WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 351–400 of 1,027 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 21
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5 Fixed in 1.5.1 CVE-2024-37945 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-54673 Patchstack
4.2 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Visual Drag and Drop Editor <= 1.27.8 - Path Traversal ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52712 Patchstack
6.4 Medium RT Easy Builder Plugin rt-easy-builder-advanced-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3 CVE-2025-8462 Wordfence
5.9 Medium OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.2.0 CVE-2025-6572 WPScan
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.5 CVE-2025-7502 Wordfence
4.3 Medium Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Plugin header-footer-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 2.4.6 CVE-2025-8488 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.10 CVE-2025-7646 Wordfence
6.4 Medium Supreme Addons for Beaver Builder Plugin supreme-addons-for-beaver-builder-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_qrcodesabb Shortcode ≤ 1.0.9 CVE-2025-3669 Wordfence
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements ≤ 8.4.1 CVE-2025-4968 Wordfence
6.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.4.8 CVE-2025-4685 Wordfence
4.9 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator SQL Injection Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter ≤ 1.45.0 CVE-2025-7638 Wordfence
6.5 Medium Theme Builder For Elementor Plugin theme-builder-for-elementor Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-54033 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-54006 Patchstack
6.4 Medium Avada (Fusion) Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.1 CVE-2025-6747 Wordfence
6.4 Medium Kadence Blocks – Gutenberg Blocks for Page Builder Features Plugin kadence-blocks Cross-Site Scripting Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter ≤ 3.5.10 CVE-2025-5678 Wordfence
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack
6.3 Medium Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm Broken Access Control Missing Authorization to Authenticated (Subscriber+) Many Actions ≤ 3.1 CVE-2025-5692 Wordfence
6.4 Medium WP VR – 360 Panorama and Free Virtual Tour Builder Plugin wpvr Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.5.32 CVE-2025-6350 Wordfence
6.5 Medium My Resume Builder Plugin my-resume-builder Cross-Site Scripting ≤ 1.0.3 CVE-2025-53336 Patchstack
6.5 Medium HT Mega – Absolute Addons for WPBakery Page Builder Plugin ht-mega-for-wpbakery Cross-Site Scripting Absolute Addons for WPBakery Page Builder plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-53206 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
5.3 Medium App Builder Plugin app-builder Broken Access Control No login needed ≤ 5.5.6 Fixed in 5.5.8 CVE-2025-49989 Patchstack
6.5 Medium Enhanced Blocks – Page Builder Blocks for Gutenberg Plugin enhanced-blocks Broken Access Control Page Builder Blocks for Gutenberg plugin <= 1.4.1 - Broken Access Control ≤ 1.4.1 CVE-2025-50034 Patchstack
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder ≤ 8.4.1 CVE-2025-4965 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 6.1.12 CVE-2024-9994 Wordfence
5.3 Medium Taskbuilder Plugin taskbuilder Broken Access Control No login needed ≤ 4.0.7 Fixed in 4.0.8 CVE-2025-30945 Patchstack
6.5 Medium BlockStrap Page Builder - Bootstrap Blocks Plugin blockstrap-page-builder-blocks Cross-Site Scripting Bootstrap Blocks plugin <= 0.1.36 - Cross Site Scripting (XSS) ≤ 0.1.36 Fixed in 0.1.37 CVE-2025-30951 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 11.5.5 Fixed in 11.5.7 CVE-2025-49301 Patchstack
4.3 Medium Profile Builder Plugin profile-builder Content Injection Content Spoofing No login needed ≤ 3.13.8 Fixed in 3.13.9 CVE-2025-49292 Patchstack
4.3 Medium WP Table Builder Plugin wp-table-builder Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-49286 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.2.7 Fixed in 6.2.8 CVE-2025-49076 Patchstack
6.4 Medium BM Content Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save ≤ 3.16.2.1 CVE-2025-1777 Wordfence
6.4 Medium Profile Builder Plugin profile-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes ≤ 3.13.8 CVE-2025-4671 Wordfence
5.6 Medium Ninja Tables – Easy Data Table Builder Plugin ninja-tables PHP Object Injection Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution No login needed ≤ 5.0.18 CVE-2025-2939 Wordfence
6.4 Medium Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder Plugin Cross-Site Scripting Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.11.2 CVE-2025-5292 Wordfence
6.5 Medium Woo Slider Pro - Drag Drop Slider Builder For WooCommerce Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Drag Drop Slider Builder For WooCommerce <= 1.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 1.12 CVE-2025-4597 Wordfence
6.5 Medium Woo Slider Pro Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.12 CVE-2025-48334 Patchstack
6.4 Medium Bold Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via additional_settings Parameter ≤ 5.3.6 CVE-2025-5286 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
4.7 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter No login needed ≤ 2.0.0 CVE-2025-4223 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link ≤ 2.0.0 CVE-2024-13427 Wordfence
6.5 Medium Custom PC Builder Lite for WooCommerce Plugin custom-pc-builder-lite-for-woocommerce Broken Access Control Settings Change No login needed ≤ 1.0.1 CVE-2025-43838 Patchstack
5.9 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.74 Fixed in 3.5.0 CVE-2025-48277 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.11.0 Fixed in 45.12.0 CVE-2025-48276 Patchstack
6.5 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Cross-Site Scripting Lite plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48232 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter ≤ 5.3.5 CVE-2025-3715 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only