WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,901–3,950 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 79 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP w3all phpBB Plugin wp-w3all-phpbb-integration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.9.9 Fixed in 3.0.0 CVE-2025-32575 Patchstack
7.1 High DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.7.1 Fixed in 5.8.2 CVE-2025-32580 Patchstack
7.1 High WordPress Spam Blocker Plugin cf7-manual-spam-blocker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.5 CVE-2025-32581 Patchstack
7.1 High Chat2 Plugin chat2 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0 Fixed in 4.1 CVE-2025-32584 Patchstack
7.1 High WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Request Forgery connectDaily plugin <= 1.5.4 - CSRF to Cross-Site Scripting No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-32597 Patchstack
7.1 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.7.5 CVE-2025-32591 Patchstack
7.1 High User Session Synchronizer Plugin user-session-synchronizer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 CVE-2025-32612 Patchstack
7.1 High Foliopress WYSIWYG Plugin foliopress-wysiwyg Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.18 CVE-2025-32610 Patchstack
7.1 High Nimbata Call Tracking Plugin nimbata-call-tracking Cross-Site Request Forgery No login needed ≤ 1.7.4 CVE-2025-32616 Patchstack
7.1 High Multiple Location Google Map Plugin multiple-location-google-map Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-32617 Patchstack
7.1 High WP Map Route Planner Plugin wp-map-route-planner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-32621 Patchstack
7.1 High KeyCAPTCHA Plugin keycaptcha Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-32619 Patchstack
7.1 High PlainInventory Plugin z-inventory-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.1.9 CVE-2025-32623 Patchstack
7.1 High Czater.pl – live chat i telefon Plugin czater Cross-Site Request Forgery live chat i telefon plugin <= 1.0.5 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2025-32624 Patchstack
7.1 High Custom Posts Order Plugin custom-posts-order Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.4 CVE-2025-32645 Patchstack
7.1 High IP2Location World Clock Plugin ip2location-world-clock Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.9 Fixed in 1.1.10 CVE-2025-32644 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
7.1 High Nepali Date Utilities Plugin nepali-date-utilities Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.15 CVE-2025-32664 Patchstack
7.1 High Interactive US Map Plugin interactive-us-map Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.7 CVE-2025-32661 Patchstack
7.1 High Doppler Forms Plugin doppler-form Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 Fixed in 2.6.0 CVE-2025-32667 Patchstack
7.1 High Epeken All Kurir Plugin epeken-all-kurir Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-32673 Patchstack
7.1 High Mergado Pack Plugin mergado-marketing-pack Cross-Site Request Forgery No login needed ≤ 4.2.1 CVE-2025-32669 Patchstack
7.6 High WP Social Stream Designer Plugin social-stream-design SQL Injection ≤ 1.3 CVE-2025-32677 Patchstack
7.6 High Verowa Connect Plugin verowa-connect SQL Injection ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-32676 Patchstack
7.6 High WP Inquiries Plugin wp-inquiries SQL Injection ≤ 0.2.1 CVE-2025-32685 Patchstack
7.5 High WP Subscription Forms Plugin wp-subscription-forms Local File Inclusion ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-32692 Patchstack
7.1 High Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2025-32117 Patchstack
7.5 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin Path Traversal WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download No login needed ≤ 6.91 CVE-2025-3431 Wordfence
8.1 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin Broken Access Control WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipulation ≤ 6.91 CVE-2024-13776 Wordfence
7.6 High Split Test For Elementor Plugin split-test-for-elementor SQL Injection ≤ 1.8.3 Fixed in 1.8.4 CVE-2025-32204 Patchstack
7.6 High Falling things Plugin falling-things SQL Injection ≤ 1.08 Fixed in 1.09 CVE-2025-32203 Patchstack
7.5 High Radius Blocks Plugin radius-blocks Local File Inclusion ≤ 2.2.1 CVE-2025-32159 Patchstack
7.5 High Sparkle Elementor Kit Plugin sparkle-elementor-kit Local File Inclusion ≤ 2.0.9 CVE-2025-32157 Patchstack
7.5 High Just Post Preview Widget Plugin just-post-preview Local File Inclusion ≤ 1.1.1 CVE-2025-32156 Patchstack
7.5 High Beds24 Online Booking Plugin beds24-online-booking Local File Inclusion ≤ 2.0.28 Fixed in 2.0.29 CVE-2025-32155 Patchstack
7.5 High Catch Dark Mode Plugin catch-dark-mode Local File Inclusion ≤ 2.0.1 Fixed in 2.1 CVE-2025-32154 Patchstack
7.5 High VG WooCarousel Plugin vg-woocarousel Local File Inclusion ≤ 1.3 CVE-2025-32153 Patchstack
7.5 High Slider a SlidersPack Plugin sliderspack-all-in-one-image-sliders Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2025-32152 Patchstack
7.5 High BuddyForms Plugin buddyforms Local File Inclusion ≤ 2.10.2 Fixed in 2.10.4 CVE-2025-32151 Patchstack
7.5 High Real Estate Manager Plugin real-estate-manager Local File Inclusion ≤ 7.3 CVE-2025-32150 Patchstack
8.5 High teachPress Plugin teachpress SQL Injection ≤ 9.0.11 Fixed in 9.0.12 CVE-2025-32149 Patchstack
8.5 High Daisycon prijsvergelijkers Plugin daisycon SQL Injection ≤ 4.8.4 Fixed in 4.9.0 CVE-2025-32148 Patchstack
8.8 High Easy WP Optimizer Plugin easy-wp-optimizer Broken Access Control ≤ 1.1.0 CVE-2025-32147 Patchstack
8.8 High JS Job Manager Plugin js-jobs Local File Inclusion ≤ 2.0.2 CVE-2025-32146 Patchstack
8.8 High Motors Plugin motors-car-dealership-classified-listings Local File Inclusion ≤ 1.4.71 Fixed in 1.4.72 CVE-2025-32142 Patchstack
8.8 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion ≤ 3.5.28 Fixed in 3.5.29 CVE-2025-32141 Patchstack
7.6 High onOffice for WP-Websites Plugin onoffice-for-wp-websites SQL Injection ≤ 5.7 Fixed in 6.5.1 CVE-2025-32127 Patchstack
7.6 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 SQL Injection ≤ 1.0.4 CVE-2025-32126 Patchstack
7.6 High Silvasoft boekhouden Plugin silvasoft-boekhouden SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-32125 Patchstack
7.6 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-32124 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only