WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,101–4,150 of 8,961 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 83 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47480 Patchstack
6.5 Medium Cost Calculator for Elementor Plugin cost-calculator-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-47476 Patchstack
6.5 Medium JupiterX Core Plugin jupiterx-core Cross-Site Scripting ≤ 4.8.11 Fixed in 4.8.12 CVE-2025-47475 Patchstack
5.4 Medium PW WooCommerce Bulk Edit Plugin pw-bulk-edit Cross-Site Request Forgery No login needed ≤ 2.134 Fixed in 2.135 CVE-2025-47473 Patchstack
5.4 Medium Music Player for WooCommerce Plugin music-player-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-47472 Patchstack
4.3 Medium Envo Extra Plugin envo-extra Broken Access Control ≤ 1.9.9 Fixed in 1.9.10 CVE-2025-47471 Patchstack
4.3 Medium GPT3 AI Content Writer Plugin gpt3-ai-content-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Prompt Generation No login needed ≤ 1.9.14 Fixed in 1.9.15 CVE-2025-47470 Patchstack
5.4 Medium Media Hygiene Plugin media-hygiene Broken Access Control ≤ 4.0.0 Fixed in 4.0.1 CVE-2025-47469 Patchstack
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-47468 Patchstack
4.3 Medium GS Testimonial Slider Plugin gs-testimonial Broken Access Control ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-47467 Patchstack
5.4 Medium Ultimate WP Mail Plugin ultimate-wp-mail Cross-Site Request Forgery No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-47466 Patchstack
4.9 Medium Blocksy Plugin blocksy Broken Access Control ≤ 2.0.97 Fixed in 2.0.98 CVE-2025-47465 Patchstack
4.9 Medium Solace Extra Plugin solace-extra Server-Side Request Forgery ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-47464 Patchstack
4.3 Medium FundEngine Plugin wp-fundraising-donation Cross-Site Request Forgery No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-47459 Patchstack
5.3 Medium LocateAndFilter Plugin locateandfilter Broken Access Control No login needed ≤ 1.6.16 Fixed in 1.6.17 CVE-2025-47457 Patchstack
4.7 Medium WP Gravity Forms Zendesk Plugin gf-zendesk Open Redirect No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-47456 Patchstack
4.7 Medium Integration for WooCommerce and Salesforce Plugin woo-salesforce-plugin-crm-perks Open Redirect No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2025-47455 Patchstack
4.7 Medium WP Gravity Forms Dynamics CRM Plugin gf-dynamics-crm Open Redirect No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-47454 Patchstack
4.3 Medium Product Quantity Dropdown For Woocommerce Plugin product-quantity-dropdown-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-47451 Patchstack
5.3 Medium Simple File List Plugin simple-file-list Broken Access Control Settings Change No login needed ≤ 6.1.13 Fixed in 6.1.14 CVE-2025-47450 Patchstack
5.9 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting ≤ 5.2.7 Fixed in 5.2.8 CVE-2025-47449 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-47448 Patchstack
4.3 Medium Cool Author Box Plugin hm-cool-author-box-widget Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2025-47447 Patchstack
4.3 Medium Listamester Plugin listamester Cross-Site Request Forgery No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-47446 Patchstack
6.5 Medium Widget Countdown Plugin widget-countdown Cross-Site Scripting ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-47443 Patchstack
6.5 Medium CC BMI Calculator Plugin cc-bmi-calculator Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-47442 Patchstack
6.5 Medium Progress Bar Plugin progress-bar Cross-Site Scripting ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-47441 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.7.1017 Fixed in 1.7.1018 CVE-2025-39361 Patchstack
4.3 Medium Download Manager and Payment Form WordPress Plugin – WP SmartPay Plugin smartpay Information Disclosure WP SmartPay 1.1.0 - 2.7.13 - Authenticated (Subscriber+) Information Exposure 1.1.0 – 2.7.13 CVE-2025-3851 Wordfence
6.5 Medium Custom Login and Registration Plugin ms-registration Cross-Site Scripting ≤ 1.0.0 CVE-2025-39363 Patchstack
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Reservation & Post Deletion ≤ 2.4.4 CVE-2025-1326 Wordfence
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 2.4.4 CVE-2025-1327 Wordfence
6.4 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.1.3 CVE-2025-3890 Wordfence
5.3 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object Reference via 'quantity' No login needed ≤ 5.1.3 CVE-2025-3889 Wordfence
6.5 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object Reference No login needed ≤ 5.1.3 CVE-2025-3874 Wordfence
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
4.3 Medium Simple Sitemap – Create a Responsive HTML Sitemap Plugin simple-sitemap Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-39413 Patchstack
5.3 Medium Kleo Plugin kleo Broken Access Control No login needed ≤ 5.4.4 Fixed in 5.4.4 CVE-2025-39367 Patchstack
5.3 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Broken Access Control Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.10.35 CVE-2025-3912 Wordfence
5.4 Medium Custom Login and Registration Plugin ms-registration Broken Access Control ≤ 1.0.0 CVE-2025-46535 Patchstack
6.5 Medium WP Quiz Plugin wp-quiz Cross-Site Scripting ≤ 2.0.10 CVE-2025-46482 Patchstack
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Information Disclosure Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.8.8 CVE-2025-3923 Wordfence
5.4 Medium Zalo Official Live Chat Plugin zalo-official-live-chat Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-46498 Patchstack
5.9 Medium COVID-19 (Coronavirus) Update Your Customers Plugin covid-19-alert Cross-Site Scripting ≤ 1.5.1 CVE-2025-46523 Patchstack
4.9 Medium WP AVCL Automation Helper (formerly WPFlyLeads) Plugin woozap Server-Side Request Forgery ≤ 3.4 CVE-2025-46531 Patchstack
6.5 Medium Fable Extra Plugin fable-extra Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46447 Patchstack
4.3 Medium Media Library Downloader Plugin media-library-downloader Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-46519 Patchstack
6.4 Medium BeerXML Shortcode Plugin beerxml-shortcode Server-Side Request Forgery ≤ 0.7.1 Fixed in 0.8 CVE-2025-46511 Patchstack
4.9 Medium Simple Google Photos Grid Plugin simple-google-photos-grid Server-Side Request Forgery ≤ 1.5 Fixed in 1.6 CVE-2025-46503 Patchstack
5.3 Medium Bulk Assign Linked Products For WooCommerce Plugin wc-bulk-assign-linked-products Broken Access Control No login needed ≤ 2.1 CVE-2025-46489 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only