WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,051–4,100 of 8,985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 82 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Sidebar Manager Light Plugin sidebar-manager-light Cross-Site Request Forgery No login needed ≤ 1.18 CVE-2025-47647 Patchstack
4.7 Medium Integrations of Zoho CRM with Elementor form Plugin integrations-of-zoho-crm-with-elementor-form Open Redirect No login needed ≤ 1.0.8 CVE-2025-47644 Patchstack
5.9 Medium WP Discord Invite Plugin wp-discord-invite Cross-Site Scripting ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-47638 Patchstack
5.5 Medium WebinarPress Plugin wp-webinarsystem Server-Side Request Forgery ≤ 1.33.28 CVE-2025-47635 Patchstack
4.3 Medium Awin – Advertiser Tracking for WooCommerce Plugin awin-advertiser-tracking Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-47633 Patchstack
6.5 Medium Awesome Gallery Plugin awesome-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-47632 Patchstack
6.5 Medium Ajax Load More Plugin ajax-load-more Cross-Site Scripting ≤ 7.3.1.2 Fixed in 7.3.1.3 CVE-2025-47630 Patchstack
5.4 Medium QS Dark Mode Plugin qs-dark-mode Broken Access Control ≤ 3.0 CVE-2025-47628 Patchstack
5.9 Medium Submission DOM tracking for Contact Form 7 Plugin cf7-submission-dom-tracking Cross-Site Scripting ≤ 2.1 Fixed in 2.2 CVE-2025-47626 Patchstack
5.9 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Scripting ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-47625 Patchstack
4.3 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Request Forgery No login needed ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-47624 Patchstack
5.9 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting ≤ 2.0 Fixed in 2.0.1 CVE-2025-47623 Patchstack
5.9 Medium Email Notification on Login Plugin email-notification-on-login Cross-Site Scripting ≤ 1.7.0 CVE-2025-47622 Patchstack
6.5 Medium Meks Flexible Shortcodes Plugin meks-flexible-shortcodes Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-47621 Patchstack
5.9 Medium WP Front User Submit / Front Editor Plugin front-editor Cross-Site Scripting ≤ 5.0.6 CVE-2025-47617 Patchstack
6.5 Medium aBlocks Plugin ablocks Cross-Site Scripting ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-47616 Patchstack
5.9 Medium Amazon Product in a Post Plugin amazon-product-in-a-post-plugin Cross-Site Scripting ≤ 5.2.2 CVE-2025-47615 Patchstack
4.3 Medium LessButtons Social Sharing and Statistics Plugin lessbuttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.6.1 CVE-2025-47614 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-47612 Patchstack
4.3 Medium EasyMe Connect Plugin easyme-connect Cross-Site Request Forgery No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-47609 Patchstack
5.9 Medium Show All Comments Plugin show-all-comments-in-one-page Cross-Site Scripting ≤ 7.0.1 CVE-2025-47607 Patchstack
4.3 Medium Simple Giveaways Plugin giveasap Cross-Site Request Forgery No login needed ≤ 2.49.0 CVE-2025-47606 Patchstack
5.9 Medium WP jQuery DataTable Plugin wp-jquery-datatable Cross-Site Scripting ≤ 4.1.0 CVE-2025-47605 Patchstack
6.5 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting ≤ 3.8.0 Fixed in 3.9.0 CVE-2025-47604 Patchstack
5.4 Medium Calculate Prices based on Distance For WooCommerce Plugin calculate-prices-based-on-distance-for-woocommerce Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-47602 Patchstack
4.3 Medium WP Podcasts Manager Plugin wp-podcasts-manager Cross-Site Request Forgery No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-47597 Patchstack
4.3 Medium Beacon Lead Magnets and Lead Capture Plugin beacon-by Cross-Site Request Forgery No login needed ≤ 1.5.8 Fixed in 1.5.9 CVE-2025-47596 Patchstack
5.9 Medium Color Your Bar Plugin color-your-bar Cross-Site Scripting ≤ 2.0 CVE-2025-47595 Patchstack
4.3 Medium Soccer Live Scores Plugin soccer-live-scores Cross-Site Request Forgery No login needed ≤ 1.0.5 CVE-2025-47594 Patchstack
5.9 Medium Really Simple Under Construction Page Plugin really-simple-under-construction Cross-Site Scripting ≤ 1.4.6 CVE-2025-47593 Patchstack
5.9 Medium Terms Popup On User Login Plugin terms-popup-on-user-login Cross-Site Scripting TPUL plugin <= 2.0.8 - Cross Site Scripting (XSS) ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-47592 Patchstack
4.3 Medium Bulk Featured Image Plugin bulk-featured-image Broken Access Control ≤ 1.2.4 CVE-2025-47591 Patchstack
4.3 Medium WPSpeed Plugin wpspeed Cross-Site Request Forgery No login needed ≤ 2.6.5 Fixed in 2.6.6 CVE-2025-47590 Patchstack
6.5 Medium Ebook Store Plugin ebook-store Cross-Site Scripting ≤ 5.8009 Fixed in 5.8010 CVE-2025-47589 Patchstack
4.3 Medium Wiki Embed Plugin wiki-embed Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47551 Patchstack
6.6 Medium Instantio Plugin instantio Arbitrary File Upload ≤ 3.3.16 Fixed in 3.3.17 CVE-2025-47550 Patchstack
5.4 Medium Wbcom Designs - Activity Link Preview For BuddyPress Plugin activity-link-preview-for-buddypress Server-Side Request Forgery Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) No login needed ≤ 1.4.4 Fixed in 1.6.0 CVE-2025-47548 Patchstack
6.5 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-47547 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Other Race Condition No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2025-47545 Patchstack
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-47543 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-47542 Patchstack
5.3 Medium weMail Plugin wemail Information Disclosure Sensitive Data Exposure No login needed ≤ 1.14.13 Fixed in 1.14.14 CVE-2025-47540 Patchstack
4.3 Medium Ovation Elements Plugin ovation-elements Broken Access Control ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-47528 Patchstack
5.4 Medium GS Variation Swatches for WooCommerce Plugin gs-woo-variation-swatches Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47526 Patchstack
5.9 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-47525 Patchstack
5.9 Medium Quran multilanguage Text & Audio Plugin quran-text-multilanguage Cross-Site Scripting ≤ 2.3.23 Fixed in 2.3.24 CVE-2025-47524 Patchstack
4.3 Medium Seznam Webmaster Plugin seznam-webmaster Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47523 Patchstack
5.9 Medium AWEOS WP Lock Plugin aweos-wp-lock Cross-Site Scripting ≤ 1.4.8 Fixed in 1.4.9 CVE-2025-47522 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2025-47521 Patchstack
5.9 Medium Charitable Plugin charitable Cross-Site Scripting ≤ 1.8.5.1 Fixed in 1.8.5.2 CVE-2025-47520 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only