WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 401–450 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Epeken All Kurir Plugin epeken-all-kurir Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-32673 Patchstack
7.1 High Mergado Pack Plugin mergado-marketing-pack Cross-Site Request Forgery No login needed ≤ 4.2.1 CVE-2025-32669 Patchstack
7.1 High Libro de Reclamaciones y Quejas Plugin libro-de-reclamaciones-y-quejas Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-32113 Patchstack
7.1 High Sidebar Manager Light Plugin sidebar-manager-light Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.18 CVE-2025-32112 Patchstack
7.1 High Web Directory Free Plugin web-directory-free Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.8 CVE-2025-30908 Patchstack
7.1 High JSON Structuring Markup Plugin json-structuring-markup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-31908 Patchstack
7.1 High WP Profitshare Plugin wp-profitshare Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.9 CVE-2025-31906 Patchstack
7.1 High Ebook Downloader Plugin ebook-downloader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-31904 Patchstack
7.1 High Useinfluence Plugin useinfluence Cross-Site Request Forgery No login needed ≤ 1.0.8 CVE-2025-31625 Patchstack
7.1 High Rich Text Editor Plugin richtexteditor Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-31623 Patchstack
7.1 High PostmarkApp Email Integrator Plugin postmarkapp-email-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 Fixed in 2.5.0 CVE-2025-31617 Patchstack
7.1 High Varnish Plugin varnish-wp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-31616 Patchstack
7.1 High Simple Contact Forms Plugin simple-contact-forms Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.4 CVE-2025-31615 Patchstack
7.1 High AB Google Map Travel Plugin ab-google-map-travel Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.6 CVE-2025-31613 Patchstack
7.1 High Leadfox Plugin leadfox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-31585 Patchstack
7.1 High WP Copy Media URL Plugin wp-copy-media-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-31583 Patchstack
7.1 High Related Posts Widget with Thumbnails Plugin advanced-css3-related-posts-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-31570 Patchstack
7.1 High wordpress related Posts with thumbnails Plugin related-posts-list-grid-and-slider-all-in-one Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0.1 CVE-2025-31569 Patchstack
7.1 High Rio Video Gallery Plugin rio-video-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.6 CVE-2025-31566 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
7.1 High KK I Like It Plugin kk-i-like-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.5.3 CVE-2025-31443 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
7.1 High Video Embedder Plugin video-embedder Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.7.1 Fixed in 1.8 CVE-2025-31458 Patchstack
7.1 High Login Alert Plugin login-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.1 CVE-2025-31459 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
7.1 High Filled In Plugin filled-in Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-22628 Patchstack
7.1 High Listings for Appfolio Plugin listings-for-appfolio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22658 Patchstack
7.1 High Secret Meta Plugin facebook-secret-meta Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-25086 Patchstack
7.1 High Cazamba Plugin cazamba Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25100 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.1 High Cookies Pro Plugin cookies-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-26546 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
8.8 High Booknetic Plugin Cross-Site Request Forgery Staff Creation via CSRF No login needed < 4.1.5 Fixed in 4.1.5 CVE-2024-13146 WPScan
7.2 High Downloable by American Osteopathic Association Plugin Server-Side Request Forgery Unauthenticated SSRF No login needed ≤ 0.1.0 CVE-2024-13618 WPScan
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack
7.1 High Map Contact Plugin map-contact Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.4 CVE-2025-30588 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only