WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,801–3,850 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 77 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Maintenance Mode & Site Under Construction Plugin wp-maintenance-mode-site-under-construction Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2025-49284 Patchstack
4.3 Medium Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Plugin gdpr-compliant-recaptcha-for-all-forms Cross-Site Request Forgery No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-49283 Patchstack
4.3 Medium WP Tools Plugin wptools Cross-Site Request Forgery No login needed ≤ 5.24 Fixed in 5.25 CVE-2025-49273 Patchstack
4.3 Medium Trinity Audio Plugin trinity-audio Broken Access Control ≤ 5.20.0 Fixed in 5.20.1 CVE-2025-49272 Patchstack
5.3 Medium WP-CRM System Plugin wp-crm-system Broken Access Control No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-49270 Patchstack
4.3 Medium Market Exporter Plugin market-exporter Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2025-49269 Patchstack
5.3 Medium Verge3D Plugin verge3d Broken Access Control No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2025-49268 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Arbitrary Shortcode Execution ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49250 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Broken Access Control ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49248 Patchstack
4.3 Medium Testimonials Showcase Plugin testimonials-showcase Broken Access Control ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49246 Patchstack
6.5 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting ≤ 7.3.5 Fixed in 7.4.0 CVE-2025-49244 Patchstack
6.5 Medium ShiftNav – Responsive Mobile Menu Plugin shiftnav-responsive-mobile-menu Cross-Site Scripting Responsive Mobile Menu plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.8.1 CVE-2025-49243 Patchstack
6.5 Medium Bellows Accordion Menu Plugin bellows-accordion-menu Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-49242 Patchstack
5.3 Medium oik Plugin oik Broken Access Control No login needed ≤ 4.15.1 Fixed in 4.15.2 CVE-2025-49241 Patchstack
4.3 Medium DocsPress Plugin docspress Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-49240 Patchstack
5.4 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery No login needed ≤ 5.5.0 Fixed in 5.6.0 CVE-2025-49239 Patchstack
4.3 Medium Everest Backup Plugin everest-backup Cross-Site Request Forgery No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2025-49238 Patchstack
5.3 Medium Raychat Plugin raychat Broken Access Control No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2025-49236 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-49235 Patchstack
5.4 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-48335 Patchstack
4.3 Medium Real Time Validation for Gravity Forms Plugin real-time-validation-for-gravity-forms Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.7.0 CVE-2025-48328 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.2.7 Fixed in 6.2.8 CVE-2025-49076 Patchstack
6.5 Medium Wishlist Plugin wishlist Cross-Site Scripting ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-49075 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-49074 Patchstack
6.5 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-49068 Patchstack
6.5 Medium Nasa Core Plugin nasa-core Cross-Site Scripting ≤ 6.4.1 Fixed in 6.4.1 CVE-2025-49067 Patchstack
4.3 Medium Dynamic Pricing and Discount Rules Plugin discount-and-dynamic-pricing Cross-Site Request Forgery No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2025-49077 Patchstack
5.3 Medium QuickCab Plugin quickcab Broken Access Control No login needed ≤ 1.3.3 CVE-2025-48337 Patchstack
6.4 Medium WordPress Ajax Load More and Infinite Scroll Plugin cpt-ajax-load-more Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.6.0 CVE-2025-5586 Wordfence
6.4 Medium ESV Bible Shortcode Plugin esv-bible-shortcode-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-5534 Wordfence
6.5 Medium Uncanny Automator Plugin uncanny-automator Broken Access Control No login needed ≤ 6.4.0.2 Fixed in 6.5.0 CVE-2025-48133 Patchstack
5.4 Medium Element Pack Pro Plugin bdthemes-element-pack Broken Access Control < 8.0.0 Fixed in 8.0.0 CVE-2025-46258 Patchstack
4.3 Medium Element Pack Pro Plugin bdthemes-element-pack Cross-Site Request Forgery No login needed < 8.0.0 Fixed in 8.0.0 CVE-2025-46257 Patchstack
6.4 Medium Staff Directory – Employee Directory Plugin Cross-Site Scripting Employee Directory for WordPress <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.0 CVE-2025-5531 Wordfence
6.4 Medium Bit File Manager – 100% Free & Open Source File Manager and Code Editor Plugin file-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads ≤ 6.7 CVE-2025-1725 Wordfence
6.1 Medium FancyBox Plugin fancybox-for-wordpress Cross-Site Scripting Unauthenticated Stored XSS No login needed < 3.3.6 Fixed in 3.3.6 CVE-2025-3662 WPScan
6.4 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.4.3 CVE-2025-3919 Wordfence
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2025-47585 Patchstack
4.3 Medium Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery No login needed ≤ 1.9.8 Fixed in 1.9.9 CVE-2025-49069 Patchstack
6.5 Medium Woo Slider Pro Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.12 CVE-2025-48334 Patchstack
6.1 Medium WordPress Gearside Developer Dashboard Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.72 CVE-2025-4429 WPScan
5.9 Medium Volunteer Sign Up Sheets Plugin pta-volunteer-sign-up-sheets Cross-Site Scripting ≤ 5.5.5 Fixed in 5.5.5 CVE-2025-3704 Patchstack
5.3 Medium Spotlight - Social Media Feeds (Premium) Plugin spotlight-social-photo-feeds-premium Information Disclosure Social Media Feeds (Premium) plugin <= 1.7.1 - Sensitive Data Exposure No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2025-39498 Patchstack
4.9 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.7 Fixed in 7.1.8 CVE-2025-46486 Patchstack
6.5 Medium Crossword Compiler Puzzles Plugin crossword-compiler-puzzles Cross-Site Scripting ≤ 14.5 CVE-2025-46493 Patchstack
6.5 Medium IGIT Related Posts With Thumb Image After Posts Plugin igit-related-posts-with-thumb-images-after-posts Cross-Site Scripting ≤ 4.5.3 CVE-2025-46518 Patchstack
6.5 Medium Web3Press Plugin likecoin Path Traversal Decentralize Publishing with Writing NFT plugin <= 3.2.0 - Arbitrary File Read ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-46527 Patchstack
6.5 Medium Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget Broken Access Control Call To Action, Sticky CTA, Floating Button Plugin <= 1.1.1 - Settings Change No login needed ≤ 1.1.1 Fixed in 1.2.1 CVE-2025-47529 Patchstack
4.9 Medium Infocob CRM Forms Plugin infocob-crm-forms Path Traversal Arbitrary File Download ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-47513 Patchstack
6.5 Medium 6Storage Rentals Plugin 6storage-rentals Broken Access Control ≤ 2.20.2 CVE-2025-47619 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only