WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 351–400 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High More Mime Type Filters Plugin more-mime-type-filters Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-31394 Patchstack
7.1 High Social Bookmarking RELOADED Plugin social-bookmarking-reloaded Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.18 CVE-2025-31393 Patchstack
7.1 High CG Scroll To Top Plugin cg-scroll-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.5 CVE-2025-31399 Patchstack
7.1 High Easy Custom CSS Plugin easy-custom-css Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31395 Patchstack
7.1 High WS Audio Player Plugin ws-audio-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.8 CVE-2025-31400 Patchstack
7.1 High NewsBoard Post and RSS Scroller Plugin newsboard Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.12 CVE-2025-31402 Patchstack
7.1 High MMX – Make Me Christmas Plugin mmx-make-me-christmas Cross-Site Request Forgery Make Me Christmas plugin <= 1.0.0 - CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-31401 Patchstack
7.1 High Advanced Tag Lists Plugin advanced-tag-list Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-32476 Patchstack
7.1 High AF Tell a Friend Plugin af-tell-a-friend Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-31404 Patchstack
7.1 High WP-Easy Menu Plugin wp-easy-menu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.41 CVE-2025-32477 Patchstack
7.1 High Flags Widget Plugin flags-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.7 CVE-2025-32479 Patchstack
7.1 High WP SexyLightBox Plugin wp-sexylightbox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5.3 CVE-2025-32478 Patchstack
7.1 High Windows Live Writer Plugin windows-live-writer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-32480 Patchstack
7.1 High Custom Smilies Plugin custom-smilies Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-32482 Patchstack
7.1 High Nino Social Connect Plugin nino-social-connect Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-32481 Patchstack
7.1 High WP-Planification Plugin wp-planification Cross-Site Request Forgery WP-Planning plugin <= 2.3.1 - CSRF to Stored XSS No login needed ≤ 2.3.1 CVE-2025-32484 Patchstack
7.1 High VKontakte Cross-Post Plugin vkontakte-cross-post Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-32498 Patchstack
7.1 High Spoiler Block Plugin spoiler-block Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-32497 Patchstack
7.1 High Rentsyst Plugin rentsyst Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.92 Fixed in 2.0.93 CVE-2025-32501 Patchstack
7.1 High Codescar Radio Widget Plugin codescar-radio-widget Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.4.2 CVE-2025-32500 Patchstack
7.1 High Link Shield Plugin link-shield Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.5.4 CVE-2025-32503 Patchstack
7.1 High ePaper Lister for Yumpu Plugin magazine-lister-for-yumpu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 CVE-2025-32502 Patchstack
7.1 High MultiMailer Plugin scand-multi-mailer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.3 CVE-2025-32505 Patchstack
7.1 High ALD Login Page Plugin ald-login-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 Fixed in 1.3 CVE-2025-32518 Patchstack
8.2 High All push notification for WP Plugin all-push-notification Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.5.3 CVE-2025-32547 Patchstack
7.1 High Simple Post Meta Manager Plugin simple-post-meta-manager Cross-Site Request Forgery CSRF to Reflected Cross-Site Scripting No login needed ≤ 1.0.9 CVE-2025-32556 Patchstack
7.1 High SEO, Nutrition and Print for Recipes by Edamam Plugin seo-nutrition-and-print-for-recipes-by-edamam Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 3.3 CVE-2025-32555 Patchstack
7.1 High REVE Chat Plugin revechat Cross-Site Request Forgery No login needed ≤ 6.4.4 CVE-2025-32559 Patchstack
7.1 High ChillPay WooCommerce Plugin chillpay-payment-gateway Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-32570 Patchstack
7.1 High WP Calais Auto Tagger Plugin calais-auto-tagger Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-32563 Patchstack
7.1 High WP w3all phpBB Plugin wp-w3all-phpbb-integration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.9.9 Fixed in 3.0.0 CVE-2025-32575 Patchstack
7.1 High DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.7.1 Fixed in 5.8.2 CVE-2025-32580 Patchstack
7.1 High WordPress Spam Blocker Plugin cf7-manual-spam-blocker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.5 CVE-2025-32581 Patchstack
7.1 High Chat2 Plugin chat2 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0 Fixed in 4.1 CVE-2025-32584 Patchstack
7.1 High WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Request Forgery connectDaily plugin <= 1.5.4 - CSRF to Cross-Site Scripting No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-32597 Patchstack
7.1 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.7.5 CVE-2025-32591 Patchstack
7.1 High User Session Synchronizer Plugin user-session-synchronizer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 CVE-2025-32612 Patchstack
7.1 High Foliopress WYSIWYG Plugin foliopress-wysiwyg Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.18 CVE-2025-32610 Patchstack
7.1 High Nimbata Call Tracking Plugin nimbata-call-tracking Cross-Site Request Forgery No login needed ≤ 1.7.4 CVE-2025-32616 Patchstack
7.1 High Multiple Location Google Map Plugin multiple-location-google-map Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-32617 Patchstack
7.1 High WP Map Route Planner Plugin wp-map-route-planner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-32621 Patchstack
7.1 High KeyCAPTCHA Plugin keycaptcha Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-32619 Patchstack
7.1 High PlainInventory Plugin z-inventory-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.1.9 CVE-2025-32623 Patchstack
7.1 High Czater.pl – live chat i telefon Plugin czater Cross-Site Request Forgery live chat i telefon plugin <= 1.0.5 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2025-32624 Patchstack
7.1 High Custom Posts Order Plugin custom-posts-order Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.4 CVE-2025-32645 Patchstack
7.1 High IP2Location World Clock Plugin ip2location-world-clock Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.9 Fixed in 1.1.10 CVE-2025-32644 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
7.1 High Nepali Date Utilities Plugin nepali-date-utilities Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.15 CVE-2025-32664 Patchstack
7.1 High Interactive US Map Plugin interactive-us-map Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.7 CVE-2025-32661 Patchstack
7.1 High Doppler Forms Plugin doppler-form Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 Fixed in 2.6.0 CVE-2025-32667 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only