WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,001–4,050 of 8,985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 81 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Sharespine Woocommerce Connector Plugin sharespine-woocommerce-connector Broken Access Control ≤ 4.7.55 Fixed in 4.8.56 CVE-2025-48128 Patchstack
6.5 Medium Push notification for Mobile and Web app Plugin push-notification-mobile-and-web-app Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-48127 Patchstack
6.5 Medium WP Notes Widget Plugin wp-notes-widget Cross-Site Scripting ≤ 1.0.6 CVE-2025-48121 Patchstack
5.3 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary Shortcode Execution No login needed ≤ 8.6.9 Fixed in 8.6.10 CVE-2025-48120 Patchstack
5.3 Medium RS WP Book Showcase Plugin rs-wp-books-showcase Content Injection No login needed ≤ 6.7.59 CVE-2025-48119 Patchstack
5.3 Medium WooCommerce POS Plugin woocommerce-pos Broken Access Control No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-48117 Patchstack
5.3 Medium EventON Plugin eventon-lite Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-48116 Patchstack
4.3 Medium ValidateCertify Plugin validar-certificados-de-cursos Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-48115 Patchstack
6.5 Medium Broadstreet Ads Plugin broadstreet Cross-Site Scripting ≤ 1.51.2 Fixed in 1.51.3 CVE-2025-48113 Patchstack
6.5 Medium Uncanny Toolkit for LearnDash Plugin uncanny-learndash-toolkit Cross-Site Scripting ≤ 3.7.0.2 Fixed in 3.7.0.3 CVE-2025-48080 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control ≤ 5.9.5.1 Fixed in 5.9.5.2 CVE-2025-48079 Patchstack
4.8 Medium WolfNet IDX Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.19.1 CVE-2023-6783 WPScan
4.8 Medium AI ChatBot for WordPress – WPBot Plugin Cross-Site Scripting WPBot < 6.2.4 - Admin+ Stored XSS < 6.2.4 Fixed in 6.2.4 CVE-2025-0329 WPScan
4.8 Medium MapPress Maps Plugin Cross-Site Scripting Admin+ Stored XSS via Map Settings < 2.93 Fixed in 2.93 CVE-2024-8620 WPScan
4.8 Medium Hustle Plugin wordpress-popup Cross-Site Scripting Admin+ Stored XSS ≤ 7.8.5 CVE-2024-8492 WPScan
4.3 Medium Joy Of Text Lite – SMS messaging Plugin Cross-Site Request Forgery SMS messaging for WordPress <= 2.3.1 - Settings Update via CSRF No login needed ≤ 2.3.1 CVE-2024-7984 WPScan
4.8 Medium Clicksold IDX Plugin Cross-Site Scripting Admin+ XSS ≤ 1.90 CVE-2024-7769 WPScan
4.8 Medium Simple Share Plugin Cross-Site Scripting Admin+ XSS ≤ 0.5.3 CVE-2024-7556 WPScan
4.8 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Admin+ Stored XSS < 4.2.1 Fixed in 4.2.1 CVE-2024-13730 WPScan
4.8 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Admin+ Stored XSS < 4.1.24 Fixed in 4.1.24 CVE-2024-13729 WPScan
4.8 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS < 4.2.7.5.1 Fixed in 4.2.7.5.1 CVE-2024-13128 WPScan
4.8 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS < 4.2.7.5.1 Fixed in 4.2.7.5.1 CVE-2024-13127 WPScan
6.1 Medium WordPress连接微博 Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 2.5.6 CVE-2024-12282 WPScan
4.8 Medium Panorama – WordPress Project Management Plugin Cross-Site Scripting WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS ≤ 1.5.1 CVE-2024-11843 WPScan
6.1 Medium tarteaucitron.js Plugin Cross-Site Scripting Stored XSS via CSRF No login needed < 0.3.0 Fixed in 0.3.0 CVE-2024-11719 WPScan
5.4 Medium tarteaucitron.js Plugin Cross-Site Scripting Author+ Stored XSS < 0.3.0 Fixed in 0.3.0 CVE-2024-11718 WPScan
4.3 Medium Tours Plugin tours Broken Access Control ≤ 1.0.0 Fixed in 1.0.1 CVE-2024-51666 Patchstack
5.3 Medium Jetpack Debug Tools Plugin jetpack-debug-helper Broken Access Control No login needed < 2.0.1 Fixed in 2.0.1 CVE-2024-56006 Patchstack
5.4 Medium Front End Users Plugin front-end-only-users Broken Access Control ≤ 3.2.35 CVE-2025-47580 Patchstack
6.5 Medium BNS Twitter Follow Button Plugin bns-twitter-follow-button Cross-Site Scripting ≤ 0.3.8 CVE-2025-47578 Patchstack
4.3 Medium Contentstudio Plugin contentstudio Broken Access Control ≤ 1.3.5 Fixed in 1.3.7 CVE-2025-47692 Patchstack
5.5 Medium Ultimate Member Plugin ultimate-member Remote Code Execution Arbitrary Function Call ≤ 2.10.3 Fixed in 2.10.4 CVE-2025-47691 Patchstack
5.3 Medium Advanced File Manager Plugin file-manager-advanced Broken Access Control Broken Access Control to Notice Dismissal No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-47688 Patchstack
6.5 Medium DELUCKS SEO Plugin delucks-seo Cross-Site Scripting ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-47686 Patchstack
5.4 Medium Smaily for WP Plugin smaily-for-wp Cross-Site Request Forgery No login needed ≤ 3.1.7 CVE-2025-47684 Patchstack
4.3 Medium Web Accessibility with Max Access Plugin accessibility-toolbar Cross-Site Request Forgery No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-47681 Patchstack
6.5 Medium RS WP Book Showcase Plugin rs-wp-books-showcase Cross-Site Scripting ≤ 6.7.59 CVE-2025-47679 Patchstack
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) ≤ 2.7.7.25 Fixed in 2.7.7.26 CVE-2025-47677 Patchstack
6.5 Medium User Login History Plugin user-login-history Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-47676 Patchstack
6.5 Medium Woobox Plugin woobox Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-47675 Patchstack
4.3 Medium Credova_Financial Plugin credova-financial Cross-Site Request Forgery No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2025-47674 Patchstack
6.5 Medium CBX Map for Google Map & OpenStreetMap Plugin cbxgooglemap Cross-Site Scripting ≤ 1.1.12 Fixed in 2.0.0 CVE-2025-47669 Patchstack
5.9 Medium CookieCode Plugin cookiecode Cross-Site Scripting ≤ 2.4.4 CVE-2025-47668 Patchstack
5.4 Medium LiveAgent Plugin liveagent Cross-Site Request Forgery No login needed ≤ 4.4.7 Fixed in 4.4.8 CVE-2025-47667 Patchstack
5.9 Medium N360 | Splash Screen Plugin n360-splash-screen Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-47665 Patchstack
4.4 Medium WP Pipes Plugin wp-pipes Server-Side Request Forgery ≤ 1.4.2 CVE-2025-47664 Patchstack
6.5 Medium Woobox Plugin woobox Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-47662 Patchstack
5.4 Medium 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.2.11 Fixed in 5.3.3 CVE-2025-47661 Patchstack
6.5 Medium WPBakery Visual Composer WHMCS Elements Plugin void-visual-whmcs-element Cross-Site Scripting ≤ 1.0.4.3 CVE-2025-47659 Patchstack
6.5 Medium Spiraclethemes Site Library Plugin spiraclethemes-site-library Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-47656 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only