WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 4,551–4,600 of 17,051 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Speed Kit | Broken Access Control |
≤ 2.0.2 |
CVE-2026-22487 |
Patchstack | |
| 5.3 Medium | Dashboard Welcome for Beaver Builder | Broken Access Control No login needed |
≤ 1.0.8 |
CVE-2026-22488 |
Patchstack | |
| 4.3 Medium | Image Slider Slideshow | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 1.8 |
CVE-2026-22489 |
Patchstack | |
| 5.4 Medium | Bulk Landing Page Creator for WordPress LPagery | Broken Access Control |
≤ 2.4.9 Fixed in 2.4.10 |
CVE-2026-22490 |
Patchstack | |
| 4.3 Medium | Docket Cache | Broken Access Control |
≤ 24.07.04 Fixed in 24.07.05 |
CVE-2026-22492 |
Patchstack | |
| 5.4 Medium | GA4WP: Google Analytics | Broken Access Control |
≤ 2.10.0 |
CVE-2026-22517 |
Patchstack | |
| 6.5 Medium | X Addons for Elementor | Cross-Site Scripting |
≤ 1.0.23 |
CVE-2026-22518 |
Patchstack | |
| 6.5 Medium | MediaPress | Cross-Site Scripting |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-22519 |
Patchstack | |
| 7.5 High | Handmade Framework | Local File Inclusion |
≤ 3.9 |
CVE-2026-22521 |
Patchstack | |
| 6.5 Medium | Block Slider | Broken Access Control |
≤ 2.2.3 |
CVE-2026-22522 |
Patchstack | |
| 5.3 Medium | Zorka | Broken Access Control No login needed |
≤ 1.5.7 |
CVE-2026-0676 |
Patchstack | |
| 4.3 Medium | Campaign Monitor | Broken Access Control |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2026-0674 |
Patchstack | |
| 5.4 Medium | Easy Media Download | Content Injection CSS Injection |
≤ 1.1.11 Fixed in 1.1.12 |
CVE-2025-69169 |
Patchstack | |
| 7.1 High | Scroll rss excerpt | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.0 |
CVE-2025-68892 |
Patchstack | |
| 7.1 High | WP App Bar | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.5 |
CVE-2025-68891 |
Patchstack | |
| 7.1 High | e-shops | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.4 |
CVE-2025-68890 |
Patchstack | |
| 7.1 High | Pinpoll | Cross-Site Scripting No login needed |
≤ 4.0.0 |
CVE-2025-68889 |
Patchstack | |
| 7.1 High | WP-BusinessDirectory | Cross-Site Scripting No login needed |
≤ 4.0.1 |
CVE-2025-68887 |
Patchstack | |
| 6.5 Medium | Flaming Password Reset | Cross-Site Scripting |
≤ 1.0.3 |
CVE-2025-68875 |
Patchstack | |
| 7.1 High | Visitor Stats Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.5.0 |
CVE-2025-68874 |
Patchstack | |
| 7.1 High | PRIMER by chloédigital | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.25 |
CVE-2025-68873 |
Patchstack | |
| 6.5 Medium | Effect Maker | Cross-Site Scripting |
≤ 1.2.1 |
CVE-2025-68867 |
Patchstack | |
| 8.1 High | Hendon | Local File Inclusion No login needed |
≤ 1.7 Fixed in 1.7 |
CVE-2025-67937 |
Patchstack | |
| 8.1 High | Curly | Local File Inclusion No login needed |
≤ 3.3 Fixed in 3.3 |
CVE-2025-67936 |
Patchstack | |
| 8.1 High | Optimize | Local File Inclusion No login needed |
≤ 2.4 Fixed in 2.4 |
CVE-2025-67935 |
Patchstack | |
| 8.1 High | Wellspring | Local File Inclusion No login needed |
≤ 2.8 Fixed in 2.8 |
CVE-2025-67934 |
Patchstack | |
| 7.1 High | Taskbuilder | Cross-Site Scripting No login needed |
≤ 4.0.9 Fixed in 5.0.0 |
CVE-2025-67933 |
Patchstack | |
| 7.1 High | Listeo Core | Cross-Site Scripting No login needed |
≤ 2.0.19 Fixed in 2.0.19 |
CVE-2025-67932 |
Patchstack | |
| 7.5 High | BulletProof Security | Information Disclosure Sensitive Data Exposure No login needed |
≤ 6.9 Fixed in 7.0 |
CVE-2025-67931 |
Patchstack | |
| 7.1 High | eHive Search | Cross-Site Scripting No login needed |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2025-67930 |
Patchstack | |
| 9.3 Critical | Automotive Listings | SQL Injection No login needed |
≤ 18.6 Fixed in 18.7 |
CVE-2025-67928 |
Patchstack | |
| 7.1 High | Link Whisper Free | Cross-Site Scripting No login needed |
≤ 0.8.8 Fixed in 0.8.9 |
CVE-2025-67927 |
Patchstack | |
| 6.5 Medium | Fluent Support | Broken Access Control |
≤ 1.10.4 Fixed in 1.10.5 |
CVE-2025-67926 |
Patchstack | |
| 7.5 High | Corpkit | Local File Inclusion |
≤ 2.0 Fixed in 2.0.1 |
CVE-2025-67925 |
Patchstack | |
| 9.9 Critical | Corpkit | Arbitrary File Upload |
≤ 2.0 Fixed in 2.0.1 |
CVE-2025-67924 |
Patchstack | |
| 7.1 High | Grand Restaurant | Cross-Site Scripting No login needed |
≤ 7.0.9 Fixed in 7.0.9 |
CVE-2025-67922 |
Patchstack | |
| 8.5 High | Lobo | SQL Injection |
≤ 2.8.6 Fixed in 2.8.6 |
CVE-2025-67921 |
Patchstack | |
| 8.1 High | Neo Ocular | Local File Inclusion No login needed |
≤ 1.2 Fixed in 1.2 |
CVE-2025-67920 |
Patchstack | |
| 6.5 Medium | Woffice Core | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 5.4.30 Fixed in 5.4.31 |
CVE-2025-67919 |
Patchstack | |
| 7.1 High | Woffice | Cross-Site Scripting No login needed |
≤ 5.4.30 Fixed in 5.4.31 |
CVE-2025-67918 |
Patchstack | |
| 6.5 Medium | Traveler | Broken Access Control No login needed |
≤ 3.2.6 Fixed in 3.2.7 |
CVE-2025-67917 |
Patchstack | |
| 7.1 High | Jobify | Cross-Site Scripting No login needed |
≤ 4.3.0 Fixed in 4.3.1 |
CVE-2025-67916 |
Patchstack | |
| 8.8 High | Timetics | Authentication Bypass Broken Authentication |
≤ 1.0.46 Fixed in 1.0.48 |
CVE-2025-67915 |
Patchstack | |
| 7.7 High | VidMov | Path Traversal |
≤ 2.3.8 Fixed in 2.3.9 |
CVE-2025-67914 |
Patchstack | |
| 6.5 Medium | Aruba HiSpeed Cache | Broken Access Control No login needed |
≤ 3.0.3 Fixed in 3.0.3 |
CVE-2025-67913 |
Patchstack | |
| 9.8 Critical | Newsletters | PHP Object Injection No login needed |
≤ 4.11 Fixed in 4.12 |
CVE-2025-67911 |
Patchstack | |
| 9.1 Critical | Contentstudio | Arbitrary File Upload |
≤ 1.3.7 Fixed in 1.4.0 |
CVE-2025-67910 |
Patchstack | |
| 7.1 High | Famous - Responsive Image And Video Grid Gallery | Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2025-27004 |
Patchstack | |
| 7.1 High | CountDown With Image or Video Background | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.5 |
CVE-2025-27002 |
Patchstack | |
| 9.3 Critical | Felan Framework | SQL Injection No login needed |
≤ 1.1.3 |
CVE-2025-23993 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.