WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,451–3,500 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 70 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54050 Patchstack
4.3 Medium Cost Calculator Plugin ql-cost-calculator Broken Access Control ≤ 7.4 Fixed in 7.5 CVE-2025-54047 Patchstack
4.3 Medium WP Post Hide Plugin wp-post-hide Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-54042 Patchstack
4.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-54041 Patchstack
4.3 Medium Animator Plugin scroll-triggered-animations Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2025-54039 Patchstack
5.4 Medium Restaurant Menu by MotoPress Plugin mp-restaurant-menu Cross-Site Request Forgery No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-54038 Patchstack
5.4 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-54037 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Cross-Site Request Forgery No login needed ≤ 5.1.20 Fixed in 5.1.21 CVE-2025-54036 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-54035 Patchstack
6.5 Medium Theme Builder For Elementor Plugin theme-builder-for-elementor Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-54033 Patchstack
4.3 Medium WooCommerce Google Sheet Connector Plugin wc-gsheetconnector Cross-Site Request Forgery No login needed ≤ 1.3.20 Fixed in 1.4.0 CVE-2025-54030 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-54024 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54023 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Cross-Site Request Forgery No login needed ≤ 6.4.0 Fixed in 6.4.1 CVE-2025-54022 Patchstack
5.4 Medium AntiSpam for Contact Form 7 Plugin cf7-antispam Cross-Site Request Forgery No login needed ≤ 0.6.3 Fixed in 0.6.4 CVE-2025-54020 Patchstack
4.3 Medium CM Pop-Up banners Plugin cm-pop-up-banners Broken Access Control ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54018 Patchstack
6.5 Medium Videopack Plugin video-embed-thumbnail-generator Cross-Site Scripting ≤ 4.10.3 Fixed in 4.10.4 CVE-2025-54016 Patchstack
6.6 Medium HT Contact Form 7 Plugin ht-contactform Local File Inclusion ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-54015 Patchstack
5.9 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting ≤ 2.11.16 Fixed in 2.11.17 CVE-2025-54013 Patchstack
4.3 Medium SMTP2GO Plugin smtp2go Broken Access Control ≤ 1.12.1 Fixed in 1.12.2 CVE-2025-54011 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Cross-Site Scripting ≤ 3.6.8 Fixed in 3.6.8.1 CVE-2025-54009 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-54006 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 4.0.4 Fixed in 4.1.1 CVE-2025-53997 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.5.10.1 Fixed in 3.5.11 CVE-2025-53996 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15.1 Fixed in 2.0.16 CVE-2025-53995 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53994 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53991 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.19 Fixed in 1.3.19.1 CVE-2025-53989 Patchstack
5.3 Medium Hestia Plugin hestia Broken Access Control No login needed ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-53986 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53984 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53982 Patchstack
5.3 Medium Guest Support – Complete customer support ticket system Plugin guest-support Broken Access Control Complete customer support ticket system for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Ticket Deletion No login needed ≤ 1.2.2 CVE-2025-5957 Wordfence
6.4 Medium Lightbox & Modal Popup WordPress Plugin – FooBox Plugin foobox-image-lightbox Cross-Site Scripting FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.7.34 CVE-2025-5537 Wordfence
6.5 Medium Email Address Security by WebEmailProtector Plugin webemailprotector Cross-Site Scripting ≤ 3.3.6 CVE-2025-28976 Patchstack
5.3 Medium WP Compress Plugin wp-compress-image-optimizer Authentication Bypass Broken Authentication No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47479 Patchstack
6.3 Medium EventON Plugin eventon Broken Access Control ≤ 4.9.9 CVE-2025-47565 Patchstack
6.5 Medium WC Pickup Store Plugin wc-pickup-store Broken Access Control Settings Change No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2025-47634 Patchstack
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
6.8 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Path Traversal Arbitrary File Download ≤ 3.28.7 Fixed in 3.28.8 CVE-2025-49303 Patchstack
6.5 Medium VG WORT METIS Plugin vgw-metis Broken Access Control ≤ 2.0.1 CVE-2025-50039 Patchstack
6.5 Medium Paytiko for WooCommerce Plugin paytiko Broken Access Control ≤ 1.3.21 CVE-2025-50032 Patchstack
6.5 Medium MF Plus WPML Plugin mf-plus-wpml Broken Access Control Settings Change No login needed ≤ 1.1 CVE-2025-49431 Patchstack
6.5 Medium Card flip image slideshow Plugin card-flip-image-slideshow Cross-Site Scripting ≤ 1.5 CVE-2025-30983 Patchstack
6.5 Medium Posts Slider Shortcode Plugin posts-slider-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-30943 Patchstack
5.3 Medium fluXtore Plugin fluxtore Broken Access Control No login needed ≤ 1.6.0 Fixed in 1.6.3 CVE-2025-30929 Patchstack
5.3 Medium CF7 7 Mailchimp Add-on Plugin cf7-mailchimp-addon Broken Access Control No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-29012 Patchstack
4.3 Medium LMSACE Connect Plugin lmsace-connect Broken Access Control ≤ 3.4 CVE-2025-29007 Patchstack
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack
5.9 Medium Easy Elements Hider Plugin easy-elements-hider Cross-Site Scripting ≤ 2.0 CVE-2025-28971 Patchstack
5.4 Medium URL Shortener Plugin exact-links Server-Side Request Forgery No login needed ≤ 3.0.7 CVE-2025-28963 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only