WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,601–4,650 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 93 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP Mailster Plugin wp-mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.17.0 Fixed in 1.8.18.0 CVE-2025-24598 Patchstack
7.1 High Find Content IDs Plugin find-content-ids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23645 Patchstack
8.5 High Traveler Code Plugin traveler-code SQL Injection Subscriber+ Arbitrary SQL Execution ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-22700 Patchstack
8.8 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager PHP Object Injection ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-24661 Patchstack
7.1 High Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23984 Patchstack
7.1 High Catalog Importer, Scraper & Crawler Plugin intelligent-importer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.3 Fixed in 5.1.4 CVE-2025-22775 Patchstack
7.1 High WordPress Signature Plugin wordpress-signature Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-22704 Patchstack
7.1 High Forge – Front-End Page Builder Plugin forge Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-22703 Patchstack
7.6 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 25.1.0 Fixed in 25.1.2 CVE-2025-22693 Patchstack
7.6 High WP Travel Plugin wp-travel SQL Injection ≤ 10.1.3 Fixed in 10.1.4 CVE-2025-22691 Patchstack
7.1 High DigiTimber cPanel Integration Plugin digitimber-cpanel-integration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.6 Fixed in 1.4.8 CVE-2025-22690 Patchstack
7.1 High Unlimited Page Sidebars Plugin unlimited-page-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.6 Fixed in 0.2.7 CVE-2025-22688 Patchstack
7.1 High Tags to Keywords Plugin tags-to-meta-keywords Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-22685 Patchstack
7.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting No login needed ≤ 5.0.0 Fixed in 5.1.0 CVE-2025-22684 Patchstack
7.1 High Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-22682 Patchstack
7.1 High Job Board Manager Plugin job-board-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.61 CVE-2025-22679 Patchstack
7.5 High Admin and Site Enhancements (ASE) Pro Plugin admin-site-enhancements-pro Privilege Escalation ≤ 7.6.2.1 Fixed in 7.6.3 CVE-2024-43333 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.24 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.24 Fixed in 2.7.7.25 CVE-2025-24707 Patchstack
7.1 High Media Downloader Plugin media-downloader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.7.5 Fixed in 0.4.7.6 CVE-2025-24684 Patchstack
7.1 High Custom WP Store Locator Plugin custom-store-locator Cross-Site Scripting No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-24676 Patchstack
7.1 High Simple Membership Custom Messages Plugin simple-membership-custom-messages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-24660 Patchstack
7.1 High Realtyna Provisioning Plugin realtyna-provisioning Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-24656 Patchstack
7.1 High XML for Avito Plugin xml-for-avito Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24646 Patchstack
7.1 High BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-24631 Patchstack
7.1 High Sikshya LMS Plugin sikshya Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.21 Fixed in 0.0.22 CVE-2025-24630 Patchstack
7.1 High Import Excel to Gravity Forms Plugin gf-excel-import Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.18 Fixed in 1.18.1 CVE-2025-24629 Patchstack
7.1 High AIO Shortcodes Plugin aio-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-24620 Patchstack
7.5 High WOLF Plugin bulk-editor Path Traversal ≤ 1.0.8.5 Fixed in 1.0.8.6 CVE-2025-24605 Patchstack
7.1 High Landing Page Cat Plugin landing-page-cat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-24576 Patchstack
7.1 High PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-24574 Patchstack
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Arbitrary File Read No login needed ≤ 1.7.5 Fixed in 2.0.1 CVE-2025-24569 Patchstack
7.1 High WP Mailster Plugin wp-mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.15.0 Fixed in 1.8.16.0 CVE-2025-24559 Patchstack
7.1 High PlainInventory Plugin z-inventory-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-24557 Patchstack
7.5 High MooWoodle Plugin moowoodle Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-24556 Patchstack
7.1 High BSK Forms Validation Plugin bsk-gravity-forms-custom-validation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 Fixed in 1.8 CVE-2025-24545 Patchstack
7.1 High Bitcoin and Altcoin Wallets Plugin wallets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3.1 Fixed in 6.3.2 CVE-2025-24544 Patchstack
7.1 High DK White Label Plugin dk-white-label Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-24541 Patchstack
7.1 High ThriveDesk Plugin thrivedesk Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24536 Patchstack
7.1 High Lockets Plugin lockets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.999 CVE-2025-23923 Patchstack
7.1 High ApplicantPro Plugin applicantpro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-23920 Patchstack
7.5 High WP Cloud Plugin cloud Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-23819 Patchstack
7.1 High .TUBE Video Curator Plugin tube-video-curator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.9 CVE-2025-23799 Patchstack
7.1 High PAFacile Plugin pafacile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2025-23755 Patchstack
7.1 High RomanCart Plugin romancart-on-wordpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.2 CVE-2025-23685 Patchstack
7.1 High WordPress Additional Logins Plugin wp-additional-logins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23614 Patchstack
7.1 High eMarksheet Plugin emarksheet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-23599 Patchstack
7.1 High Google Map With Fancybox Plugin location-piker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-23594 Patchstack
7.1 High EmailPress Plugin emailpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23593 Patchstack
7.1 High blu Logistics Plugin blu-logistics Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23591 Patchstack
7.1 High Dezdy Plugin dezdy-mcommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23590 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only