WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 301–350 of 569 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
6.4 Medium WpEvently Plugin mage-eventpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.2 CVE-2025-5568 Wordfence
5.9 Medium Next Event Calendar Plugin next-event-calendar Cross-Site Scripting ≤ 1.2 CVE-2023-26001 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
6.5 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Cross-Site Scripting ≤ 1.4.9 Fixed in 1.4.10 CVE-2025-49311 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.10.1 Fixed in 5.10.2 CVE-2025-49298 Patchstack
9.0 Critical Motors - Events Plugin stm-motors-events Local File Inclusion Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.7 CVE-2025-47586 Patchstack
5.3 Medium Modern Events Calendar Plugin modern-events-calendar-lite Information Disclosure Information Exposure No login needed ≤ 7.21.9 CVE-2025-5733 Wordfence
9.8 Critical Eventin Plugin wp-event-solution Privilege Escalation No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2025-47539 Patchstack
7.1 High WordPress Events Calendar Registration & Tickets Plugin wpeventplus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-39372 Patchstack
9.8 Critical WordPress Events Calendar Registration & Tickets Plugin wpeventplus PHP Object Injection No login needed ≤ 2.6.0 CVE-2025-47581 Patchstack
6.5 Medium Import Social Events Plugin import-facebook-events Cross-Site Scripting ≤ 1.8.5 Fixed in 1.8.6 CVE-2025-48256 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.11.2.1 Fixed in 6.12.0 CVE-2025-48246 Patchstack
6.4 Medium EventON - WordPress Virtual Event Calendar Plugin Broken Access Control WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.9.6 CVE-2025-3527 Wordfence
9.3 Critical Eventer Plugin eventer SQL Injection No login needed ≤ 3.11.4 Fixed in 3.11.4 CVE-2025-39481 Patchstack
4.3 Medium Eventer Plugin eventer Broken Access Control ≤ 3.11.4 Fixed in 3.11.4 CVE-2025-39482 Patchstack
5.3 Medium EventON Plugin eventon Broken Access Control No login needed ≤ 4.9.8 CVE-2025-47564 Patchstack
5.3 Medium EventON Plugin eventon-lite Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-48116 Patchstack
3.5 Low Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Cross-Site Scripting Admin+ Stored XSS < 2.3.8 Fixed in 2.3.8 CVE-2024-6711 WPScan
6.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update 3.4.9 – < 3.5.0 Fixed in 3.5.0 CVE-2024-4665 WPScan
4.8 Medium Event Calendar Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.4 CVE-2024-8701 WPScan
7.5 High Event Calendar Plugin Broken Access Control Unauthenticated Arbitrary Calendar Deletion No login needed ≤ 1.0.4 CVE-2024-8700 WPScan
4.8 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Admin+ Stored XSS < 6.6.4 Fixed in 6.6.4 CVE-2024-8493 WPScan
7.5 High Eventin Plugin wp-event-solution Path Traversal Arbitrary File Download No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2025-47445 Patchstack
7.5 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Path Traversal Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read No login needed ≤ 4.0.26 CVE-2025-3419 Wordfence
7.5 High XT Event Widget for Social Events Plugin xt-facebook-events Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-47531 Patchstack
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-47519 Patchstack
7.5 High Display Eventbrite Events Plugin widget-for-eventbrite-api Local File Inclusion ≤ 6.3 Fixed in 6.3 CVE-2025-47510 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-47494 Patchstack
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Information Disclosure Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.8.8 CVE-2025-3923 Wordfence
5.4 Medium Prevent Direct Access Plugin prevent-direct-access Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Multiple Media Actions 2.8.6 – 2.8.8.2 CVE-2025-3861 Wordfence
8.8 High My Tickets – Accessible Event Ticketing Plugin my-tickets Privilege Escalation Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation ≤ 2.0.16 CVE-2025-3761 Wordfence
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.9.11 Fixed in 5.10.0 CVE-2025-46228 Patchstack
7.1 High HT Event Plugin ht-event Cross-Site Scripting WordPress Event Manager Plugin for Elementor Plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-24624 Patchstack
5.3 Medium MyTicket Events Plugin myticket-events Path Traversal Non-Arbitrary File Read No login needed ≤ 1.2.4 CVE-2025-27299 Patchstack
7.1 High Event Espresso – Custom Email Template Shortcode Plugin email-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-32507 Patchstack
7.5 High Simple WP Events Plugin simple-wp-events Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32594 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion ≤ 4.0.25 Fixed in 4.0.26 CVE-2025-39584 Patchstack
8.8 High EventON Plugin eventon-lite Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4.1 CVE-2025-32614 Patchstack
7.5 High Simple WP Events Plugin simple-wp-events Arbitrary File Deletion No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32509 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-32160 Patchstack
8.8 High WpEvently Plugin mage-eventpress PHP Object Injection ≤ 4.3.6 Fixed in 4.3.7 CVE-2025-32145 Patchstack
7.1 High WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Request Forgery connectDaily plugin <= 1.5.4 - CSRF to Cross-Site Scripting No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-32597 Patchstack
9.1 Critical Simple WP Events Plugin simple-wp-events Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.8.17 CVE-2025-2004 Wordfence
5.3 Medium WP Event Manager Plugin wp-event-manager Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32225 Patchstack
6.5 Medium Simple WP Events Plugin simple-wp-events Cross-Site Scripting ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32193 Patchstack
6.5 Medium Tockify Events Calendar Plugin tockify-events-calendar Cross-Site Scripting ≤ 2.2.13 Fixed in 2.3.0 CVE-2025-32174 Patchstack
7.1 High Awesome Event Booking Plugin awesome-event-booking Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.4 Fixed in 2.8.5 CVE-2025-31416 Patchstack
6.4 Medium Minimalistic Event Manager Plugin minimalistic-event-manager Broken Access Control ≤ 1.1.1 CVE-2025-31739 Patchstack
7.1 High CGM Event Calendar Plugin cgm-event-calendar Cross-Site Scripting No login needed ≤ 0.8.5 CVE-2025-31462 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only