WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,301–3,350 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 67 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-49039 Patchstack
4.3 Medium Backup Bolt Plugin backup-bolt Cross-Site Request Forgery No login needed ≤ 1.5.0 CVE-2025-49040 Patchstack
6.5 Medium School Management Plugin school-management Broken Access Control ≤ 93.2.0 CVE-2025-48108 Patchstack
4.7 Medium Automatic Plugin - AI content generator and auto poster Plugin Cross-Site Request Forgery AI content generator and auto poster plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.118.0 CVE-2025-6247 Wordfence
4.3 Medium Post Type Converter Plugin post-type-converter Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-48303 Patchstack
4.3 Medium Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Plugin sertifier-certificates-open-badges Cross-Site Request Forgery Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update No login needed ≤ 1.19 CVE-2025-7841 Wordfence
5.3 Medium Church Admin Plugin church-admin Broken Access Control No login needed ≤ 5.0.26 Fixed in 5.0.27 CVE-2025-57896 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-57895 Patchstack
4.3 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.19.8 Fixed in 3.19.8.1 CVE-2025-57894 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.79.270 Fixed in 1.79.274 CVE-2025-57893 Patchstack
4.3 Medium Simple Statistics for Feeds Plugin simple-feed-stats Cross-Site Request Forgery No login needed ≤ 20250322 Fixed in 20250820 CVE-2025-57892 Patchstack
5.9 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-57891 Patchstack
5.9 Medium Sessions Plugin sessions Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-57890 Patchstack
5.3 Medium Jobmonster Theme noo-jobmonster Information Disclosure Sensitive Data Exposure No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57888 Patchstack
6.5 Medium Jobmonster Theme noo-jobmonster Cross-Site Scripting ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57887 Patchstack
5.4 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.30.0 Fixed in 1.30.1 CVE-2025-57886 Patchstack
4.3 Medium Fluent Support Plugin fluent-support Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-57885 Patchstack
4.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 12.1.1 Fixed in 12.1.2 CVE-2025-57884 Patchstack
5.3 Medium ProveSource Social Proof Plugin provesource Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.2 Fixed in 4.0.0 CVE-2025-48355 Patchstack
6.5 Medium Notice Bar Plugin notice-bar Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-49389 Patchstack
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery No login needed ≤ 2.3.3 Fixed in 2.3.3.1 CVE-2025-49391 Patchstack
6.5 Medium Themify Icons Plugin themify-icons Cross-Site Scripting ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-49395 Patchstack
5.9 Medium Themify Audio Dock Plugin themify-audio-dock Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-49392 Patchstack
6.5 Medium Colorbox Lightbox Plugin wp-colorbox Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-49397 Patchstack
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control ≤ 7.6.7 Fixed in 7.6.8 CVE-2025-49396 Patchstack
6.5 Medium Infility Global Plugin infility-global Path Traversal Arbitrary File Download ≤ 2.15.06 CVE-2025-47650 Patchstack
5.9 Medium Page Transition Plugin page-transition Cross-Site Scripting ≤ 1.3 CVE-2025-49412 Patchstack
5.3 Medium WP Discord Post Plus – Supports Unlimited Channels Plugin wp-discord-post-plus Cross-Site Request Forgery Supports Unlimited Channels plugin <= 1.0.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.0.2 CVE-2025-49896 Patchstack
6.5 Medium JetEngine Plugin jet-engine Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1.1 CVE-2025-53195 Patchstack
6.5 Medium JetEngine Plugin jet-engine Information Disclosure Sensitive Data Exposure ≤ 3.7.0 Fixed in 3.7.1.1 CVE-2025-53196 Patchstack
6.5 Medium Prevent files / folders access Plugin prevent-file-access Path Traversal ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-53561 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Information Disclosure Sensitive Data Exposure ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53983 Patchstack
6.5 Medium JetMenu Plugin jet-menu Information Disclosure Sensitive Data Exposure ≤ 2.4.11.1 Fixed in 2.4.11.2 CVE-2025-53987 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Information Disclosure Sensitive Data Exposure ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53985 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Information Disclosure Sensitive Data Exposure ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53992 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Information Disclosure Sensitive Data Exposure ≤ 1.3.18 Fixed in 1.3.19 CVE-2025-53988 Patchstack
6.5 Medium JetPopup Plugin jet-popup Information Disclosure Sensitive Data Exposure ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53993 Patchstack
6.5 Medium JetWooBuilder Plugin jet-woo-builder Information Disclosure Sensitive Data Exposure ≤ 2.1.20 Fixed in 2.1.20.1 CVE-2025-53998 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Information Disclosure Sensitive Data Exposure ≤ 3.6.7 Fixed in 3.6.7.1 CVE-2025-54008 Patchstack
6.5 Medium Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.5 Fixed in 7.8.5 CVE-2025-54019 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control Settings Change No login needed ≤ 6.4.0 Fixed in 6.4.2 CVE-2025-54025 Patchstack
6.5 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 5.1.20 Fixed in 5.1.22 CVE-2025-54040 Patchstack
6.5 Medium Cost Calculator Plugin ql-cost-calculator Cross-Site Scripting ≤ 7.4 Fixed in 7 .5 CVE-2025-54046 Patchstack
6.6 Medium Groundhogg Plugin groundhogg PHP Object Injection ≤ 4.2.2 Fixed in 4.2.2.1 CVE-2025-54053 Patchstack
6.5 Medium ServerBuddy by PluginBuddy.com Plugin serverbuddy-by-pluginbuddy Cross-Site Request Forgery CSRF to PHP Object Injection ≤ 1.0.5 CVE-2025-49895 Patchstack
5.3 Medium Ultimate Video Player Plugin fwduvp Broken Access Control No login needed ≤ 10.1 CVE-2025-49432 Patchstack
6.4 Medium WP Table Builder – WordPress Table Plugin wp-table-builder Cross-Site Scripting WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.0.12 CVE-2025-8604 Wordfence
4.3 Medium flexo-social-gallery Plugin flexo-social-gallery Cross-Site Request Forgery No login needed ≤ 1.0006 CVE-2025-52769 Patchstack
4.3 Medium NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52767 Patchstack
6.5 Medium Video Expander Plugin video-expander Cross-Site Scripting ≤ 1.0 CVE-2025-52771 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only