WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,151–4,200 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 84 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Custom Product Stickers for Woocommerce Plugin custom-product-stickers-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 CVE-2025-28889 Patchstack
7.1 High Omnify Plugin omnify-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-28882 Patchstack
7.1 High Blue Captcha Plugin blue-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.4 Fixed in 2.0.0 CVE-2025-28880 Patchstack
7.1 High Key4ce osTicket Bridge Plugin key4ce-osticket-bridge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-28877 Patchstack
8.5 High Shuffle Theme shuffle SQL Injection ≤ 0.5 CVE-2025-28873 Patchstack
7.1 High NextGEN Gallery Voting Plugin nextgen-gallery-voting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 CVE-2025-28869 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.1 High Arrow Maps Plugin ap-google-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28858 Patchstack
7.1 High Teleport Plugin teleport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2025-28855 Patchstack
7.1 High Random Quotes Plugin random-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-27267 Patchstack
7.1 High TBTestimonials Plugin tb-testimonials Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-26584 Patchstack
7.1 High Video Share VOD Plugin video-share-vod Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2025-26583 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.1 High MicroPayments Plugin paid-membership Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-26579 Patchstack
7.1 High WP Simple Slideshow Plugin wp-simple-slideshow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26576 Patchstack
7.1 High Display Post Meta Plugin display-post-meta Cross-Site Scripting WordPress Display Post Meta plugin <= 1.5- Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-26575 Patchstack
7.1 High Rizzi Guestbook Plugin rizzi-guestbook Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-26573 Patchstack
7.1 High In Stock Mailer for WooCommerce Plugin in-stock-mailer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-26566 Patchstack
7.1 High GNUPress Plugin gnupress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-26565 Patchstack
7.1 High GNUCommerce Plugin gnucommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 CVE-2025-26564 Patchstack
7.1 High WP Contact Form III Plugin wp-contact-form-iii Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2d CVE-2025-26560 Patchstack
7.1 High Cookies Pro Plugin cookies-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-26546 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
7.1 High Zalo Live Chat Plugin zalo-live-chat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-26542 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack
7.1 High Another Events Calendar Plugin another-events-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.0 CVE-2025-26536 Patchstack
7.1 High Theme Demo Bar Plugin wordpress-theme-demo-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-25134 Patchstack
8.1 High Formality Plugin formality Local File Inclusion No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-24690 Patchstack
7.1 High Google Plus Plugin google-plus-google Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23964 Patchstack
8.1 High custom-field-list-widget Plugin custom-field-list-widget Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-23952 Patchstack
8.1 High LinkedIn Lite Plugin linkedin-lite Local File Inclusion No login needed ≤ 1.0 CVE-2025-23937 Patchstack
7.1 High Infugrator Plugin infugrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23735 Patchstack
7.1 High AuMenu Plugin aumenu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-23728 Patchstack
7.1 High AppReview Plugin appreview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-23714 Patchstack
7.1 High Your Lightbox Plugin your-lightbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23704 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
7.1 High Management-screen-droptiles Plugin cxc-sawa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23666 Patchstack
7.1 High Frontend Post Submission Plugin frontend-post-submission Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23638 Patchstack
7.1 High WP Database Audit Plugin database-audit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23633 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23612 Patchstack
7.1 High RDP inGroups+ Plugin rdp-ingroups Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-23546 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack
7.1 High RDP Linkedin Login Plugin rdp-linkedin-login Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2025-23542 Patchstack
7.1 High Site Editor Google Map Plugin site-editor-google-map Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23466 Patchstack
7.1 High RWS Enquiry And Lead Follow-up Plugin rws-enquiry Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23460 Patchstack
7.1 High NS Simple Intro Loader Plugin ns-simple-intro-loader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2025-23459 Patchstack
7.1 High GetSocial Plugin getsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-22283 Patchstack
7.2 High WordPress Importer Plugin wordpress-importer PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 0.8.3 CVE-2024-13889 Wordfence
7.2 High Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Remote Code Execution WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection ≤ 1.16.10 CVE-2025-2257 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only