WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,351–4,400 of 8,961 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 88 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Contact Form Builder by vcita Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.10.2 Fixed in 4.10.5 CVE-2025-32199 Patchstack
6.5 Medium Brizy Plugin brizy Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-32198 Patchstack
5.9 Medium FooBox Image Lightbox Plugin foobox-image-lightbox Cross-Site Scripting FooBox plugin <= 2.7.33 - Cross Site Scripting (XSS) ≤ 2.7.33 Fixed in 2.7.34 CVE-2025-32139 Patchstack
5.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2025-26888 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Cross-Site Request Forgery No login needed ≤ 2.6.1 CVE-2025-26902 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Broken Access Control ≤ 2.6.1 CVE-2025-26901 Patchstack
4.3 Medium Rich Table of Contents Plugin rich-table-of-content Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-31004 Patchstack
4.3 Medium Easyfonts Plugin easyfonts Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31005 Patchstack
5.4 Medium IndieBlocks Plugin indieblocks Server-Side Request Forgery No login needed ≤ 0.13.1 Fixed in 0.13.2 CVE-2025-31009 Patchstack
5.9 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4 CVE-2025-31008 Patchstack
5.3 Medium Age Gate Plugin age-gate Broken Access Control No login needed ≤ 3.5.4 Fixed in 3.6.0 CVE-2025-31012 Patchstack
6.5 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2025-31020 Patchstack
6.5 Medium Nav Menu Manager Plugin noakes-menu-manager Cross-Site Scripting ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-31017 Patchstack
5.9 Medium WP Editor.md – The Perfect WordPress Markdown Editor Plugin wp-editormd Cross-Site Scripting The Perfect Markdown Editor plugin <= 10.2.1 - Cross Site Scripting (XSS) ≤ 10.2.1 CVE-2025-31035 Patchstack
4.3 Medium Customize Login Page Plugin customize-login-page Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1 CVE-2025-31034 Patchstack
5.3 Medium Sandwich Adsense Plugin firsth3tagadsense Broken Access Control No login needed ≤ 4.0.2 CVE-2025-31042 Patchstack
5.9 Medium Request Call Back Plugin request-call-back Cross-Site Scripting ≤ 1.4.1 CVE-2025-32483 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2025-32485 Patchstack
5.9 Medium Aria Font Plugin aria-font Cross-Site Scripting ≤ 1.4 CVE-2025-32488 Patchstack
4.9 Medium Waymark Plugin waymark Server-Side Request Forgery ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-32487 Patchstack
5.9 Medium Wetterwarner Plugin wetterwarner Cross-Site Scripting ≤ 2.7.3 Fixed in 2.8 CVE-2025-32489 Patchstack
5.9 Medium BP Social Connect Plugin bp-social-connect Cross-Site Scripting ≤ 1.6.2 CVE-2025-32493 Patchstack
5.9 Medium Admin Menu Post List Plugin admin-menu-post-list Cross-Site Scripting ≤ 2.0.7 CVE-2025-32492 Patchstack
6.5 Medium Waymark Plugin waymark Cross-Site Scripting ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-32495 Patchstack
4.3 Medium reCAPTCHA Jetpack Plugin recaptcha-jetpack Cross-Site Request Forgery No login needed ≤ 0.2.2 CVE-2025-32494 Patchstack
6.5 Medium Logo Showcase Ultimate Plugin logo-showcase-ultimate Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-32499 Patchstack
5.9 Medium Ally Plugin pojo-accessibility Cross-Site Scripting ≤ 3.1.0 Fixed in 3.2.0 CVE-2025-32640 Patchstack
6.8 Medium SEO Help Plugin seo-help Server-Side Request Forgery ≤ 6.7.9 CVE-2025-32675 Patchstack
5.4 Medium User Registration Using Contact Form 7 Plugin user-registration-using-contact-form-7 Cross-Site Request Forgery No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32679 Patchstack
4.3 Medium WP Show Stats Plugin wp-show-stats Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-32678 Patchstack
5.9 Medium Review Stream Plugin review-stream Cross-Site Scripting ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-32680 Patchstack
6.5 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting ≤ 8.6.6 Fixed in 8.6.7 CVE-2025-32683 Patchstack
5.0 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Broken Access Control ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32684 Patchstack
6.5 Medium PowerPress Podcasting Plugin powerpress Cross-Site Scripting ≤ 11.12.5 Fixed in 11.12.6 CVE-2025-32690 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.12.6 Fixed in 11.12.7 CVE-2025-32691 Patchstack
4.7 Medium WebinarPress Plugin wp-webinarsystem Open Redirect No login needed ≤ 1.33.28 CVE-2025-32693 Patchstack
4.7 Medium Ultimate WP Mail Plugin ultimate-wp-mail Open Redirect No login needed ≤ 1.3.10 CVE-2025-32694 Patchstack
4.3 Medium Live Forms Plugin liveforms Broken Access Control No login needed ≤ 4.8.5 CVE-2025-32279 Patchstack
6.5 Medium Broadstreet Ads Plugin broadstreet Cross-Site Scripting ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-32211 Patchstack
6.5 Medium m1.DownloadList Plugin m1downloadlist Information Disclosure Sensitive Data Exposure ≤ 0.24 CVE-2025-32164 Patchstack
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence
6.5 Medium coreActivity: Activity Logging Plugin coreactivity SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.7 CVE-2025-3436 Wordfence
5.4 Medium 6Storage Rentals Plugin 6storage-rentals Broken Access Control ≤ 2.20.2 CVE-2025-32178 Patchstack
5.4 Medium Rollbar Plugin rollbar Cross-Site Request Forgery No login needed ≤ 2.7.1 Fixed in 3.0.0 CVE-2025-32250 Patchstack
4.3 Medium Social Share Buttons & Analytics Plugin – GetSocial.io Plugin wp-share-buttons-analytics-by-getsocial Broken Access Control ≤ 4.5 CVE-2025-32239 Patchstack
5.4 Medium Privyr CRM Integration Plugin privy-crm-integration Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-32224 Patchstack
4.3 Medium WP Project Manager Plugin wedevs-project-manager Cross-Site Request Forgery No login needed ≤ 2.6.25 Fixed in 2.6.25 CVE-2025-32280 Patchstack
4.3 Medium Table Block by RioVizual Plugin riovizual Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-32278 Patchstack
4.3 Medium RepairBuddy Plugin computer-repair-shop Broken Access Control ≤ 3.8213 Fixed in 3.8214 CVE-2025-32277 Patchstack
4.3 Medium Administrator Z Plugin administrator-z Cross-Site Request Forgery No login needed ≤ 2026.03.02 CVE-2025-32276 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only