WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,201–4,250 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 85 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WP01 Plugin wp01 Path Traversal Arbitrary File Download No login needed ≤ 2.6.2 CVE-2025-30567 Patchstack
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
7.6 High JiangQie Official Website Mini Program Plugin jiangqie-official-website-mini-program SQL Injection ≤ 1.8.2 CVE-2025-30604 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30590 Patchstack
7.1 High Map Contact Plugin map-contact Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.4 CVE-2025-30588 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High cTabs Plugin ctabs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-30586 Patchstack
7.1 High AlphaOmega Captcha & Anti-Spam Filter Plugin alphaomega-captcha-anti-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3 CVE-2025-30584 Patchstack
7.1 High Pro Rank Tracker Plugin proranktracker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30583 Patchstack
7.1 High AdSense Privacy Policy Plugin adsense-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30578 Patchstack
7.1 High Browser Address Bar Color Plugin browser-address-bar-color Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3 Fixed in 3.4 CVE-2025-30577 Patchstack
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
7.6 High STEdb Forms Plugin stedb-forms SQL Injection ≤ 1.0.4 CVE-2025-30571 Patchstack
7.6 High دکمه، شبکه اجتماعی خرید Plugin dokme SQL Injection ≤ 2.0.6 CVE-2025-30570 Patchstack
8.5 High WP Featured Entries Plugin wp-featured-entries SQL Injection WordPress WP Featured Entries plugin <= - 1.0 SQL Injection ≤ 1.0 CVE-2025-30569 Patchstack
7.1 High banner-manager Plugin banner-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 16.04.19 CVE-2025-30565 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
7.1 High CAS Maestro Plugin cas-maestro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 CVE-2025-30561 Patchstack
7.1 High jQuery Dropdown Menu Plugin jquery-drop-down-menu-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 CVE-2025-30560 Patchstack
7.1 High ANAC XML Render Plugin anac-xml-render Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.7 CVE-2025-30558 Patchstack
7.1 High WordPres 同步微博 Plugin wp2wb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30555 Patchstack
7.1 High WordPress Admin Bar Improved Plugin wordpress-admin-bar-improved Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.5 CVE-2025-30552 Patchstack
7.1 High CallPhone'r Plugin callphoner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30550 Patchstack
7.6 High WP Profitshare Plugin wp-profitshare SQL Injection ≤ 1.4.9 CVE-2025-30525 Patchstack
7.6 High Super Simple Subscriptions Plugin super-simple-subscriptions SQL Injection ≤ 1.1.0 CVE-2025-30523 Patchstack
7.1 High Contact Form 7 Material Design Plugin cf7-material-design Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30522 Patchstack
8.8 High FoodBakery | Delivery Restaurant Directory Theme Broken Access Control Missing Authorization in Multiple Functions ≤ 4.7 CVE-2024-12920 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
8.5 High All In Menu Plugin all-in-menu SQL Injection ≤ 1.1.5 CVE-2025-27281 Patchstack
8.5 High FS Poster Plugin fs-poster SQL Injection ≤ 6.5.8 Fixed in 6.5.9 CVE-2025-26978 Patchstack
8.5 High PrivateContent Plugin private-content SQL Injection ≤ 8.11.4 CVE-2025-26976 Patchstack
7.1 High PrivateContent Plugin private-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.11.5 CVE-2025-26972 Patchstack
8.3 High PrivateContent Plugin private-content Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 8.11.5 CVE-2025-26969 Patchstack
8.6 High Fresh Framework Plugin fresh-framework Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.70.0 CVE-2025-26961 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
7.6 High PublishPress Authors Plugin publishpress-authors SQL Injection ≤ 4.7.3 Fixed in 4.7.4 CVE-2025-26886 Patchstack
7.1 High WP AntiDDOS Plugin wpantiddos Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-26556 Patchstack
7.1 High Debug-Bar-Extender Plugin debug-bar-extender Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-26555 Patchstack
7.1 High WP Discord Post Plugin wp-discord-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-26554 Patchstack
7.1 High Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26553 Patchstack
7.1 High Random Image Selector Plugin random-image-selector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26548 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Privilege Escalation uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 2.2.0 CVE-2025-1653 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Broken Access Control uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection ≤ 2.2.0 CVE-2025-1657 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only