WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,701–4,750 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 95 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Nearby Now Reviews Plugin nearby-now-reviews Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 5.2 CVE-2025-13853 Wordfence
6.4 Medium Entry Views Plugin entry-views Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.0 CVE-2025-13729 Wordfence
6.4 Medium AMP for WP Plugin accelerated-mobile-pages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.10 CVE-2026-0627 Wordfence
4.3 Medium WP Table Builder Plugin wp-table-builder Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation ≤ 2.0.19 CVE-2025-13753 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion ≤ 3.9.2 CVE-2025-13935 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass ≤ 3.9.3 CVE-2025-13934 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification ≤ 3.9.3 CVE-2025-13628 Wordfence
5.3 Medium Booking Calendar Plugin booking Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 10.14.10 CVE-2025-14146 Wordfence
5.3 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 2.1.15 CVE-2025-14574 Wordfence
6.4 Medium IndieWeb Plugin indieweb Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Telephone' Parameter ≤ 4.0.5 CVE-2025-14893 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
5.4 Medium Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories Plugin post-expirator Broken Access Control Missing Authorization to Authenticated (Contributor+) Workflow Manipulation ≤ 4.9.3 CVE-2025-14718 Wordfence
6.4 Medium WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Plugin wp-google-street-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpgsv_map' Shortcode ≤ 1.1.8 CVE-2026-0563 Wordfence
5.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export ≤ 1.49.1 CVE-2025-14782 Wordfence
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
6.5 Medium BetterDocs Plugin betterdocs Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 4.3.3 CVE-2025-14980 Wordfence
6.8 Medium Nex-Forms Express WP Form Builder Plugin Cross-Site Scripting Authenticated Stored XSS < 9.1.8 Fixed in 9.1.8 CVE-2025-14803 WPScan
4.3 Medium Clearfy Plugin clearfy Cross-Site Request Forgery Cross-Site Request Forgery to Update Notification Tampering No login needed ≤ 2.4.0 CVE-2025-13749 Wordfence
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.7.17 CVE-2025-14886 Wordfence
5.3 Medium Re Gallery Plugin regallery Broken Access Control No login needed ≤ 1.18.9 Fixed in 1.18.10 CVE-2026-22486 Patchstack
4.3 Medium Speed Kit Plugin baqend Broken Access Control ≤ 2.0.2 CVE-2026-22487 Patchstack
5.3 Medium Dashboard Welcome for Beaver Builder Plugin dashboard-welcome-for-beaver-builder Broken Access Control No login needed ≤ 1.0.8 CVE-2026-22488 Patchstack
4.3 Medium Image Slider Slideshow Plugin image-slider-slideshow Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8 CVE-2026-22489 Patchstack
5.4 Medium Bulk Landing Page Creator for WordPress LPagery Plugin lpagery Broken Access Control ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-22490 Patchstack
4.3 Medium Docket Cache Plugin docket-cache Broken Access Control ≤ 24.07.04 Fixed in 24.07.05 CVE-2026-22492 Patchstack
5.4 Medium GA4WP: Google Analytics Plugin ga-for-wp Broken Access Control ≤ 2.10.0 CVE-2026-22517 Patchstack
6.5 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting ≤ 1.0.23 CVE-2026-22518 Patchstack
6.5 Medium MediaPress Plugin mediapress Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-22519 Patchstack
6.5 Medium Block Slider Plugin block-slider Broken Access Control ≤ 2.2.3 CVE-2026-22522 Patchstack
6.4 Medium Gutenverse Form Plugin gutenverse-form Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.3.2 CVE-2025-14984 Wordfence
5.3 Medium Zorka Theme zorka Broken Access Control No login needed ≤ 1.5.7 CVE-2026-0676 Patchstack
4.3 Medium Campaign Monitor Plugin forms-for-campaign-monitor Broken Access Control ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-0674 Patchstack
5.4 Medium Easy Media Download Plugin easy-media-download Content Injection CSS Injection ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-69169 Patchstack
6.5 Medium Flaming Password Reset Plugin flaming-password-reset Cross-Site Scripting ≤ 1.0.3 CVE-2025-68875 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Cross-Site Scripting ≤ 1.2.1 CVE-2025-68867 Patchstack
6.5 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 1.10.4 Fixed in 1.10.5 CVE-2025-67926 Patchstack
6.5 Medium Woffice Core Plugin woffice-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67919 Patchstack
6.5 Medium Traveler Plugin traveler Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2025-67917 Patchstack
6.5 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control No login needed ≤ 3.0.3 Fixed in 3.0.3 CVE-2025-67913 Patchstack
6.4 Medium nK Themes Helper Plugin nk-themes-helper Server-Side Request Forgery ≤ 1.7.9 CVE-2025-22726 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details ≤ 3.9.3 CVE-2025-13679 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.0.1 CVE-2025-14275 Wordfence
4.3 Medium Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Plugin folders Broken Access Control Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement ≤ 3.1.5 CVE-2025-12640 Wordfence
6.5 Medium WP Cost Estimation Plugin Path Traversal Upload Directory Traversal No login needed < 9.660 Fixed in 9.660 CVE-2019-25295 Wordfence
4.9 Medium External Media Plugin external-media Server-Side Request Forgery ≤ 1.0.36 CVE-2025-49335 Patchstack
6.5 Medium The Plus Addons for Elementor Pro Plugin theplus_elementor_addon Broken Access Control ≤ 6.3.7 Fixed in 6.3.7 CVE-2025-46434 Patchstack
6.4 Medium Advanced Database Cleaner PRO Plugin advanced-database-cleaner-pro Path Traversal Limited .txt Path Traversal ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-46256 Patchstack
4.3 Medium JetEngine Plugin jet-engine Broken Access Control ≤ 3.8.1.1 Fixed in 3.8.1.2 CVE-2025-69333 Patchstack
4.3 Medium Oneline Lite Plugin oneline-lite Broken Access Control ≤ 6.6 Fixed in 6.7 CVE-2025-69344 Patchstack
4.4 Medium Multi-column Tag Map Plugin multi-column-tag-map Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'mctm_css_conditional' Parameter ≤ 17.0.39 CVE-2025-14057 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only