WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,801–4,850 of 8,961 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 97 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Paytm Payment Donation Plugin paytm-donation Cross-Site Scripting ≤ 2.3.3 CVE-2025-22640 Patchstack
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-22646 Patchstack
4.3 Medium AIO Performance Profiler, Monitor, Optimize, Compress & Debug Plugin all-in-one-performance-accelerator Broken Access Control ≤ 1.2 Fixed in 1.3 CVE-2025-22647 Patchstack
6.5 Medium Blog, Posts and Category Filter for Elementor Plugin blog-posts-and-category-for-elementor Cross-Site Scripting ≤ 2.0.1 Fixed in 2.1.0 CVE-2025-22648 Patchstack
5.9 Medium WP Project Manager Plugin wedevs-project-manager Cross-Site Scripting ≤ 2.6.22 Fixed in 2.6.23 CVE-2025-22649 Patchstack
6.5 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 2.10.44 Fixed in 2.10.45 CVE-2025-22659 Patchstack
6.5 Medium Include Mastodon Feed Plugin include-mastodon-feed Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2025-22660 Patchstack
4.3 Medium RapidLoad Plugin unusedcss Broken Access Control ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-22665 Patchstack
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
6.5 Medium Awesome Event Booking Plugin awesome-event-booking Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.5 CVE-2025-22668 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
6.5 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-22670 Patchstack
4.3 Medium Disable Elementor Editor Translation Plugin disable-elementor-editor-translation Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-22671 Patchstack
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control ≤ 5.3.5 Fixed in 5.4.0 CVE-2025-22673 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
5.4 Medium Envo Multipurpose Theme envo-multipurpose Broken Access Control ≤ 1.1.6 CVE-2025-22770 Patchstack
6.5 Medium Power Mag Plugin power-mag Cross-Site Scripting ≤ 1.1.5 CVE-2025-22816 Patchstack
6.5 Medium ARPrice Plugin arprice Cross-Site Scripting ≤ 4.1.3 CVE-2025-26731 Patchstack
6.5 Medium StoreBiz Plugin storebiz Cross-Site Scripting ≤ 1.0.32 CVE-2025-26732 Patchstack
6.5 Medium Hester Plugin hester Cross-Site Scripting ≤ 1.1.10 CVE-2025-26734 Patchstack
6.5 Medium MorningTime Lite Plugin morningtime-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-26736 Patchstack
6.5 Medium City Store Theme city-store Cross-Site Scripting ≤ 1.4.5 CVE-2025-26737 Patchstack
6.5 Medium Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting ≤ 3.1.5 CVE-2025-26738 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30925 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
6.5 Medium Simplebooklet PDF Viewer and Embedder Plugin simplebooklet Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-30922 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-30920 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-30918 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.3 Fixed in 7.2.4 CVE-2025-30909 Patchstack
6.5 Medium SecuPress Free Plugin secupress Cross-Site Scripting ≤ 2.2.5.3 Fixed in 2.2.5.4 CVE-2025-30907 Patchstack
5.9 Medium Chartify Plugin chart-builder Cross-Site Scripting ≤ 3.1.7 Fixed in 3.1.9 CVE-2025-30904 Patchstack
6.5 Medium SyntaxHighlighter Evolved Plugin syntaxhighlighter Cross-Site Scripting ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30903 Patchstack
6.5 Medium Zoho Billing – Embed Payment Form Plugin zoho-subscriptions Cross-Site Scripting Embed Payment Form plugin <= 4.0 - Stored Cross Site Scripting (XSS) ≤ 4.0 Fixed in 4.1 CVE-2025-30900 Patchstack
5.9 Medium User Registration Plugin user-registration Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-30899 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-30898 Patchstack
4.3 Medium Analytify Plugin wp-analytify Broken Access Control Settings Change ≤ 5.5.1 Fixed in 6.0.0 CVE-2025-30897 Patchstack
5.4 Medium WP ERP Plugin erp Broken Access Control ≤ 1.13.4 Fixed in 1.14.0 CVE-2025-30896 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Broken Access Control ≤ 1.79.262 Fixed in 1.79.264 CVE-2025-30894 Patchstack
6.5 Medium LeadConnector Plugin leadconnector Cross-Site Scripting ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-30893 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 4.2.9 Fixed in 4.3.0 CVE-2025-30887 Patchstack
4.7 Medium Bit Form Plugin bit-form Open Redirect No login needed ≤ 2.18.0 Fixed in 2.18.1 CVE-2025-30885 Patchstack
4.7 Medium Bit Integrations Plugin bit-integrations Open Redirect No login needed ≤ 2.4.10 Fixed in 2.5.0 CVE-2025-30884 Patchstack
4.3 Medium Trust.Reviews Plugin fb-reviews-widget Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2025-30883 Patchstack
4.3 Medium Big Store Plugin big-store Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-30881 Patchstack
4.3 Medium Specific Content For Mobile Plugin specific-content-for-mobile Broken Access Control ≤ 0.5.3 Fixed in 0.5.4 CVE-2025-30874 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 11.0.2 Fixed in 11.1 CVE-2025-30873 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only