WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,551–4,600 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 92 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Settings Change No login needed ≤ 5.0.37.decaf Fixed in 5.0.53.decaf CVE-2025-68007 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
6.5 Medium Shown Connector Plugin shown-connector Broken Access Control Settings Change No login needed ≤ 1.2.10 CVE-2025-68003 Patchstack
6.4 Medium WPO365 Plugin wpo365-login Server-Side Request Forgery ≤ 40.0 Fixed in 40.1 CVE-2025-67961 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2025-67942 Patchstack
6.5 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.2 Fixed in 3.5.6.3 CVE-2025-67939 Patchstack
4.3 Medium WP SEO Search Plugin wp-seo-search Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-67626 Patchstack
5.4 Medium Crumber Plugin crumber-elementor Broken Access Control ≤ 1.0.10 CVE-2025-66143 Patchstack
5.4 Medium Comparimager for Elementor Plugin comparimager-elementor Broken Access Control ≤ 1.0.1 CVE-2025-66142 Patchstack
5.4 Medium Scroller Plugin scroller Broken Access Control ≤ 2.0.2 CVE-2025-66141 Patchstack
5.4 Medium Uper for Elementor Plugin uper-elementor Broken Access Control ≤ 1.0.5 CVE-2025-66140 Patchstack
5.4 Medium Audier For Elementor Plugin audier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66139 Patchstack
5.4 Medium Motionger for Elementor Plugin motionger-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66138 Patchstack
5.4 Medium Searcher for Elementor Plugin searcher-elementor Broken Access Control ≤ 1.0.3 CVE-2025-66137 Patchstack
5.4 Medium Carter for Elementor Plugin carter-elementor Broken Access Control ≤ 1.0.2 CVE-2025-66136 Patchstack
5.4 Medium Imager for Elementor Plugin imager-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66135 Patchstack
4.9 Medium ANAC XML Viewer Plugin anac-xml-viewer Server-Side Request Forgery ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-64252 Patchstack
4.3 Medium REHub Framework Plugin rehub-framework Information Disclosure Sensitive Data Exposure ≤ 19.9.9.4 Fixed in 19.9.9.4 CVE-2025-63051 Patchstack
6.5 Medium Grand Restaurant Theme Elements for Elementor Plugin grandrestaurant-elementor Cross-Site Scripting ≤ 2.1.1 CVE-2025-63026 Patchstack
5.3 Medium Cookies and Content Security Policy Plugin cookies-and-content-security-policy Information Disclosure Sensitive Data Exposure No login needed ≤ 2.34 Fixed in 2.35 CVE-2025-63019 Patchstack
4.3 Medium Bard Plugin bard Broken Access Control ≤ 2.229 CVE-2025-63018 Patchstack
5.3 Medium Payment Gateway bKash for WC Plugin woo-payment-bkash Broken Access Control No login needed ≤ 3.1.0 CVE-2025-62754 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack
5.4 Medium WP-CRM System Plugin wp-crm-system Broken Access Control ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-62106 Patchstack
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
6.5 Medium Electron Plugin electron Broken Access Control ≤ 1.8.2 CVE-2025-5805 Patchstack
6.5 Medium xSmart Plugin xsmart Broken Access Control ≤ 1.2.9.4 CVE-2025-54002 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50005 Patchstack
5.4 Medium HomeLancer Plugin homelancer Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-49375 Patchstack
5.9 Medium Pondol BBS Plugin pondol-bbs Cross-Site Scripting ≤ 1.1.8.4 CVE-2025-49336 Patchstack
5.3 Medium WoodMart Theme woodmart Arbitrary Shortcode Execution No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2025-47600 Patchstack
5.9 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting ≤ 3.19.5 Fixed in 3.19.6 CVE-2025-47500 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Request Forgery No login needed ≤ 8.3.13 Fixed in 8.3.14 CVE-2025-31413 Patchstack
5.3 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Broken Access Control Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion No login needed ≤ 1.8.36 CVE-2026-1036 Wordfence
4.3 Medium NotificationX Plugin notificationx Broken Access Control Missing Authorization to Authenticated (Contributor+) Analytics Reset ≤ 3.1.11 CVE-2026-0554 Wordfence
6.4 Medium Head Meta Data Plugin head-meta-data Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta ≤ 20251118 CVE-2026-0608 Wordfence
6.4 Medium FlatPM – Ad Manager, AdSense and Custom Code Plugin flatpm-wp Cross-Site Scripting Ad Manager, AdSense and Custom Code <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Post Meta ≤ 3.2.2 CVE-2026-0690 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Migration Control ≤ 6.15.13 CVE-2025-15043 Wordfence
5.4 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion ≤ 3.9.4 CVE-2026-0548 Wordfence
6.5 Medium Bookingor Plugin bookingor Broken Access Control Subscriber+ Category Deletion ≤ 1.0.12 CVE-2025-12573 WPScan
4.4 Medium WP Hello Bar Plugin wp-hello-bar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'digit_one' and 'digit_two' Parameters ≤ 1.02 CVE-2026-1042 Wordfence
4.4 Medium Viet contact Plugin viet-contact Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'll1', 'll2', 'll3', and 'll4' Parameters ≤ 1.3.2 CVE-2026-1045 Wordfence
5.3 Medium weMail Plugin wemail Information Disclosure Insufficient Authorization via x-wemail-user Header to Sensitive Information Disclosure No login needed ≤ 2.0.7 CVE-2025-14348 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API No login needed ≤ 4.3.2.4 CVE-2025-14798 Wordfence
5.3 Medium Custom Fonts – Host Your Fonts Locally Plugin custom-fonts Broken Access Control Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion No login needed ≤ 2.1.16 CVE-2025-14351 Wordfence
4.3 Medium Newsletter – Send awesome emails from Plugin newsletter Cross-Site Request Forgery Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription No login needed ≤ 9.1.0 CVE-2026-1051 Wordfence
5.3 Medium PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) Plugin peachpay-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 1.119.8 CVE-2025-14978 Wordfence
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management ≤ 3.6.9 CVE-2025-15466 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only