WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,901–4,950 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 99 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Call me Now Plugin call-me-now Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-23745 Patchstack
7.1 High Social Analytics Plugin social-analytics Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2 CVE-2025-23743 Patchstack
7.1 High Theme My Ontraport Smartform Plugin theme-my-ontraport-smartform Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.11 CVE-2025-23717 Patchstack
7.1 High Web Push Plugin web-push Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 CVE-2025-23720 Patchstack
7.1 High Kapost Plugin kapost-byline Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2025-23712 Patchstack
7.1 High Anonymize Links Plugin anonymize-links Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23702 Patchstack
7.1 High Post & Page Notes Plugin post-page-notes Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.1 CVE-2025-23715 Patchstack
7.1 High Flying Twitter Birds Plugin flying-twitter-birds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8 CVE-2025-23710 Patchstack
7.1 High Free MailClient FMC Plugin mailclient Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23703 Patchstack
7.1 High DF Draggable Plugin df-draggable Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.13.2 CVE-2025-23708 Patchstack
7.1 High WP Custom Google Search Plugin wp-custom-google-search Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23698 Patchstack
7.1 High Shabbos and Yom Tov Plugin shabbos-and-yom-tov Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9 CVE-2025-23694 Patchstack
7.1 High Event Countdown Timer Plugin by TechMix Plugin event-countdown-timer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23699 Patchstack
7.1 High Slider for Writers Plugin slider-for-writers Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-23692 Patchstack
7.1 High Book a Place Plugin book-a-place Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.7.1 CVE-2025-23690 Patchstack
7.1 High Import Users to MailChimp Plugin import-users-to-mailchimp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23675 Patchstack
7.1 High Blogger Image Import Plugin blogger-image-import Cross-Site Request Forgery CSRF to Stored XSS No login needed 2.1 CVE-2025-23689 Patchstack
7.1 High HTTP to HTTPS link changer by Eyga.net Plugin https-links-in-content Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.4 CVE-2025-23677 Patchstack
7.1 High Email on Publish Plugin email-on-publish Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-23673 Patchstack
7.1 High Secure CAPTCHA Plugin secure-captcha Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23693 Patchstack
7.1 High Send to Twitter Plugin send-to-twitter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.2 CVE-2025-23691 Patchstack
7.1 High RSV GMaps Plugin rsv-google-maps Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-23665 Patchstack
7.1 High NV Slider Plugin nv-slider Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-23661 Patchstack
7.1 High Auphonic Importer Plugin auphonic-importer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.1 CVE-2025-23649 Patchstack
7.1 High Twitter Post Plugin twitterpost Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-23654 Patchstack
7.1 High Real Seguro Viagem Plugin seguro-viagem Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.0.5 Fixed in 3.0.0 CVE-2025-23664 Patchstack
7.1 High MFPlugin Plugin mfplugin Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-23660 Patchstack
7.1 High WP Panoramio Plugin wp-panoramio Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 1.5.0 CVE-2025-23662 Patchstack
7.1 High MercadoLibre Integration Plugin mercadolibre-integration Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-23659 Patchstack
7.1 High Rename Author Slug Plugin rename-author-slug Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 CVE-2025-23640 Patchstack
7.1 High Contact Form 7 – CCAvenue Add-on Plugin cf7-cc-avenue-add-on Cross-Site Scripting CCAvenue Add-on plugin <= 1.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23623 Patchstack
7.1 High Comment-Emailer Plugin comment-emailer Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2025-23627 Patchstack
7.1 High MDC YouTube Downloader Plugin mdc-youtube-downloader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0 CVE-2025-23639 Patchstack
7.1 High Twitter Shortcode Plugin twitter-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-23618 Patchstack
7.1 High WP Background Tile Plugin wp-background-tile Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23573 Patchstack
7.1 High Word Freshener Plugin word-freshener Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-23577 Patchstack
7.1 High Floatbox Plus Plugin floatbox-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.4 CVE-2025-23617 Patchstack
7.1 High MemeOne Plugin memeone Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.5 CVE-2025-23559 Patchstack
7.1 High GDReseller Plugin gdreseller Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6 CVE-2025-23567 Patchstack
7.1 High Shortcode in Comment Plugin shortcode-in-comment Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-23569 Patchstack
7.1 High LH Login Page Plugin lh-login-page Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.14 CVE-2025-23547 Patchstack
7.1 High Captchelfie – Captcha by Selfie Plugin captchelfie-captcha-by-selfie Cross-Site Scripting Captcha by Selfie plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 CVE-2025-23620 Patchstack
7.1 High UpDownUpDown Plugin updownupdown-postcomment-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23572 Patchstack
7.1 High Find Your Reps Plugin find-your-reps Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23557 Patchstack
7.1 High Web Testimonials Plugin web-testimonials Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23560 Patchstack
7.1 High Custom Post Plugin custom-post-type-gui Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23566 Patchstack
8.8 High DD Roles Plugin dd-roles Privilege Escalation ≤ 4.1 CVE-2025-23528 Patchstack
8.8 High MyAnime Widget Plugin myanime-widget Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0 CVE-2025-23532 Patchstack
7.1 High Geotagged Media Plugin geotagged-media Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.0 CVE-2025-23558 Patchstack
7.1 High add custom google tag manager Plugin add-custom-google-tag-manager Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2025-23537 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only