WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,951–4,000 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 80 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High uListing Plugin ulisting SQL Injection ≤ 2.2.0 CVE-2025-32122 Patchstack
7.6 High Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member SQL Injection ≤ 1.1.3 CVE-2025-32121 Patchstack
7.6 High Easy Query – WP Query Builder Plugin easy-query SQL Injection WP Query Builder plugin <= 2.0.4 - SQL Injection ≤ 2.0.4 CVE-2025-32120 Patchstack
7.1 High Libro de Reclamaciones y Quejas Plugin libro-de-reclamaciones-y-quejas Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-32113 Patchstack
7.1 High Sidebar Manager Light Plugin sidebar-manager-light Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.18 CVE-2025-32112 Patchstack
7.1 High Videos Plugin videos Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2025-31384 Patchstack
7.1 High Sequel Plugin sequel Cross-Site Scripting No login needed ≤ 1.0.11 Fixed in 1.0.13 CVE-2025-31389 Patchstack
7.5 High Fami WooCommerce Compare Plugin fami-woocommerce-compare Local File Inclusion No login needed ≤ 1.0.5 CVE-2025-31405 Patchstack
7.1 High Awesome Event Booking Plugin awesome-event-booking Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.4 Fixed in 2.8.5 CVE-2025-31416 Patchstack
7.1 High Gravel Theme gravel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-31418 Patchstack
7.6 High wpForo Forum Plugin wpforo Privilege Escalation ≤ 2.4.2 Fixed in 2.4.4 CVE-2025-31420 Patchstack
7.1 High ez Form Calculator Premium Plugin ez-form-calculator-premium Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.14.1.2 CVE-2025-22282 Patchstack
7.5 High Apptivo Business Site CRM Plugin apptivo-business-site Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.3 Fixed in 5.4 CVE-2025-31909 Patchstack
7.1 High Team Builder Plugin team-display Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-31907 Patchstack
7.1 High Team Rosters Plugin team-rosters Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7 Fixed in 4.8 CVE-2025-31905 Patchstack
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-31903 Patchstack
7.1 High Social Share And Social Locker Plugin social-share-and-social-locker-arsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-31902 Patchstack
7.1 High Digihood HTML Sitemap Plugin wedesin-html-sitemap Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.1 CVE-2025-31901 Patchstack
7.1 High Lexicata Plugin lexicata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.16 CVE-2025-31900 Patchstack
7.1 High Awesome Logos Plugin awesome-logos Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-31899 Patchstack
7.1 High MediaView Plugin mediaview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31898 Patchstack
7.1 High Support Helpdesk Ticket System Lite Plugin ticket-help-desk-system-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.5.2 Fixed in 5.0.0 CVE-2025-31626 Patchstack
7.1 High Contact Form vCard Generator Plugin contact-form-vcard-generator Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-31582 Patchstack
7.1 High PeproDev CF7 Database Plugin pepro-cf7-database Cross-Site Scripting No login needed ≤ 2.0.0 CVE-2025-31573 Patchstack
7.1 High CF7 Spreadsheets Plugin cf7-spreadsheets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.2 CVE-2025-31536 Patchstack
7.1 High WP_Identicon Plugin wp-identicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31468 Patchstack
7.1 High Flickr Photostream Plugin flickr-photostream Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.8 CVE-2025-31467 Patchstack
7.1 High Search engine keywords highlighter Plugin keywords-highlight-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2025-31442 Patchstack
7.1 High Blubrry PowerPress Podcasting plugin MultiSite add-on Plugin powerpress-multisite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1 CVE-2025-31436 Patchstack
7.5 High DeBounce Email Validator Plugin debounce-io-email-validator Local File Inclusion No login needed ≤ 5.7 Fixed in 5.7.1 CVE-2025-31098 Patchstack
7.1 High Web Directory Free Plugin web-directory-free Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.8 CVE-2025-30908 Patchstack
8.8 High Testimonial Slider Plugin testimonial PHP Object Injection ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-30889 Patchstack
7.1 High Snow Storm Plugin snow-storm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-30858 Patchstack
7.1 High Latest Custom Post Type Updates Plugin latest-custom-post-type-updates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2025-30616 Patchstack
7.1 High Wptobe-signinup Plugin wptobe-signinup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-30611 Patchstack
8.5 High Actionwear products sync Plugin actionwear-products-sync SQL Injection ≤ 2.3.3 CVE-2025-31619 Patchstack
7.1 High Auto scroll for reading Plugin auto-scroll-for-reading Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-31594 Patchstack
7.5 High Ni WooCommerce Product Enquiry Plugin ni-woocommerce-product-enquiry Broken Access Control No login needed ≤ 4.1.8 CVE-2025-31580 Patchstack
7.1 High Fonts Manager | Custom Fonts Plugin fonts-manager-custom-fonts Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-31578 Patchstack
7.1 High The Logo Slider Plugin the-logo-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-31571 Patchstack
7.1 High LeadLab by wiredminds Plugin wiredminds-leadlab Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-31568 Patchstack
8.5 High Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin ai-auto-tool SQL Injection ≤ 2.2.6 Fixed in 2.2.8 CVE-2025-31564 Patchstack
7.1 High AI Search Bar Plugin open-ai-search-bar Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-31563 Patchstack
8.5 High Ultimate Push Notifications Plugin ultimate-push-notifications SQL Injection ≤ 1.2.0 CVE-2025-31561 Patchstack
7.2 High Salon booking system Plugin salon-booking-system Privilege Escalation ≤ 10.15 Fixed in 10.15 CVE-2025-31560 Patchstack
7.1 High Ultimate Push Notifications Plugin ultimate-push-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-31548 Patchstack
7.1 High Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16 Fixed in 2.20 CVE-2025-31537 Patchstack
7.1 High CGM Event Calendar Plugin cgm-event-calendar Cross-Site Scripting No login needed ≤ 0.8.5 CVE-2025-31462 Patchstack
7.1 High NanoSupport Plugin nanosupport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.0 CVE-2025-31461 Patchstack
7.1 High Limit Max IPs Per User Plugin limit-max-ips-per-user Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-31455 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only