WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,151–4,200 of 8,985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 84 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Progress Bar Plugin progress-bar Cross-Site Scripting ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-47441 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.7.1017 Fixed in 1.7.1018 CVE-2025-39361 Patchstack
4.3 Medium Download Manager and Payment Form WordPress Plugin – WP SmartPay Plugin smartpay Information Disclosure WP SmartPay 1.1.0 - 2.7.13 - Authenticated (Subscriber+) Information Exposure 1.1.0 – 2.7.13 CVE-2025-3851 Wordfence
6.5 Medium Custom Login and Registration Plugin ms-registration Cross-Site Scripting ≤ 1.0.0 CVE-2025-39363 Patchstack
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Reservation & Post Deletion ≤ 2.4.4 CVE-2025-1326 Wordfence
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 2.4.4 CVE-2025-1327 Wordfence
6.4 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.1.3 CVE-2025-3890 Wordfence
5.3 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object Reference via 'quantity' No login needed ≤ 5.1.3 CVE-2025-3889 Wordfence
6.5 Medium WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object Reference No login needed ≤ 5.1.3 CVE-2025-3874 Wordfence
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
4.3 Medium Simple Sitemap – Create a Responsive HTML Sitemap Plugin simple-sitemap Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-39413 Patchstack
5.3 Medium Kleo Plugin kleo Broken Access Control No login needed ≤ 5.4.4 Fixed in 5.4.4 CVE-2025-39367 Patchstack
5.3 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Broken Access Control Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.10.35 CVE-2025-3912 Wordfence
5.4 Medium Custom Login and Registration Plugin ms-registration Broken Access Control ≤ 1.0.0 CVE-2025-46535 Patchstack
6.5 Medium WP Quiz Plugin wp-quiz Cross-Site Scripting ≤ 2.0.10 CVE-2025-46482 Patchstack
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Information Disclosure Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.8.8 CVE-2025-3923 Wordfence
5.4 Medium Zalo Official Live Chat Plugin zalo-official-live-chat Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-46498 Patchstack
5.9 Medium COVID-19 (Coronavirus) Update Your Customers Plugin covid-19-alert Cross-Site Scripting ≤ 1.5.1 CVE-2025-46523 Patchstack
4.9 Medium WP AVCL Automation Helper (formerly WPFlyLeads) Plugin woozap Server-Side Request Forgery ≤ 3.4 CVE-2025-46531 Patchstack
6.5 Medium Fable Extra Plugin fable-extra Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46447 Patchstack
4.3 Medium Media Library Downloader Plugin media-library-downloader Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-46519 Patchstack
6.4 Medium BeerXML Shortcode Plugin beerxml-shortcode Server-Side Request Forgery ≤ 0.7.1 Fixed in 0.8 CVE-2025-46511 Patchstack
4.9 Medium Simple Google Photos Grid Plugin simple-google-photos-grid Server-Side Request Forgery ≤ 1.5 Fixed in 1.6 CVE-2025-46503 Patchstack
5.3 Medium Bulk Assign Linked Products For WooCommerce Plugin wc-bulk-assign-linked-products Broken Access Control No login needed ≤ 2.1 CVE-2025-46489 Patchstack
5.3 Medium WP Customize Login Page Plugin wp-customize-login-page Broken Access Control No login needed ≤ 1.6.5 CVE-2025-46485 Patchstack
5.9 Medium WP Customize Login Page Plugin wp-customize-login-page Cross-Site Scripting ≤ 1.6.5 CVE-2025-46477 Patchstack
5.9 Medium Send From Plugin send-from Cross-Site Scripting ≤ 2.2 Fixed in 2.3 CVE-2025-46469 Patchstack
5.9 Medium Confirm User Registration Plugin confirm-user-registration Cross-Site Scripting ≤ 2.1.5 CVE-2025-46459 Patchstack
5.9 Medium Floating Social Bar Plugin floating-social-bar Cross-Site Scripting ≤ 1.1.7 CVE-2025-46451 Patchstack
5.9 Medium WP-reCAPTCHA-bp Plugin wp-recaptcha-bp Cross-Site Scripting ≤ 4.1 CVE-2025-46541 Patchstack
5.9 Medium Landing pages and Domain aliases Plugin landing-pages-and-domain-aliases Cross-Site Scripting ≤ 0.8 CVE-2025-46533 Patchstack
5.9 Medium Business Contact Widget Plugin business-contact-widget Cross-Site Scripting ≤ 2.7.0 CVE-2025-46529 Patchstack
5.9 Medium WP Cookie Consent Plugin wp-cookie-consent Cross-Site Scripting ≤ 1.0 CVE-2025-46525 Patchstack
5.9 Medium WS Force Login Page Plugin ws-force-login-page Cross-Site Scripting ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-46521 Patchstack
5.9 Medium Blog Manager WP Plugin blog-manager-wp Cross-Site Scripting ≤ 1.0.5 CVE-2025-46517 Patchstack
4.3 Medium All in One Time Clock Lite Plugin aio-time-clock-lite Cross-Site Request Forgery No login needed ≤ 1.3.326 Fixed in 1.3.326 CVE-2025-46513 Patchstack
6.5 Medium 360 View Plugin 360-view Cross-Site Scripting ≤ 1.1.0 CVE-2025-46509 Patchstack
6.5 Medium Peekaboo Plugin peekaboo Cross-Site Scripting ≤ 1.1 CVE-2025-46505 Patchstack
6.5 Medium Mixcloud Embed Plugin mixcloud-embed Cross-Site Scripting ≤ 2.2.0 CVE-2025-46501 Patchstack
6.5 Medium Mini twitter feed Plugin mini-twitter-feed Cross-Site Scripting ≤ 3.0 CVE-2025-46496 Patchstack
6.5 Medium Multi-Column Taxonomy List Plugin multi-column-taxonomy-list Cross-Site Scripting ≤ 1.5 CVE-2025-46491 Patchstack
6.5 Medium Peadig’s Google +1 Button Plugin google-1 Cross-Site Scripting ≤ 0.1.2 CVE-2025-46483 Patchstack
6.5 Medium BBCode Deluxe Plugin bbcode-deluxe Cross-Site Scripting ≤ 2020.08.01.2 CVE-2025-46479 Patchstack
6.5 Medium Able Player Plugin ableplayer Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-46475 Patchstack
6.5 Medium WP Custom Post Popup Plugin custom-post-popup Cross-Site Scripting ≤ 1.0.1 CVE-2025-46471 Patchstack
6.5 Medium RAphicon Plugin raphicon Cross-Site Scripting ≤ 2.1.2 CVE-2025-46467 Patchstack
6.5 Medium RRSSB Plugin rrssb Cross-Site Scripting ≤ 1.0.1 CVE-2025-46461 Patchstack
6.5 Medium Zoho Creator Forms Plugin zohocreator Cross-Site Scripting ≤ 1.0.5 CVE-2025-46453 Patchstack
6.5 Medium External Markdown Plugin external-markdown Cross-Site Scripting ≤ 0.0.1 CVE-2025-46445 Patchstack
6.5 Medium Xpert Tab Plugin xpert-tab Cross-Site Scripting ≤ 1.3 CVE-2025-46542 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only