0 CVE-2025-48081 Patchstack
5.9 Medium Admin Menu Groups Plugin admin-menu-groups Cross-Site Scripting ≤ 0.1.2 CVE-2025-49035 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only