WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 301–350 of 425 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WPFront User Role Editor Plugin wpfront-user-role-editor Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function No login needed ≤ 4.2.1 CVE-2025-3064 Wordfence
7.5 High Read More & Accordion Plugin expand-maker Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 3.4.7 CVE-2025-0810 Wordfence
7.1 High Useinfluence Plugin useinfluence Cross-Site Request Forgery No login needed ≤ 1.0.8 CVE-2025-31625 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
7.1 High Video Embedder Plugin video-embedder Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.7.1 Fixed in 1.8 CVE-2025-31458 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
7.6 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.5.0 CVE-2025-1912 Wordfence
8.8 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed 4.11.13 – 5.25.08 CVE-2025-2319 Wordfence
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
7.1 High AdSense Privacy Policy Plugin adsense-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30578 Patchstack
7.1 High Browser Address Bar Color Plugin browser-address-bar-color Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3 Fixed in 3.4 CVE-2025-30577 Patchstack
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
7.6 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.2 CVE-2025-1970 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
8.8 High InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 0.1.0.83 CVE-2024-13913 Wordfence
7.5 High LoginPress Plugin loginpress Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.3.1 CVE-2025-1764 Wordfence
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
8.8 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.4.2 CVE-2024-11640 Wordfence
8.8 High Newscrunch Theme newscrunch Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1306 Wordfence
8.8 High Cardealer Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Update via update_user_profile No login needed ≤ 1.6.4 CVE-2025-1687 Wordfence
8.1 High Ultimate Classified Listings Plugin ultimate-classified-listings Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover No login needed ≤ 1.5 CVE-2024-13753 Wordfence
8.8 High Shopwarden – Automated WooCommerce monitoring & testing Plugin shopwarden Cross-Site Request Forgery Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0.11 CVE-2024-13315 Wordfence
8.8 High Option Editor Plugin option-editor Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0 CVE-2024-13852 Wordfence
8.1 High Reset Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Database Reset No login needed ≤ 1.6 CVE-2024-13684 Wordfence
8.1 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Account Deletion No login needed ≤ 2.7.3 CVE-2024-12386 Wordfence
7.1 High Forge – Front-End Page Builder Plugin forge Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-22703 Patchstack
8.8 High WP Image Uploader Plugin wp-image-uploader Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.0.1 CVE-2024-13707 Wordfence
8.8 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.7.2 CVE-2024-11641 Wordfence
7.1 High Better Protected Pages Plugin better-protected-pages Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-23875 Patchstack
7.1 High Copyright Safeguard Footer Notice Plugin copyright-safeguard-footer-notice Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 3.0 CVE-2025-23870 Patchstack
7.1 High MHR-Custom-Anti-Copy Plugin mhr-custom-anti-copy Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 2.0 CVE-2025-23817 Patchstack
8.5 High W3 Total Cache Plugin w3-total-cache Broken Access Control Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery ≤ 2.8.1 CVE-2024-12365 Wordfence
8.8 High ThePerfectWedding.nl Widget Plugin theperfectweddingnl-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.8 CVE-2024-12322 Wordfence
8.8 High ListingPro Theme listingpro Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39623 Patchstack
8.8 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Request Forgery Cross-Site Request Forgery to Password Reset No login needed ≤ 3.3.43 CVE-2024-12771 Wordfence
8.8 High User Role Editor Plugin user-role-editor Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.64.3 CVE-2024-12293 Wordfence
7.6 High WP All Import Pro Plugin Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via File Import ≤ 4.9.3 CVE-2024-9624 Wordfence
7.2 High Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.83 Fixed in 2.0.85 CVE-2024-54385 Patchstack
7.1 High Increase Sociability Plugin increase-sociability Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.0 CVE-2024-54395 Patchstack
7.1 High Visual Recent Posts Plugin visual-recent-posts Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.3 CVE-2024-54403 Patchstack
7.2 High Hurrakify Plugin hurrakify Server-Side Request Forgery No login needed ≤ 2.4 Fixed in 8.0.1 CVE-2024-54330 Patchstack
8.8 High HQ Rental Software Plugin hq-rental-software Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.29 CVE-2024-11689 Wordfence
7.1 High Out Of Stock Badge Plugin out-of-stock-badge Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2024-53754 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only