WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,301–4,350 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 87 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Events Planner Plugin events-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.10 CVE-2025-26586 Patchstack
7.1 High DL Leadback Plugin dl-leadback Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-26585 Patchstack
7.1 High Mobile Plugin rocket-wp-mobile Cross-Site Scripting No login needed ≤ 1.3.3 CVE-2025-26563 Patchstack
7.1 High ViperBar Plugin viperbar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-26557 Patchstack
7.7 High Helloprint Plugin helloprint Arbitrary File Deletion ≤ 2.0.7 Fixed in 2.1.0 CVE-2025-26540 Patchstack
8.6 High Helloprint Plugin helloprint Arbitrary File Deletion No login needed ≤ 2.0.7 Fixed in 2.1.0 CVE-2025-26534 Patchstack
7.1 High Migrate Posts Plugin migrate-post Cross-Site Scripting Post Based Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-25170 Patchstack
7.1 High Authors Autocomplete Meta Box Plugin authors-autocomplete-meta-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25169 Patchstack
7.1 High Staff Directory Plugin: Company Directory Plugin staff-directory-pro Cross-Site Scripting No login needed ≤ 4.3 CVE-2025-25165 Patchstack
7.1 High Meta Accelerator Plugin meta-accelerator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-25164 Patchstack
7.1 High Sports Rankings and Lists Plugin sports-rankings-lists Path Traversal Arbitrary File Download No login needed ≤ 1.0.2 CVE-2025-25162 Patchstack
7.1 High WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.3.1 CVE-2025-25161 Patchstack
7.1 High Uncomplicated SEO Plugin uncomplicated-seo Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-25158 Patchstack
7.1 High WP Church Center Plugin wp-church-center Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-25157 Patchstack
7.1 High WP Less Compiler Plugin wp-less-compiler Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2025-25142 Patchstack
7.1 High WP Frontend Submit Plugin wp-frontend-submit Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-25133 Patchstack
7.1 High Visitor Details Plugin visitors-details Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-25132 Patchstack
7.5 High Delete Comments By Status Plugin delete-comments-by-status Local File Inclusion No login needed ≤ 2.1.1 CVE-2025-25130 Patchstack
7.1 High Callback Request Plugin callback-request Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-25129 Patchstack
7.1 High Contact Us By Lord Linus Plugin contact-us-by-lord-linus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6 CVE-2025-25127 Patchstack
7.1 High Status Updater Plugin fb-status-updater Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2025-25124 Patchstack
8.1 High WizShop Plugin wizshop Local File Inclusion No login needed ≤ 3.0.2 CVE-2025-25122 Patchstack
7.1 High Woocommerce osCommerce Sync Plugin woo-oscommerce-sync Cross-Site Scripting No login needed ≤ 2.0.20 CVE-2025-25119 Patchstack
7.1 High Top Bar – PopUps – by WPOptin Plugin wpoptin Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2025-25118 Patchstack
7.1 High User Role Plugin user-roles Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-25114 Patchstack
7.1 High Implied Cookie Consent Plugin implied-cookie-consent Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-25113 Patchstack
7.6 High Social Links Plugin social-links SQL Injection ≤ 1.2 CVE-2025-25112 Patchstack
8.1 High WP Vehicle Manager Plugin js-vehicle-manager Local File Inclusion No login needed ≤ 3.1 CVE-2025-25109 Patchstack
7.1 High SW Plus Plugin shalom-world-media-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-25108 Patchstack
7.1 High Yahoo BOSS Plugin yahoo-boss Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7 CVE-2025-25102 Patchstack
7.1 High Appointment Buddy Widget Plugin appointment-buddy-online-appointment-booking-by-accrete Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-25099 Patchstack
7.1 High All push notification for WP Plugin all-push-notification Cross-Site Scripting No login needed ≤ 1.5.3 CVE-2025-25092 Patchstack
7.1 High Dreamstime Stock Photos Plugin dreamstime-stock-photos Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1 Fixed in 4.2 CVE-2025-25090 Patchstack
7.1 High Image Rotator Plugin appten-image-rotator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-25089 Patchstack
7.1 High seekXL Snapr Plugin seekxl-snapr Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.6 CVE-2025-25087 Patchstack
7.1 High EP4 More Embeds Plugin ep4-more-embeds Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-25083 Patchstack
7.1 High Album Reviewer Plugin albumreviewer Cross-Site Scripting No login needed ≤ 2.0.2 CVE-2025-25070 Patchstack
7.1 High CM Map Locations Plugin cm-map-locations Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-24758 Patchstack
7.1 High CM Pop-Up banners Plugin cm-pop-up-banners Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-24694 Patchstack
7.1 High WP Easy Post Mailer Plugin wp-mailer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.64 CVE-2025-23956 Patchstack
7.5 High Popliup Plugin popliup Local File Inclusion ≤ 1.1.1 CVE-2025-23945 Patchstack
7.1 High Rebrand Fluent Forms Plugin rebrand-fluent-forms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23904 Patchstack
7.1 High Local Shipping Labels for WooCommerce Plugin local-shipping-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23903 Patchstack
7.1 High Stray Random Quotes Plugin stray-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.9 CVE-2025-23883 Patchstack
7.1 High LJ Custom Menu Links Plugin lj-custom-menu-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2025-23881 Patchstack
7.1 High Easy Automatic Newsletter Lite Plugin easy-automatic-newsletter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 CVE-2025-23879 Patchstack
7.1 High First Comment Redirect Plugin first-comment-redirect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23852 Patchstack
7.1 High Mojo Under Construction Plugin mojo-under-construction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23850 Patchstack
7.1 High Site Launcher Plugin site-launcher Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.4 CVE-2025-23847 Patchstack
7.1 High WP-HR Manager: The Human Resources Plugin wp-hr-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.0 Fixed in 3.2.0 CVE-2025-23843 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only