WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,451–4,500 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 90 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Fast Flow Plugin fast-flow-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.16 Fixed in 1.2.18 CVE-2025-26868 Patchstack
7.5 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Path Traversal Arbitrary File Download No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26753 Patchstack
8.6 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Arbitrary File Deletion No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26752 Patchstack
7.1 High Alphabetic Pagination Plugin alphabetic-pagination Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-26751 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.25.17 Fixed in 3.25.18 CVE-2025-26987 Patchstack
8.1 High Majestic Support Plugin majestic-support Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-26985 Patchstack
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
7.1 High 无觅相关文章插件 Plugin wumii-related-posts Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.5.7 CVE-2025-27352 Patchstack
7.1 High Smart Maintenance & Countdown Plugin smart-maintenance-countdown Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-27332 Patchstack
7.1 High Blightly Explorer Plugin blighty-explorer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.0 CVE-2025-27321 Patchstack
8.5 High WP Sitemap Plugin wp-sitemap SQL Injection ≤ 1.0 CVE-2025-27312 Patchstack
7.2 High NHR Options Table Manager Plugin nhrrob-options-table-manager PHP Object Injection Deserialization of untrusted data ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-27301 Patchstack
7.2 High ADFO Plugin admin-form PHP Object Injection Deserialization of untrusted data ≤ 1.9.1 CVE-2025-27300 Patchstack
8.3 High WP Video Posts Plugin wp-video-posts Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 3.5.1 CVE-2025-27298 Patchstack
7.6 High Bravo Search & Replace Plugin bravo-search-and-replace SQL Injection ≤ 1.0 CVE-2025-27297 Patchstack
7.2 High Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue Plugin revenueflex-easy-ads Broken Access Control Increase Google Adsense and Ad Manager Revenue Plugin <= 1.5 - Settings Change ≤ 1.5 Fixed in 1.5.1 CVE-2025-27296 Patchstack
7.1 High Add Linked Images To Gallery Plugin add-linked-images-to-gallery-v01 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-27277 Patchstack
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
7.5 High VG PostCarousel Plugin vg-postcarousel Local File Inclusion ≤ 1.1 CVE-2025-27272 Patchstack
7.1 High Eventer Plugin eventer Cross-Site Scripting WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.9 Fixed in 3.9.9 CVE-2025-22635 Patchstack
7.1 High WooCommerce Pricing – Product Pricing Plugin woo-pricing-table Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-22632 Patchstack
7.1 High Marketing Automation Plugin marketing-automation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6.8 Fixed in 1.2.6.9 CVE-2025-22631 Patchstack
7.1 High Responsive Modal Builder for High Conversion – Easy Popups Plugin easy-popups Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-26774 Patchstack
7.5 High Calculator Builder Plugin calculator-builder Local File Inclusion No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-26760 Patchstack
7.5 High FULL Customer Plugin full-customer Local File Inclusion Cliente plugin <= 3.1.26 - Local File Inclusion No login needed ≤ 3.1.26 Fixed in 3.1.27 CVE-2025-26757 Patchstack
8.8 High A1POST.BG Shipping for Woo Plugin a1post-bg-shipping-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5 Fixed in 1.5.1 CVE-2025-27012 Patchstack
7.1 High Magic the Gathering Card Tooltips Plugin magic-the-gathering-card-tooltips Cross-Site Scripting No login needed ≤ 3.5.0 Fixed in 3.6.0 CVE-2025-26756 Patchstack
8.6 High Paid Videochat Turnkey Site Plugin ppv-live-webcams Arbitrary File Deletion No login needed ≤ 7.2.12 Fixed in 7.3 CVE-2025-22663 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.9 Fixed in 4.1.0 CVE-2025-22657 Patchstack
8.1 High Cookie Monster Plugin cookie-monster Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-22656 Patchstack
8.5 High Distance Rate Shipping for WooCommerce Plugin distance-rate-shipping-for-woocommerce-pro SQL Injection ≤ 1.3.4 CVE-2025-22639 Patchstack
7.2 High FormCraft - Premium WordPress Form Builder Plugin Cross-Site Scripting Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.9.11 CVE-2025-0817 Wordfence
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
8.1 High Affiliate Links: WordPress Plugin for Link Cloaking and Link Management Plugin Broken Access Control Missing Authorization to Unauthenticated Import/Export and PHP Object Injection No login needed ≤ 3.0.1 CVE-2024-13556 Wordfence
7.1 High ImageMeta Plugin imagemeta Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23845 Patchstack
7.1 High WP-NOTCAPTCHA Plugin wp-notcaptcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 CVE-2025-23840 Patchstack
7.1 High what3words Address Field Plugin 3-word-address-validation-field Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.15 Fixed in 4.0.16 CVE-2025-26768 Patchstack
7.1 High Content Snippet Manager Plugin content-snippet-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-26759 Patchstack
7.6 High WP Airbnb Review Slider Plugin wp-airbnb-review-slider SQL Injection ≤ 3.9 Fixed in 4.0 CVE-2025-26755 Patchstack
7.1 High Ad Inserter Pro Plugin ad-inserter-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.39 Fixed in 2.8.0 CVE-2025-22680 Patchstack
7.1 High LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition Cross-Site Scripting Worldwide Express Edition plugin <= 5.0.21 - Reflected Cross Site Scripting (XSS) No login needed ≤ 5.0.21 Fixed in 5.0.22 CVE-2025-22286 Patchstack
7.1 High LTL Freight Quotes – Unishippers Edition Plugin ltl-freight-quotes-unishippers-edition Cross-Site Scripting Unishippers Edition plugin <= 2.5.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.8 Fixed in 2.5.9 CVE-2025-22284 Patchstack
7.1 High Oshine Modules Plugin oshine-modules Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44044 Patchstack
7.1 High Admin Options Pages Plugin admin-options-pages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.7 Fixed in 0.9.8 CVE-2025-23905 Patchstack
7.1 High Disqus Popular Posts Plugin disqus-popular-posts Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-22705 Patchstack
7.2 High Monetag Official Plugin monetag-official Broken Access Control No login needed ≤ 1.1.3 CVE-2024-52500 Patchstack
7.1 High Bulk Menu Edit Plugin bulk-menu-edit Broken Access Control ≤ 1.3 Fixed in 1.3.1 CVE-2025-24692 Patchstack
7.1 High WP Mailster Plugin wp-mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.20.0 Fixed in 1.8.21.0 CVE-2025-24688 Patchstack
7.1 High WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-24700 Patchstack
7.1 High WP Coder Plugin wp-coder Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 3.6 Fixed in 3.6.1 CVE-2025-24699 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only