WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,801–4,850 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 97 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Content Planner Plugin content-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23631 Patchstack
7.1 High Cyber Slider Plugin cyber-new-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23630 Patchstack
7.1 High Unique UX Plugin unique-ux Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.2 CVE-2025-23625 Patchstack
7.1 High WH Cache & Security Plugin wh-cache-and-security Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-23611 Patchstack
7.1 High Ultimate Events Plugin ultimate-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23610 Patchstack
7.1 High Tagesteller Plugin tagesteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v.1.1 CVE-2025-23609 Patchstack
7.1 High CAMOO SMS Plugin camoo-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.1 CVE-2025-23607 Patchstack
7.1 High Calendi Plugin calendi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-23606 Patchstack
7.1 High Call To Action Popup Plugin call-to-action-popup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23605 Patchstack
7.1 High Rezdy Reloaded Plugin reloaded-rezdy Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23604 Patchstack
7.1 High Group category creator Plugin group-category-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0.3 CVE-2025-23603 Patchstack
7.1 High EELV Newsletter Plugin eelv-newsletter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.2 CVE-2025-23602 Patchstack
7.1 High Tab My Content Plugin tab-my-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23601 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
7.1 High dForms Plugin dforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23592 Patchstack
7.1 High ContentOptin Lite Plugin contentoptin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23589 Patchstack
7.1 High Explara Membership Plugin explara-membership Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23583 Patchstack
7.1 High Custom CSS Addons Plugin css-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23578 Patchstack
7.5 High XLSXviewer Plugin xlsx-viewer Arbitrary File Deletion No login needed ≤ 2.1.1 CVE-2025-23562 Patchstack
7.1 High Responsivity Plugin responsivity Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.6 CVE-2025-23548 Patchstack
7.1 High REAL WordPress Sidebar Plugin drag-and-drop-custom-sidebar Cross-Site Scripting No login needed ≤ 0.1 CVE-2025-23535 Patchstack
7.5 High Team 118GROUP Agent Plugin team-118group-agent Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.6.0 CVE-2025-23512 Patchstack
7.1 High HyperComments Plugin comments-with-hypercommentscom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.6 CVE-2025-23509 Patchstack
7.1 High Blrt WP Embed Plugin blrt-wp-embed Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.9 CVE-2025-23507 Patchstack
7.1 High Customizable Captcha and Contact Us Plugin customizable-captcha-and-contact-us-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23503 Patchstack
7.1 High Simple Custom post type custom field Plugin simple-content-construction-kit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23500 Patchstack
7.1 High Translation.Pro Plugin translation-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23498 Patchstack
7.1 High WooCommerce Order Search Plugin woocommerce-order-searching Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-23495 Patchstack
7.1 High Estatebud – Properties & Listings Plugin estatebud-properties-listings Cross-Site Request Forgery Properties & Listings plugin <= 5.5.0 - CSRF to Settings Update & Stored XSS No login needed ≤ 5.5.0 CVE-2025-23994 Patchstack
7.1 High BizLibrary Plugin bizlibrary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23580 Patchstack
7.1 High SexBundle Plugin sexbundle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23551 Patchstack
7.1 High WP-Announcements Plugin wp-announcements Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-23489 Patchstack
8.2 High Realty Workstation Plugin realty-workstation Broken Access Control No login needed ≤ 1.0.45 CVE-2025-23477 Patchstack
7.1 High Social2Blog Plugin social2blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.990 CVE-2025-23461 Patchstack
7.1 High Nature FlipBook Plugin vertical-diamond-flipbook-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2025-23454 Patchstack
7.1 High PPO Call To Actions Plugin ppo-call-to-actions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.3 CVE-2025-24001 Patchstack
7.1 High UltraLight Plugin the-ultralight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23998 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.18 Fixed in 3.6.19 CVE-2025-22733 Patchstack
7.1 High VikAppointments Services Booking Calendar Plugin vikappointments Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-22719 Patchstack
7.5 High My Tickets Plugin my-tickets Broken Access Control No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2025-22717 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-22716 Patchstack
7.1 High Image Source Control Plugin image-source-control-isc Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.29.0 Fixed in 2.29.1 CVE-2025-22711 Patchstack
7.6 High Smart Manager Plugin smart-manager-for-wp-e-commerce SQL Injection ≤ 8.52.0 Fixed in 8.53.0 CVE-2025-22710 Patchstack
7.1 High Verge3D Plugin verge3d Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-22709 Patchstack
7.1 High Social Pug: Author Box Plugin social-pug-author-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-22706 Patchstack
7.1 High Brizy Pro Plugin brizy-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2025-22763 Patchstack
7.1 High WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-22735 Patchstack
7.1 High Private Messages for UserPro Plugin userpro-messaging Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.10.0 CVE-2025-22322 Patchstack
7.5 High Standard Box Sizes – for WooCommerce Plugin standard-box-sizes Broken Access Control No login needed ≤ 1.6.13 Fixed in 1.6.14 CVE-2025-22318 Patchstack
7.5 High Private Messages for UserPro Plugin userpro-messaging Local File Inclusion No login needed ≤ 4.10.0 CVE-2025-22311 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only