WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 401–450 of 1,928 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.9 Medium | Link Library | Server-Side Request Forgery |
≤ 7.8.7 Fixed in 7.8.8 |
CVE-2025-68600 |
Patchstack | |
| 4.3 Medium | Vimeotheque | Cross-Site Request Forgery No login needed |
≤ 2.3.5.2 Fixed in 2.3.6 |
CVE-2025-68584 |
Patchstack | |
| 4.3 Medium | Fast User Switching | Cross-Site Request Forgery No login needed |
≤ 1.4.10 |
CVE-2025-68583 |
Patchstack | |
| 4.3 Medium | Advanced Classifieds & Directory Pro | Cross-Site Request Forgery No login needed |
≤ 3.2.9 Fixed in 3.3.0 |
CVE-2025-68580 |
Patchstack | |
| 5.4 Medium | Simple Keyword to Link | Cross-Site Request Forgery No login needed |
≤ 1.5 |
CVE-2025-68573 |
Patchstack | |
| 5.4 Medium | My auctions allegro | Cross-Site Request Forgery No login needed |
≤ 3.6.33 Fixed in 3.6.34 |
CVE-2025-68567 |
Patchstack | |
| 4.3 Medium | Trade Runner | Cross-Site Request Forgery No login needed |
≤ 3.14 |
CVE-2025-67625 |
Patchstack | |
| 5.4 Medium | 6Storage Rentals | Server-Side Request Forgery No login needed |
≤ 2.22.0 |
CVE-2025-67623 |
Patchstack | |
| 4.3 Medium | WP Email Capture | Cross-Site Request Forgery No login needed |
≤ 3.12.5 Fixed in 3.12.6 |
CVE-2025-68529 |
Patchstack | |
| 4.9 Medium | Prime Slider – Addons For Elementor | Server-Side Request Forgery Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) |
≤ 4.0.10 Fixed in 4.1.0 |
CVE-2025-68500 |
Patchstack | |
| 4.3 Medium | Premium Addons for Elementor | Cross-Site Request Forgery Cross-Site Request Forgery via 'insert_inner_template' No login needed |
≤ 4.11.53 |
CVE-2025-14163 |
Wordfence | |
| 4.3 Medium | Feather Login Page | Cross-Site Request Forgery No login needed |
≤ 1.1.7 |
CVE-2025-62107 |
Patchstack | |
| 4.3 Medium | Custom 404 Pro | Cross-Site Request Forgery No login needed |
≤ 3.12.0 |
CVE-2025-62880 |
Patchstack | |
| 4.3 Medium | Web to SugarCRM Lead | Cross-Site Request Forgery Cross-Site Request Forgery to Custom Field Deletion No login needed |
≤ 1.0.0 |
CVE-2025-13361 |
Wordfence | |
| 6.1 Medium | WP Hallo Welt | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.4. |
CVE-2025-13365 |
Wordfence | |
| 4.3 Medium | WP DB Booster | Cross-Site Request Forgery Cross-Site Request Forgery to Database Cleanup No login needed |
≤ 1.0.1 |
CVE-2025-14168 |
Wordfence | |
| 5.4 Medium | Amazon affiliate lite | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-14734 |
Wordfence | |
| 4.3 Medium | Quran Gateway | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.5 |
CVE-2025-14164 |
Wordfence | |
| 4.3 Medium | Prime Slider – Addons for Elementor | Server-Side Request Forgery Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 4.0.9 |
CVE-2025-14277 |
Wordfence | |
| 4.3 Medium | Download Plugins and Themes from Dashboard | Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Plugin/Theme Archival No login needed |
≤ 1.9.6 |
CVE-2025-14399 |
Wordfence | |
| 4.9 Medium | Zephyr Project Manager | Path Traversal Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery |
≤ 3.3.203 |
CVE-2025-12496 |
Wordfence | |
| 6.5 Medium | Fancy Product Designer | WooCommerce | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed |
≤ 6.4.8 |
CVE-2025-13231 |
Wordfence | |
| 5.4 Medium | Meks Quick Plugin Disabler | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-68083 |
Patchstack | |
| 5.4 Medium | Semrush Content Toolkit | Cross-Site Request Forgery No login needed |
≤ 1.1.32 Fixed in 1.1.33 |
CVE-2025-68082 |
Patchstack | |
| 5.4 Medium | Kerge | Server-Side Request Forgery No login needed |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2025-67989 |
Patchstack | |
| 4.3 Medium | Freshchat | Cross-Site Request Forgery No login needed |
≤ 2.3.4 |
CVE-2025-64240 |
Patchstack | |
| 4.3 Medium | RTL Tester | Cross-Site Request Forgery No login needed |
≤ 1.2 |
CVE-2025-64239 |
Patchstack | |
| 4.3 Medium | Quick Interest Slider | Cross-Site Request Forgery No login needed |
≤ 3.1.5 Fixed in 3.1.6 |
CVE-2025-64237 |
Patchstack | |
| 4.3 Medium | Listify | Cross-Site Request Forgery No login needed |
≤ 3.2.5 |
CVE-2025-59009 |
Patchstack | |
| 4.3 Medium | WP Attractive Donations System - Easy Stripe & Paypal donations | Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.25 |
CVE-2025-58999 |
Patchstack | |
| 4.3 Medium | Popover Windows | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Popover Configuration Update No login needed |
≤ 1.2 |
CVE-2025-14394 |
Wordfence | |
| 4.3 Medium | Lucky Draw Contests | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 4.2 |
CVE-2025-14462 |
Wordfence | |
| 4.4 Medium | Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated | Server-Side Request Forgery AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated <= 1.0.9 - Authenticated (Admin+) Server-Side Request Forgery |
≤ 1.0.9 |
CVE-2025-11970 |
Wordfence | |
| 4.3 Medium | Image Slider by Ays- Responsive Slider and Carousel | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed |
≤ 2.7.0 |
CVE-2025-14454 |
Wordfence | |
| 4.3 Medium | Events Manager – Calendar, Bookings, Tickets, and more! | Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed |
≤ 7.2.2.2 |
CVE-2025-12407 |
Wordfence | |
| 4.3 Medium | Secure Copy Content Protection and Content Locking | Cross-Site Request Forgery Cross-Site Request Forgery to Data Export No login needed |
≤ 4.9.2 |
CVE-2025-14159 |
Wordfence | |
| 4.3 Medium | Simple Theme Changer | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration Update No login needed |
≤ 1.0 |
CVE-2025-14391 |
Wordfence | |
| 4.3 Medium | Rabbit Hole | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed |
≤ 1.1 |
CVE-2025-13366 |
Wordfence | |
| 4.3 Medium | Upcoming for Calendly | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.4 |
CVE-2025-14160 |
Wordfence | |
| 4.3 Medium | Purchase and Expense Manager | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Purchase Record Deletion No login needed |
≤ 1.1.2 |
CVE-2025-13987 |
Wordfence | |
| 4.3 Medium | Animated Pixel Marquee Creator | Cross-Site Request Forgery Cross-Site Request Forgery via 'marquee' Parameter No login needed |
≤ 1.0.0 |
CVE-2025-14062 |
Wordfence | |
| 4.3 Medium | Truefy Embed | Cross-Site Request Forgery Cross-Site Request Forgery to 'truefy_embed_options_update' Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-14161 |
Wordfence | |
| 4.3 Medium | Resource Library for Logged In Users | Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed |
≤ 1.5 |
CVE-2025-14354 |
Wordfence | |
| 4.3 Medium | Kirim.Email WooCommerce Integration | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.9 |
CVE-2025-14165 |
Wordfence | |
| 4.3 Medium | IMAQ Core | Cross-Site Request Forgery Cross-Site Request Forgery to URL Structure Update No login needed |
≤ 1.2.1 |
CVE-2025-13363 |
Wordfence | |
| 4.3 Medium | Coding Blocks | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-14158 |
Wordfence | |
| 4.3 Medium | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images | Cross-Site Request Forgery Cross-Site Request Forgery to Google OAuth Connection No login needed |
≤ 2.5.2 |
CVE-2025-13408 |
Wordfence | |
| 4.3 Medium | BMLT | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Creation and Deletion No login needed |
≤ 3.11.4 |
CVE-2025-14162 |
Wordfence | |
| 5.8 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 5.1.1 |
CVE-2025-11467 |
Wordfence | |
| 4.3 Medium | Advanced Product Fields (Product Addons) for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Product Field Group Duplication and Publication No login needed |
≤ 1.6.17 |
CVE-2025-13924 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.