WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 4,751–4,800 of 6,499 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | WP Front-end login and register | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.0 |
CVE-2025-23540 |
Patchstack | |
| 7.1 High | Blue Wrench Video Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.0 |
CVE-2025-23809 |
Patchstack | |
| 7.1 High | WP Download Codes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.4 |
CVE-2025-23882 |
Patchstack | |
| 7.1 High | Flexible Blogtitle | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.1 |
CVE-2025-23846 |
Patchstack | |
| 7.1 High | Contact Form 7 Round Robin Lead Distribution | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.1 |
CVE-2025-23812 |
Patchstack | |
| 7.1 High | InFunding | Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-23768 |
Patchstack | |
| 7.1 High | CMC MIGRATE | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.0.3 |
CVE-2025-23746 |
Patchstack | |
| 7.1 High | Formatted post | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.01 |
CVE-2025-23709 |
Patchstack | |
| 7.1 High | ReadMe Creator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-23643 |
Patchstack | |
| 7.1 High | WP IMAP Auth | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.1 |
CVE-2025-23506 |
Patchstack | |
| 7.1 High | History timeline | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.7.2 |
CVE-2025-23475 |
Patchstack | |
| 7.1 High | FWD Slider | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-23462 |
Patchstack | |
| 7.1 High | Simple shortcode buttons | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.2 |
CVE-2025-23449 |
Patchstack | |
| 7.1 High | Mapbox for WP Advanced | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-22772 |
Patchstack | |
| 7.1 High | a Gateway for Pasargad Bank on WooCommerce | Cross-Site Scripting No login needed |
≤ 2.5.2 |
CVE-2025-23966 |
Patchstack | |
| 7.1 High | Good Old Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.2 |
CVE-2025-23959 |
Patchstack | |
| 8.1 High | Improved Sale Badges – Free Version | Local File Inclusion Free Version Plugin <= 1.0.1 - Local File Inclusion No login needed |
≤ 1.0.1 |
CVE-2025-23949 |
Patchstack | |
| 8.1 High | Background animation blocks | Local File Inclusion No login needed |
≤ 2.1.5 |
CVE-2025-23948 |
Patchstack | |
| 8.8 High | WOOEXIM | PHP Object Injection |
≤ 5.0.0 |
CVE-2025-23944 |
Patchstack | |
| 7.5 High | Image Gallery Box by CRUDLab | Local File Inclusion |
≤ 1.0.3 |
CVE-2025-23938 |
Patchstack | |
| 8.5 High | Menus Plus+ | SQL Injection |
≤ 1.9.6 |
CVE-2025-23910 |
Patchstack | |
| 7.1 High | WP Block Pack | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.6 |
CVE-2025-23874 |
Patchstack | |
| 7.1 High | WordPress File Search | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-23867 |
Patchstack | |
| 7.1 High | EU DSGVO Helper | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.6.1 |
CVE-2025-23866 |
Patchstack | |
| 7.1 High | WP2APP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.2 |
CVE-2025-23811 |
Patchstack | |
| 7.1 High | Ultimate Subscribe | Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3 |
CVE-2025-23806 |
Patchstack | |
| 7.1 High | Snippy | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 1.4.1 |
CVE-2025-23803 |
Patchstack | |
| 7.1 High | Mass Messaging in BuddyPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.1 |
CVE-2025-23798 |
Patchstack | |
| 7.6 High | Contact Form 7 Round Robin Lead Distribution | SQL Injection |
≤ 1.2.1 |
CVE-2025-23784 |
Patchstack | |
| 7.5 High | WM Options Import Export | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.0.1 |
CVE-2025-23781 |
Patchstack | |
| 7.5 High | WPDB to Sql | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.2 |
CVE-2025-23774 |
Patchstack | |
| 7.1 High | Fast Tube | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.3.1 |
CVE-2025-23770 |
Patchstack | |
| 7.1 High | Content Mirror | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-23769 |
Patchstack | |
| 7.1 High | Pootle button | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.0 |
CVE-2025-23758 |
Patchstack | |
| 7.1 High | Easy Filtering | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.0 |
CVE-2025-23732 |
Patchstack | |
| 7.1 High | Jet Skinner for BuddyPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.5 |
CVE-2025-23706 |
Patchstack | |
| 7.1 High | Lime Developer Login | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.0 |
CVE-2025-23701 |
Patchstack | |
| 7.1 High | yCyclista | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.3 |
CVE-2025-23700 |
Patchstack | |
| 7.1 High | Podčlánková inzerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.4.0 |
CVE-2025-23697 |
Patchstack | |
| 7.1 High | Staging CDN | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-23696 |
Patchstack | |
| 7.1 High | CtyGrid Hyp3rL0cal Search | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.1.1.1 |
CVE-2025-23695 |
Patchstack | |
| 7.1 High | Admin Menu Organizer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-23686 |
Patchstack | |
| 7.1 High | MACME | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-23683 |
Patchstack | |
| 7.1 High | Preloader Quotes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-23682 |
Patchstack | |
| 7.1 High | REDIRECTION PLUS | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.0 |
CVE-2025-23681 |
Patchstack | |
| 7.1 High | FP RSS Category Excluder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-23679 |
Patchstack | |
| 7.1 High | LocalGrid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-23678 |
Patchstack | |
| 7.1 High | LH Email | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.12 |
CVE-2025-23676 |
Patchstack | |
| 7.1 High | Bit.ly linker | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-23674 |
Patchstack | |
| 7.1 High | Instant Appointment | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-23672 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.