WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 401–450 of 1,027 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 21
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Ultimate Tours Builder Plugin wp_ultimatetoursbuilder Cross-Site Request Forgery No login needed ≤ 1.055 CVE-2025-31921 Patchstack
5.4 Medium Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-31915 Patchstack
6.1 Medium WooCommerce Checkout & Funnel Builder by FunnelKit Plugin SQL Injection Admin+ SQL Injection No login needed < 3.10.2 Fixed in 3.10.2 CVE-2025-2203 WPScan
4.8 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Stored XSS < 6.0.2.1 Fixed in 6.0.2.1 CVE-2024-9390 WPScan
4.8 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Page Builder: Pagelayer < 1.9.0- Admin+ Stored XSS < 1.9.0 Fixed in 1.9.0 CVE-2024-8618 WPScan
4.8 Medium Profile Builder Plugin Cross-Site Scripting Admin+ Stored Cross Site Scripting < 3.12.2 Fixed in 3.12.2 CVE-2024-6708 WPScan
5.4 Medium ARForms Builder Plugin Cross-Site Scripting Unauthenticated Stored XSS < 1.7.1 Fixed in 1.7.1 CVE-2024-10504 WPScan
4.8 Medium Lead Form Builder Plugin Cross-Site Scripting Admin+ Stored XSS < 1.9.8 Fixed in 1.9.8 CVE-2024-10475 WPScan
4.3 Medium Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 6.18.15 CVE-2025-3949 Wordfence
6.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Remote Code Execution Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function ≤ 8.9.1 CVE-2025-4208 Wordfence
6.4 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting ≤ 8.9.1 CVE-2025-3468 Wordfence
5.9 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-47525 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.2 Fixed in 5.3.3 CVE-2025-47488 Patchstack
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
6.5 Medium tagDiv Opt-In Builder Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via subscriptionCouponId Parameter ≤ 1.7 CVE-2025-2890 Wordfence
5.3 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Broken Access Control Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.10.35 CVE-2025-3912 Wordfence
5.3 Medium Upsell Funnel Builder for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Other Unauthenticated Order Manipulation No login needed ≤ 3.0.0 CVE-2025-3743 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.5 Medium Image Hover Effects For WPBakery Page Builder Plugin image-hover-effects-for-visual-composer Cross-Site Scripting ≤ 2.0 CVE-2025-46484 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.10.0 Fixed in 45.11.0 CVE-2025-46254 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 2.1 CVE-2025-46235 Patchstack
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.13.6 CVE-2025-2314 Wordfence
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.9 CVE-2025-26998 Patchstack
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2025-3276 Wordfence
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder SQL Injection Authenticated (Subscriber+) SQL Injection via order_ids Parameter ≤ 3.2.67 CVE-2025-2128 Wordfence
6.5 Medium Contact Form Builder by vcita Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.10.2 Fixed in 4.10.5 CVE-2025-32199 Patchstack
4.3 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.8.4 Fixed in 1.2.8.5 CVE-2025-32201 Patchstack
6.5 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.329 Fixed in 1.0.332 CVE-2025-32185 Patchstack
6.4 Medium RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 6.0.4.3 CVE-2025-2836 Wordfence
5.4 Medium Pearl Plugin pearl-header-builder Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-31881 Patchstack
4.3 Medium Pearl Plugin pearl-header-builder Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-31880 Patchstack
6.5 Medium PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Cross-Site Scripting ≤ 2.1.0 Fixed in 2.2.0 CVE-2025-31850 Patchstack
6.5 Medium Team Members for Elementor Page Builder Plugin team-members-for-elementor Cross-Site Scripting ≤ 1.0.4 CVE-2025-31771 Patchstack
6.5 Medium HMH Footer Builder For Elementor Plugin hmh-footer-builder-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2025-31749 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.11.14 CVE-2025-1665 Wordfence
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.65 Fixed in 3.2.66 CVE-2025-31414 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.9 Medium Chartify Plugin chart-builder Cross-Site Scripting ≤ 3.1.7 Fixed in 3.1.9 CVE-2025-30904 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 11.0.2 Fixed in 11.1 CVE-2025-30873 Patchstack
5.4 Medium Live Forms Plugin liveforms Broken Access Control Live Forms plugin <= 4.8.4 - Settings Change ≤ 4.8.4 Fixed in 4.8.5 CVE-2025-30809 Patchstack
6.5 Medium Build Theme build Cross-Site Scripting ≤ 1.0.3 CVE-2025-26869 Patchstack
6.4 Medium Amazing service box Addons For WPBakery Page Builder Plugin amazing-service-box-visual-composer-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.0.0 CVE-2025-2573 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
6.4 Medium Make Builder Plugin make-builder Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via make_builder_ajax_subscribe Function ≤ 1.1.10 CVE-2024-13856 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication ≤ 1.9.8 CVE-2025-2104 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 CVE-2024-13430 Wordfence
5.5 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 6.2 CVE-2024-13838 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only