WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,551–3,600 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 72 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Import external attachments Plugin import-external-attachments Cross-Site Request Forgery No login needed ≤ 1.5.12 CVE-2025-53268 Patchstack
4.3 Medium Hide Admin Bar From Front End Plugin hide-admin-bar-from-front-end Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-53267 Patchstack
4.3 Medium Cron Logger Plugin cron-logger Broken Access Control ≤ 1.3.0 CVE-2025-53266 Patchstack
5.4 Medium Virusdie Plugin virusdie Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-53265 Patchstack
4.3 Medium ONet Regenerate Thumbnails Plugin onet-regenerate-thumbnails Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-53264 Patchstack
5.4 Medium Address Autocomplete via Google for Gravity Forms Plugin gf-google-address-autocomplete Cross-Site Request Forgery No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-53263 Patchstack
5.4 Medium Writesonic Plugin writesonic Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-53262 Patchstack
4.3 Medium WP YouTube Live Plugin wp-youtube-live Cross-Site Request Forgery No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-53261 Patchstack
5.3 Medium HurryTimer Plugin hurrytimer Broken Access Control No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2025-53255 Patchstack
4.3 Medium Cyrlitera Plugin cyrlitera Cross-Site Request Forgery No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-53254 Patchstack
5.9 Medium WP Edit Plugin wp-edit Cross-Site Scripting ≤ 4.0.4 CVE-2025-53253 Patchstack
5.3 Medium Audio Editor & Recorder Plugin audio-editor-recorder Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-53211 Patchstack
6.5 Medium HT Mega – Absolute Addons for WPBakery Page Builder Plugin ht-mega-for-wpbakery Cross-Site Scripting Absolute Addons for WPBakery Page Builder plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-53206 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
6.5 Medium Responsive Blocks Plugin responsive-block-editor-addons Cross-Site Scripting ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-53202 Patchstack
4.3 Medium ChatBot Plugin chatbot Broken Access Control ≤ 6.7.3 Fixed in 6.7.5 CVE-2025-53200 Patchstack
6.5 Medium HT Slider For Elementor Plugin ht-slider-for-elementor Cross-Site Scripting ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-53199 Patchstack
4.3 Medium Cookiebot Plugin cookiebot Cross-Site Request Forgery No login needed ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-53197 Patchstack
4.3 Medium Burst Statistics Plugin burst-statistics Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.8 CVE-2025-53193 Patchstack
4.3 Medium DarkMySite Plugin darkmysite Cross-Site Request Forgery No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-32281 Patchstack
6.4 Medium A/B Testing Plugin ab-testing-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.18.2 CVE-2025-4587 Wordfence
6.4 Medium TableOn – WordPress Posts Table Filterable Plugin posts-table-filterable Cross-Site Scripting WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode ≤ 1.0.4.1 CVE-2025-5143 Wordfence
4.3 Medium ClipLink Plugin cliplink Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49964 Patchstack
4.3 Medium Oganro Travel Portal Search Widget for HotelBeds APITUDE API Plugin oganro-travel-portal-search-widget-for-hotelbeds-apitude-api Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49966 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium XML Travel Portal Widget Plugin oganro-reservation-widget Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-49968 Patchstack
4.3 Medium Live Sports Streamthunder Plugin live-sports-streamthunder Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-49967 Patchstack
4.3 Medium Zara 4 Image Compression Plugin zara-4 Broken Access Control ≤ 1.2.17.2 CVE-2025-49969 Patchstack
4.3 Medium Hello FSE Blog Plugin hello-fse-blog Broken Access Control ≤ 1.0.6 CVE-2025-49970 Patchstack
4.3 Medium eDS Responsive Menu Plugin eds-responsive-menu Broken Access Control ≤ 1.2 CVE-2025-49971 Patchstack
4.3 Medium Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes Plugin image-sizes-controller Broken Access Control ≤ 1.0.10 CVE-2025-49973 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
4.3 Medium UpStream: a Project Management Plugin upstream Broken Access Control ≤ 2.1.1 CVE-2025-49974 Patchstack
4.3 Medium Notifier Plugin notifier Broken Access Control ≤ 2.7.12 Fixed in 2.7.13 CVE-2025-49976 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-49975 Patchstack
4.3 Medium JobSearch Plugin wp-jobsearch Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.0.6 Fixed in 3.0.6 CVE-2025-49978 Patchstack
4.3 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Request Forgery No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-49977 Patchstack
4.3 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Broken Access Control ≤ 1.0.6 CVE-2025-49980 Patchstack
4.3 Medium Media Hygiene Plugin media-hygiene Broken Access Control ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-49979 Patchstack
4.3 Medium WP Customer Area Plugin customer-area Broken Access Control ≤ 8.3.4 CVE-2025-49982 Patchstack
4.3 Medium User Roles and Capabilities Plugin user-roles-and-capabilities Broken Access Control ≤ 1.2.6 CVE-2025-49981 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.13.11 Fixed in 11.13.12 CVE-2025-49984 Patchstack
4.9 Medium WPThumb Plugin wp-thumb Server-Side Request Forgery ≤ 0.10 CVE-2025-49983 Patchstack
5.3 Medium Video List Manager Plugin video-list-manager Broken Access Control No login needed ≤ 1.7 CVE-2025-49986 Patchstack
4.9 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery ≤ 3.3.2 CVE-2025-49985 Patchstack
5.3 Medium Contact Form 7 AWeber Extension Plugin integrate-contact-form-7-and-aweber Broken Access Control No login needed ≤ 0.1.40 Fixed in 0.1.43 CVE-2025-49988 Patchstack
5.3 Medium CRM ERP Business Solution Plugin crm-erp-business-solution Broken Access Control No login needed ≤ 1.13 CVE-2025-49987 Patchstack
5.3 Medium Contentstudio Plugin contentstudio Broken Access Control No login needed ≤ 1.3.7 Fixed in 1.4.0 CVE-2025-49990 Patchstack
5.3 Medium App Builder Plugin app-builder Broken Access Control No login needed ≤ 5.5.6 Fixed in 5.5.8 CVE-2025-49989 Patchstack
5.3 Medium Cookie-Script.com Plugin cookie-script-com Broken Access Control No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-49993 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only