WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,251–4,300 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 86 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Civi - Job Board & Freelance Marketplace Theme Information Disclosure Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Sensitive Information Exposure No login needed ≤ 2.1.4 CVE-2024-13773 Wordfence
8.8 High JobCareer | Job Board Responsive Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions ≤ 7.1 CVE-2024-12810 Wordfence
8.1 High Eco Nature - Environment & Ecology Theme Broken Access Control Environment & Ecology WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 2.0.4 CVE-2025-0952 Wordfence
7.1 High MaxA/B Plugin maxab Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-28933 Patchstack
7.1 High Insert Code Plugin insert-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 CVE-2025-28932 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
7.1 High WATI Chat and Notification Plugin wati-chat-and-notification Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.5 CVE-2025-28925 Patchstack
7.1 High No Disposable Email Plugin no-disposable-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-28923 Patchstack
7.1 High Go To Top Plugin go-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.8 CVE-2025-28922 Patchstack
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack
7.1 High TabGarb Pro Plugin tabgarb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6 CVE-2025-28900 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High List of Posts from each Category Plugin list-posts-by-category Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28894 Patchstack
7.1 High FTP Sync Plugin ftp-sync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.6 CVE-2025-28892 Patchstack
7.1 High price-calc Plugin price-calc Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6.3 CVE-2025-28891 Patchstack
7.1 High WP Compare Tables Plugin wp-compare-tables Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-28883 Patchstack
7.1 High WP jQuery Persian Datepicker Plugin wpjqp-datepicker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0 CVE-2025-28861 Patchstack
7.1 High Google News Editors Picks Feed Generator Plugin google-news-editors-picks-news-feeds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-28860 Patchstack
7.1 High Rankchecker.io Integration Plugin rankchecker-io-integration Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28857 Patchstack
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
7.1 High WordPress Activity O Meter Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13668 WPScan
8.8 High Eventer - WordPress Event & Booking Manager Plugin SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id ≤ 3.9.9.2 CVE-2025-0959 Wordfence
8.8 High School Management System Plugin wpschoolpress Privilege Escalation Authenticated (Student+) Account Takeover and Privilege Escalation ≤ 93.0.0 CVE-2024-9658 Wordfence
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
8.1 High Flex Mag - Responsive WordPress News Theme Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 3.5.2 CVE-2024-13655 Wordfence
8.8 High WordPress Awesome Import & Export Plugin - Import & Export WordPress Data Plugin Broken Access Control Import & Export WordPress Data <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Execution/Privilege Escalation ≤ 4.1.1 CVE-2024-13232 Wordfence
8.1 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin PHP Object Injection WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection No login needed ≤ 6.91 CVE-2024-13777 Wordfence
7.1 High Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26994 Patchstack
7.1 High Zigaform Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26989 Patchstack
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory PHP Object Injection ≤ 2.3.14 Fixed in 2.3.15 CVE-2025-26967 Patchstack
7.1 High Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Cross-Site Scripting Unishippers Edition plugin <= 2.4.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26918 Patchstack
7.1 High WP Templata Plugin wptemplata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26917 Patchstack
7.1 High Variable Inspector Plugin variable-inspector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2025-26914 Patchstack
7.2 High WordPress Assistant Plugin assistant PHP Object Injection ≤ 1.5.1 Fixed in 1.5.1.1 CVE-2025-26885 Patchstack
7.1 High s2Member Plugin s2member Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 241216 Fixed in 250214 CVE-2025-26879 Patchstack
7.1 High Flashfader Plugin flashfader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-27279 Patchstack
7.1 High AcuGIS Leaflet Maps Plugin mapfig-premium-leaflet-map-maker Cross-Site Scripting Multiple Cross Site Scripting (XSS) vulnerabilities No login needed ≤ 5.1.1.0 CVE-2025-27278 Patchstack
7.1 High WOO Codice Fiscale Plugin woo-codice-fiscale Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-27275 Patchstack
7.1 High DB Tables Import/Export Plugin db-tables-importexport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-27271 Patchstack
7.1 High .htaccess Login block Plugin htaccess-login-block Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9a CVE-2025-27269 Patchstack
7.5 High Doctor Appointment Booking Plugin doctor-appointment-booking Local File Inclusion ≤ 1.0.0 CVE-2025-27264 Patchstack
8.5 High Doctor Appointment Booking Plugin doctor-appointment-booking SQL Injection ≤ 1.0.0 CVE-2025-27263 Patchstack
7.1 High IE CSS3 Support Plugin ie-css3-support Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-26589 Patchstack
7.1 High TTT Crop Plugin ttt-crop Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26588 Patchstack
7.1 High sidebarTabs Plugin sidebartabs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1 CVE-2025-26587 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only