WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,001–4,050 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 81 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Delete Post Revision Plugin delete-post-revision Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31454 Patchstack
7.1 High WP Cleaner Plugin wpcleaner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-31446 Patchstack
7.1 High Pages Order Plugin pages-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-31445 Patchstack
7.1 High WordPress Galleria Plugin wp-galleria Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-31441 Patchstack
7.1 High WP Bookmarks Plugin wp-bookmarks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31431 Patchstack
8.1 High Material Dashboard Plugin material-dashboard Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31097 Patchstack
8.5 High Order Splitter for WooCommerce Plugin woo-order-splitter SQL Injection ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-31089 Patchstack
7.1 High Product Table by WBW Plugin woo-product-tables Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-31086 Patchstack
7.1 High xili-language Plugin xili-language Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.21.2 Fixed in 2.21.3 CVE-2025-31085 Patchstack
8.1 High News & Blog Designer Pack Plugin blog-designer-pack Local File Inclusion No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2025-31082 Patchstack
7.1 High Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.5 Fixed in 4.1.6 CVE-2025-31081 Patchstack
7.1 High HTML Forms Plugin html-forms Cross-Site Scripting No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-31080 Patchstack
7.1 High Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition Cross-Site Scripting Worldwide Express Edition plugin <= 5.2.18 - Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-31078 Patchstack
7.1 High Access Areas Plugin wp-access-areas Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.19 Fixed in 1.5.20 CVE-2025-30913 Patchstack
7.1 High Plugin Oficial – Getnet para WooCommerce Plugin wc-checkout-getnet Cross-Site Scripting Getnet para WooCommerce plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.8.0 CVE-2025-30906 Patchstack
7.1 High Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.4.5 CVE-2025-30905 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager PHP Object Injection ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30892 Patchstack
7.1 High Oracle Cards Lite Plugin oracle-cards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-30852 Patchstack
7.1 High Watu Quiz Plugin watu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-30844 Patchstack
8.8 High WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce Plugin wpc-smart-linked-products Privilege Escalation ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-30825 Patchstack
7.1 High VPSUForm Plugin v-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.9 Fixed in 3.1.10 CVE-2025-30778 Patchstack
7.1 High Frizzly Plugin frizzly Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-30554 Patchstack
7.6 High BookingPress Plugin bookingpress-appointment-booking SQL Injection ≤ 1.1.28 Fixed in 1.1.38 CVE-2025-31910 Patchstack
7.1 High JSON Structuring Markup Plugin json-structuring-markup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-31908 Patchstack
7.1 High WP Profitshare Plugin wp-profitshare Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.9 CVE-2025-31906 Patchstack
7.1 High Ebook Downloader Plugin ebook-downloader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31904 Patchstack
8.5 High RJ Quickcharts Plugin rj-quickcharts SQL Injection ≤ 0.6.1 CVE-2025-31024 Patchstack
7.5 High GTM Kit Plugin gtm-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-31001 Patchstack
8.8 High Vitepos Plugin vitepos-lite Authentication Bypass Broken Authentication ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-22277 Patchstack
7.6 High YayExtra Plugin yayextra Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-31415 Patchstack
8.8 High Mobile DJ Manager Plugin mobile-dj-manager PHP Object Injection ≤ 1.7.5.2 Fixed in 1.7.5.3 CVE-2025-31074 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.4 Fixed in 4.2.4 CVE-2025-30924 Patchstack
7.1 High SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30917 Patchstack
8.6 High CM Download Manager Plugin cm-download-manager Arbitrary File Deletion No login needed ≤ 2.9.6 Fixed in 3.0.0 CVE-2025-30910 Patchstack
7.1 High AEC Kiosque Plugin aec-kiosque Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.3 Fixed in 1.9.4 CVE-2025-30902 Patchstack
8.1 High JS Help Desk Plugin js-support-ticket Local File Inclusion No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30901 Patchstack
7.5 High JS Help Desk Plugin js-support-ticket Path Traversal Arbitrary File Download No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-30882 Patchstack
7.5 High JS Help Desk Plugin js-support-ticket Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30880 Patchstack
8.6 High JS Help Desk Plugin js-support-ticket Arbitrary File Deletion No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30878 Patchstack
8.1 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion No login needed ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-30870 Patchstack
7.1 High Image Wall Plugin image-wall Cross-Site Scripting No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-30869 Patchstack
8.1 High Essential Real Estate Plugin essential-real-estate Local File Inclusion No login needed ≤ 5.2.0 Fixed in 5.2.1 CVE-2025-30849 Patchstack
7.1 High Hostel Plugin hostel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 Fixed in 1.1.5.5 CVE-2025-30848 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.5 Fixed in 2.12.5.1 CVE-2025-30840 Patchstack
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.5 High Bit Assist Plugin bit-assist Path Traversal No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30834 Patchstack
7.1 High WP2LEADS Plugin wp2leads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.5 Fixed in 3.4.7 CVE-2025-30827 Patchstack
7.1 High About Author Plugin about-author Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30808 Patchstack
7.1 High Better WishList API Plugin better-wlm-api Cross-Site Scripting No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-30798 Patchstack
7.5 High Greek Multi Tool – Fix peralinks, accents, auto create menus and more Plugin greek-multi-tool Broken Access Control Fix peralinks, accents, auto create menus and more plugin <= 2.3.1 - Broken Access Control No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-30797 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only