WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,451–4,500 of 8,961 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 90 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Musician's Pack For Elementor Plugin music-pack-for-elementor Cross-Site Scripting ≤ 1.8.7 CVE-2025-32190 Patchstack
6.5 Medium BWD Elementor Addons Plugin bwd-elementor-addons Cross-Site Scripting ≤ 4.4.2 CVE-2025-32189 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.15 Fixed in 2.16 CVE-2025-32188 Patchstack
6.5 Medium Administrator Z Plugin administrator-z Cross-Site Scripting ≤ 2026.03.02 CVE-2025-32187 Patchstack
6.5 Medium Turbo Addons Elementor Plugin turbo-addons-elementor Cross-Site Scripting ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-32186 Patchstack
6.5 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.329 Fixed in 1.0.332 CVE-2025-32185 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.5.0 Fixed in 2.6.0 CVE-2025-32184 Patchstack
6.5 Medium Video Playlist For YouTube Plugin video-playlist-for-youtube Cross-Site Scripting ≤ 6.7.1 CVE-2025-32183 Patchstack
6.5 Medium Spider Elements Plugin spider-elements Cross-Site Scripting Addons for Elementor plugin <= 1.6.5 - Cross Site Scripting (XSS) ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-32182 Patchstack
6.5 Medium Search, Filters & Merchandising for WooCommerce Plugin instantsearch-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.58 Fixed in 3.0.59 CVE-2025-32181 Patchstack
6.5 Medium Maps for WP Plugin maps-for-wp Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-32179 Patchstack
6.5 Medium Embed Chessboard Plugin embed-chessboard Cross-Site Scripting ≤ 3.08.00 CVE-2025-32177 Patchstack
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-32176 Patchstack
6.5 Medium VK Filter Search Plugin vk-filter-search Cross-Site Scripting ≤ 2.20.2 CVE-2025-32175 Patchstack
6.5 Medium Tockify Events Calendar Plugin tockify-events-calendar Cross-Site Scripting ≤ 2.2.13 Fixed in 2.3.0 CVE-2025-32174 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-32173 Patchstack
6.5 Medium YaMaps Plugin yamaps Cross-Site Scripting ≤ 0.6.40 Fixed in 0.6.41 CVE-2025-32172 Patchstack
6.5 Medium Table Block by Tableberg Plugin tableberg Cross-Site Scripting ≤ 0.6.10 Fixed in 0.6.12 CVE-2025-32171 Patchstack
6.5 Medium Motors Plugin motors-car-dealership-classified-listings Cross-Site Scripting ≤ 1.4.71 Fixed in 1.4.72 CVE-2025-32170 Patchstack
6.5 Medium Showeblogin Social Plugin showeblogin-facebook-page-like-box Cross-Site Scripting ≤ 7.0 CVE-2025-32169 Patchstack
6.5 Medium Gutenify Plugin gutenify Cross-Site Scripting ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-32168 Patchstack
6.5 Medium SurveyJS Plugin surveyjs Cross-Site Scripting ≤ 1.12.20 Fixed in 1.12.57 CVE-2025-32167 Patchstack
6.5 Medium Emma Plugin emma-emarketing-plugin Cross-Site Scripting ≤ 1.3.3 CVE-2025-32166 Patchstack
6.5 Medium Doppler Forms Plugin doppler-form Cross-Site Scripting ≤ 2.5.1 Fixed in 2.6.0 CVE-2025-32165 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.10 Fixed in 1.4.11 CVE-2025-32163 Patchstack
6.5 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Cross-Site Scripting ≤ 3.3.11 CVE-2025-32162 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.27.1 CVE-2025-32161 Patchstack
6.6 Medium Easy Google Maps Plugin google-maps-easy XML External Entity ≤ 1.11.18 Fixed in 1.11.19 CVE-2025-32138 Patchstack
4.9 Medium s2Member Plugin s2member Local File Inclusion ≤ 250419 Fixed in 250424 CVE-2025-32137 Patchstack
5.9 Medium ActiveCampaign Plugin activecampaign-subscription-forms Cross-Site Scripting ≤ 8.1.16 Fixed in 8.1.17 CVE-2025-32136 Patchstack
5.9 Medium Split Test For Elementor Plugin split-test-for-elementor Cross-Site Scripting ≤ 1.8.4 CVE-2025-32135 Patchstack
5.9 Medium URL Shortify Plugin url-shortify Cross-Site Scripting ≤ 1.10.5.1 Fixed in 1.10.6 CVE-2025-32134 Patchstack
5.9 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting ≤ 4.5.5 Fixed in 4.5.6 CVE-2025-32133 Patchstack
5.9 Medium FunnelCockpit Plugin funnelcockpit Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32132 Patchstack
5.9 Medium Social Intents Plugin live-chat-support-by-social-intents Cross-Site Scripting ≤ 1.6.19 CVE-2025-32131 Patchstack
5.9 Medium Posts Footer Manager Plugin intelly-posts-footer-manager Cross-Site Scripting ≤ 2.2.0 CVE-2025-32130 Patchstack
5.9 Medium Welcome Bar Plugin intelly-welcome-bar Cross-Site Scripting ≤ 2.0.4 CVE-2025-32129 Patchstack
6.5 Medium Pallet Packaging for WooCommerce Plugin pallet-packaging-for-woocommerce Broken Access Control No login needed ≤ 1.1.15 Fixed in 1.1.16 CVE-2025-22285 Patchstack
6.5 Medium Simplish Plugin simplish Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.6.4 CVE-2025-22281 Patchstack
6.5 Medium Booking Calendar and Notification Plugin booking-calendar-and-notification Authentication Bypass Broken Authentication No login needed ≤ 4.0.3 CVE-2025-31381 Patchstack
6.5 Medium Tiger Theme tiger Cross-Site Scripting ≤ 2.0 CVE-2025-31407 Patchstack
5.8 Medium Srbtranslatin Plugin srbtranslatin Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.0 CVE-2025-31421 Patchstack
6.5 Medium GetBookingsWP Plugin get-bookings-wp Broken Access Control ≤ 1.1.27 CVE-2025-31896 Patchstack
6.5 Medium Botnet Attack Blocker Plugin botnet-attack-blocker Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 CVE-2025-31893 Patchstack
5.8 Medium Payday Plugin payday Broken Access Control No login needed ≤ 3.3.18 CVE-2025-31876 Patchstack
6.5 Medium Local Magic Plugin local-magic Broken Access Control No login needed ≤ 2.9.0 CVE-2025-31858 Patchstack
6.3 Medium FPW Category Thumbnails Plugin fpw-category-thumbnails Broken Access Control ≤ 1.9.5 CVE-2025-31841 Patchstack
4.9 Medium Fonto Plugin fonto Path Traversal Arbitrary File Download ≤ 1.2.2 CVE-2025-31827 Patchstack
4.9 Medium Category Icon Plugin category-icon Path Traversal Arbitrary File Download ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-31825 Patchstack
6.5 Medium Publitio Plugin publitio Path Traversal Arbitrary File Read ≤ 2.2.0 Fixed in 2.2.2 CVE-2025-31800 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only