WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,401–3,450 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 69 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium WP Modal Popup with Cookie Integration Plugin wp-modal-popup-with-cookie-integration Cross-Site Scripting ≤ 2.4 Fixed in 2.5 CVE-2025-54683 Patchstack
5.4 Medium Connector for Gravity Forms and Google Sheets Plugin wp-gravity-forms-spreadsheets Cross-Site Request Forgery No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-54682 Patchstack
4.7 Medium Connector for Gravity Forms and Google Sheets Plugin wp-gravity-forms-spreadsheets Open Redirect No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-54681 Patchstack
6.5 Medium Blogger Buzz Plugin blogger-buzz Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-54680 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54676 Patchstack
4.3 Medium YITH WooCommerce Popup Plugin yith-woocommerce-popup Cross-Site Request Forgery No login needed ≤ 1.48.0 Fixed in 1.48.1 CVE-2025-54675 Patchstack
5.4 Medium Product Configurator for WooCommerce Plugin product-configurator-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.4.4 Fixed in 1.5.0 CVE-2025-54674 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-54673 Patchstack
4.3 Medium Photo Engine Plugin wplr-sync Cross-Site Request Forgery No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2025-54672 Patchstack
4.3 Medium oik Plugin oik Cross-Site Request Forgery No login needed ≤ 4.15.2 Fixed in 4.15.3 CVE-2025-54671 Patchstack
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.9.4.3 Fixed in 2.9.4.4 CVE-2025-54668 Patchstack
5.3 Medium myCred Plugin mycred Other Race Condition No login needed ≤ 2.9.4.3 Fixed in 2.9.4.4 CVE-2025-54667 Patchstack
6.5 Medium Advanced Google Universal Analytics Plugin advanced-google-universal-analytics Broken Access Control Broken Access Control to Sensitive Data Exposure ≤ 1.0.3 CVE-2025-28962 Patchstack
6.4 Medium PressForward Plugin pressforward Server-Side Request Forgery ≤ 5.9.5 CVE-2025-28987 Patchstack
6.5 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.7 - Broken Access Control ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30993 Patchstack
6.5 Medium Eventer Plugin eventer Content Injection No login needed ≤ 3.9.9.1 Fixed in 3.9.9.1 CVE-2025-39483 Patchstack
6.5 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Cross-Site Scripting ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-47610 Patchstack
5.9 Medium Inspectlet – User Session Recording and Heatmaps Plugin inspectlet-heatmaps-and-user-session-recording Cross-Site Scripting User Session Recording and Heatmaps plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 3.0 CVE-2025-49048 Patchstack
5.9 Medium DigitalOcean Spaces Sync Plugin do-spaces-sync Cross-Site Scripting ≤ 2.2.1 CVE-2025-49047 Patchstack
4.3 Medium Netease Music Plugin netease-music Broken Access Control ≤ 3.2.1 CVE-2025-49052 Patchstack
6.5 Medium Hide Text Shortcode Plugin hide-text-shortcode Cross-Site Scripting ≤ 1.1 CVE-2025-49051 Patchstack
5.9 Medium WP Airdrop Manager Plugin airdrop Cross-Site Scripting ≤ 1.0.5 CVE-2025-49053 Patchstack
6.5 Medium Porn Videos Embed Plugin porn-videos-embed Cross-Site Scripting ≤ 0.9.1 CVE-2025-49061 Patchstack
6.5 Medium WP LOL Rotation Plugin league-of-legends-rotation Cross-Site Scripting ≤ 1.0 CVE-2025-49437 Patchstack
6.5 Medium Supermalink Plugin supermalink Cross-Site Scripting ≤ 1.1 CVE-2025-49433 Patchstack
6.5 Medium AI Tools Plugin artificial-intelligence-auto-content-generator Broken Access Control Arbitrary Content Deletion ≤ 4.0.7 CVE-2025-50029 Patchstack
6.5 Medium CF7 Spreadsheets Plugin cf7-spreadsheets Cross-Site Scripting ≤ 2.3.2 CVE-2025-50040 Patchstack
6.5 Medium DB Backup Plugin db-backup Broken Access Control ≤ 6.0 CVE-2025-50031 Patchstack
4.2 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Visual Drag and Drop Editor <= 1.27.8 - Path Traversal ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52712 Patchstack
6.5 Medium Global Gallery Plugin global-gallery Broken Access Control No login needed ≤ 9.2.3 Fixed in 9.2.4 CVE-2025-52721 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Broken Access Control No login needed ≤ 1.32.1 Fixed in 1.32.2 CVE-2025-47444 Patchstack
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.5 CVE-2025-7502 Wordfence
6.5 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird SQL Injection WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection ≤ 6.4.8 CVE-2025-6986 Wordfence
6.1 Medium WordPress Qwizcards Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.9.4 CVE-2025-6174 WPScan
6.5 Medium Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read ≤ 16.8 CVE-2025-7772 Wordfence
5.3 Medium Listly: Listicles Plugin listly Broken Access Control Unauthenticated Arbitrary Transient Deletion No login needed ≤ 2.7 CVE-2025-5811 Wordfence
6.5 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30959 Patchstack
6.5 Medium Profiler - What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed ≤ 1.0.0 CVE-2025-48339 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-49319 Patchstack
6.5 Medium Internal Linking of Related Contents Plugin internal-linking-of-related-contents Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-49884 Patchstack
6.5 Medium Ultimate Push Notifications Plugin ultimate-push-notifications Broken Access Control No login needed ≤ 1.2.0 CVE-2025-50028 Patchstack
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
5.3 Medium Residential Address Detection Plugin residential-address-detection Broken Access Control No login needed ≤ 2.5.9 Fixed in 2.5.10 CVE-2025-48155 Patchstack
6.5 Medium Image Wall Plugin image-wall Cross-Site Scripting ≤ 3.1 Fixed in 3.2 CVE-2025-48156 Patchstack
5.4 Medium Chatbox Manager Plugin wa-chatbox-manager Broken Access Control ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-48167 Patchstack
5.3 Medium Stop and Block bots plugin Anti bots Plugin antibots Broken Access Control No login needed ≤ 1.48 Fixed in 1.50 CVE-2025-48166 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-48295 Patchstack
4.4 Medium FG Drupal to Plugin fg-drupal-to-wp Server-Side Request Forgery ≤ 3.90.0 Fixed in 3.90.1 CVE-2025-48294 Patchstack
6.5 Medium LightBox Block Plugin lightbox-block Cross-Site Scripting ≤ 1.1.30 Fixed in 1.1.31 CVE-2025-54051 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only