WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 4,001–4,050 of 8,985 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Sharespine Woocommerce Connector | Broken Access Control |
≤ 4.7.55 Fixed in 4.8.56 |
CVE-2025-48128 |
Patchstack | |
| 6.5 Medium | Push notification for Mobile and Web app | Broken Access Control No login needed |
≤ 2.0.3 Fixed in 2.0.4 |
CVE-2025-48127 |
Patchstack | |
| 6.5 Medium | WP Notes Widget | Cross-Site Scripting |
≤ 1.0.6 |
CVE-2025-48121 |
Patchstack | |
| 5.3 Medium | MapSVG | Arbitrary Shortcode Execution No login needed |
≤ 8.6.9 Fixed in 8.6.10 |
CVE-2025-48120 |
Patchstack | |
| 5.3 Medium | RS WP Book Showcase | Content Injection No login needed |
≤ 6.7.59 |
CVE-2025-48119 |
Patchstack | |
| 5.3 Medium | WooCommerce POS | Broken Access Control No login needed |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2025-48117 |
Patchstack | |
| 5.3 Medium | EventON | Broken Access Control No login needed |
≤ 2.4.4 Fixed in 2.4.5 |
CVE-2025-48116 |
Patchstack | |
| 4.3 Medium | ValidateCertify | Cross-Site Request Forgery No login needed |
≤ 1.6.4 Fixed in 1.6.5 |
CVE-2025-48115 |
Patchstack | |
| 6.5 Medium | Broadstreet Ads | Cross-Site Scripting |
≤ 1.51.2 Fixed in 1.51.3 |
CVE-2025-48113 |
Patchstack | |
| 6.5 Medium | Uncanny Toolkit for LearnDash | Cross-Site Scripting |
≤ 3.7.0.2 Fixed in 3.7.0.3 |
CVE-2025-48080 |
Patchstack | |
| 4.3 Medium | ProfileGrid | Broken Access Control |
≤ 5.9.5.1 Fixed in 5.9.5.2 |
CVE-2025-48079 |
Patchstack | |
| 4.8 Medium | WolfNet IDX | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.19.1 |
CVE-2023-6783 |
WPScan | |
| 4.8 Medium | AI ChatBot for WordPress – WPBot | Cross-Site Scripting WPBot < 6.2.4 - Admin+ Stored XSS |
< 6.2.4 Fixed in 6.2.4 |
CVE-2025-0329 |
WPScan | |
| 4.8 Medium | MapPress Maps | Cross-Site Scripting Admin+ Stored XSS via Map Settings |
< 2.93 Fixed in 2.93 |
CVE-2024-8620 |
WPScan | |
| 4.8 Medium | Hustle | Cross-Site Scripting Admin+ Stored XSS |
≤ 7.8.5 |
CVE-2024-8492 |
WPScan | |
| 4.3 Medium | Joy Of Text Lite – SMS messaging | Cross-Site Request Forgery SMS messaging for WordPress <= 2.3.1 - Settings Update via CSRF No login needed |
≤ 2.3.1 |
CVE-2024-7984 |
WPScan | |
| 4.8 Medium | Clicksold IDX | Cross-Site Scripting Admin+ XSS |
≤ 1.90 |
CVE-2024-7769 |
WPScan | |
| 4.8 Medium | Simple Share | Cross-Site Scripting Admin+ XSS |
≤ 0.5.3 |
CVE-2024-7556 |
WPScan | |
| 4.8 Medium | Podlove Podcast Publisher | Cross-Site Scripting Admin+ Stored XSS |
< 4.2.1 Fixed in 4.2.1 |
CVE-2024-13730 |
WPScan | |
| 4.8 Medium | Podlove Podcast Publisher | Cross-Site Scripting Admin+ Stored XSS |
< 4.1.24 Fixed in 4.1.24 |
CVE-2024-13729 |
WPScan | |
| 4.8 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS |
< 4.2.7.5.1 Fixed in 4.2.7.5.1 |
CVE-2024-13128 |
WPScan | |
| 4.8 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS |
< 4.2.7.5.1 Fixed in 4.2.7.5.1 |
CVE-2024-13127 |
WPScan | |
| 6.1 Medium | WordPress连接微博 | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 2.5.6 |
CVE-2024-12282 |
WPScan | |
| 4.8 Medium | Panorama – WordPress Project Management | Cross-Site Scripting WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS |
≤ 1.5.1 |
CVE-2024-11843 |
WPScan | |
| 6.1 Medium | tarteaucitron.js | Cross-Site Scripting Stored XSS via CSRF No login needed |
< 0.3.0 Fixed in 0.3.0 |
CVE-2024-11719 |
WPScan | |
| 5.4 Medium | tarteaucitron.js | Cross-Site Scripting Author+ Stored XSS |
< 0.3.0 Fixed in 0.3.0 |
CVE-2024-11718 |
WPScan | |
| 4.3 Medium | Tours | Broken Access Control |
≤ 1.0.0 Fixed in 1.0.1 |
CVE-2024-51666 |
Patchstack | |
| 5.3 Medium | Jetpack Debug Tools | Broken Access Control No login needed |
< 2.0.1 Fixed in 2.0.1 |
CVE-2024-56006 |
Patchstack | |
| 5.4 Medium | Front End Users | Broken Access Control |
≤ 3.2.35 |
CVE-2025-47580 |
Patchstack | |
| 6.5 Medium | BNS Twitter Follow Button | Cross-Site Scripting |
≤ 0.3.8 |
CVE-2025-47578 |
Patchstack | |
| 4.3 Medium | Contentstudio | Broken Access Control |
≤ 1.3.5 Fixed in 1.3.7 |
CVE-2025-47692 |
Patchstack | |
| 5.5 Medium | Ultimate Member | Remote Code Execution Arbitrary Function Call |
≤ 2.10.3 Fixed in 2.10.4 |
CVE-2025-47691 |
Patchstack | |
| 5.3 Medium | Advanced File Manager | Broken Access Control Broken Access Control to Notice Dismissal No login needed |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2025-47688 |
Patchstack | |
| 6.5 Medium | DELUCKS SEO | Cross-Site Scripting |
≤ 2.5.9 Fixed in 2.6.0 |
CVE-2025-47686 |
Patchstack | |
| 5.4 Medium | Smaily for WP | Cross-Site Request Forgery No login needed |
≤ 3.1.7 |
CVE-2025-47684 |
Patchstack | |
| 4.3 Medium | Web Accessibility with Max Access | Cross-Site Request Forgery No login needed |
≤ 2.0.9 Fixed in 2.1.0 |
CVE-2025-47681 |
Patchstack | |
| 6.5 Medium | RS WP Book Showcase | Cross-Site Scripting |
≤ 6.7.59 |
CVE-2025-47679 |
Patchstack | |
| 6.5 Medium | Photo Gallery | Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) |
≤ 2.7.7.25 Fixed in 2.7.7.26 |
CVE-2025-47677 |
Patchstack | |
| 6.5 Medium | User Login History | Cross-Site Scripting |
≤ 2.1.6 Fixed in 2.1.7 |
CVE-2025-47676 |
Patchstack | |
| 6.5 Medium | Woobox | Cross-Site Scripting |
≤ 1.6 Fixed in 1.7 |
CVE-2025-47675 |
Patchstack | |
| 4.3 Medium | Credova_Financial | Cross-Site Request Forgery No login needed |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2025-47674 |
Patchstack | |
| 6.5 Medium | CBX Map for Google Map & OpenStreetMap | Cross-Site Scripting |
≤ 1.1.12 Fixed in 2.0.0 |
CVE-2025-47669 |
Patchstack | |
| 5.9 Medium | CookieCode | Cross-Site Scripting |
≤ 2.4.4 |
CVE-2025-47668 |
Patchstack | |
| 5.4 Medium | LiveAgent | Cross-Site Request Forgery No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2025-47667 |
Patchstack | |
| 5.9 Medium | N360 | Splash Screen | Cross-Site Scripting |
≤ 1.0.6 Fixed in 1.0.7 |
CVE-2025-47665 |
Patchstack | |
| 4.4 Medium | WP Pipes | Server-Side Request Forgery |
≤ 1.4.2 |
CVE-2025-47664 |
Patchstack | |
| 6.5 Medium | Woobox | Cross-Site Scripting |
≤ 1.6 Fixed in 1.7 |
CVE-2025-47662 |
Patchstack | |
| 5.4 Medium | 워드프레스 결제 심플페이 | Cross-Site Request Forgery No login needed |
≤ 5.2.11 Fixed in 5.3.3 |
CVE-2025-47661 |
Patchstack | |
| 6.5 Medium | WPBakery Visual Composer WHMCS Elements | Cross-Site Scripting |
≤ 1.0.4.3 |
CVE-2025-47659 |
Patchstack | |
| 6.5 Medium | Spiraclethemes Site Library | Cross-Site Scripting |
≤ 1.5.4 Fixed in 1.5.5 |
CVE-2025-47656 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.