WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,901–4,950 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 99 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium GDPR Tools Plugin gdpr-tools Cross-Site Scripting ≤ 1.0.2 CVE-2025-26537 Patchstack
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.7 CVE-2025-1312 Wordfence
6.4 Medium Zapier Plugin zapier Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user Function ≤ 1.5.1 CVE-2024-13411 Wordfence
6.5 Medium Jobs Plugin job-postings Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 2.7.11 CVE-2025-1310 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.19.0 CVE-2025-1784 Wordfence
6.5 Medium Gallery for Social Photo Plugin feed-instagram-lite Cross-Site Scripting ≤ 1.0.0.35 Fixed in 1.0.0.37 CVE-2025-26742 Patchstack
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11273 WPScan
6.1 Medium Contact Form & SMTP Plugin for WordPress by PirateForms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-11272 WPScan
5.9 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.11 Fixed in 2.7.11 CVE-2024-10105 WPScan
5.9 Medium wA11y – The Web Accessibility Toolbox Plugin wa11y Cross-Site Scripting The Web Accessibility Toolbox plugin <= 1.0.3 - Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2025-30623 Patchstack
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack
6.5 Medium WP Social Widget Plugin wp-social-widget Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-30610 Patchstack
5.3 Medium AppExperts Plugin appexperts Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.5 CVE-2025-30609 Patchstack
5.9 Medium Easy Page Transition Plugin easy-page-transition Cross-Site Scripting ≤ 1.0.1 CVE-2025-30606 Patchstack
4.3 Medium sourceplay-navermap Plugin sourceplay-navermap Broken Access Control ≤ 0.0.2 CVE-2025-30605 Patchstack
4.3 Medium Flipdish Ordering System Plugin flipdish-ordering-system Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.5.2 CVE-2025-30601 Patchstack
5.9 Medium WP Hotjar Plugin wp-hotjar Cross-Site Scripting ≤ 0.0.3 CVE-2025-30600 Patchstack
5.9 Medium WP Parallax Content Slider Plugin wp-parallax-content-slider Cross-Site Scripting ≤ 0.9.8 CVE-2025-30599 Patchstack
4.3 Medium OSS Upload Plugin oss-upload Cross-Site Request Forgery WordPress OSS Upload plugin <= 4.8.9 Cross Site Request Forgery (CSRF) No login needed ≤ 4.8.9 CVE-2025-30598 Patchstack
6.5 Medium IG Shortcodes Plugin ig-shortcodes Cross-Site Scripting WordPress IG Shortcodes plugin <= 3.1 Cross Site Scripting (XSS) ≤ 3.1 CVE-2025-30597 Patchstack
6.5 Medium include-file Plugin include-file Cross-Site Scripting WordPress include-file plugin <= 1 Cross Site Scripting (XSS) ≤ 1 CVE-2025-30595 Patchstack
6.5 Medium Include URL Plugin include-url Cross-Site Scripting WordPress Include URL plugin <= 0.3.5 Cross Site Scripting (XSS) ≤ 0.3.5 CVE-2025-30593 Patchstack
5.3 Medium Advanced Dewplayer Plugin advanced-dewplayer Broken Access Control plugin <= 1.6 Broken Access Control No login needed ≤ 1.6 CVE-2025-30592 Patchstack
5.3 Medium Music Press Pro Plugin music-press-pro Broken Access Control WordPress Music Press Pro plugin <= 1.4.6 Broken Access Control No login needed ≤ 1.4.6 CVE-2025-30591 Patchstack
4.3 Medium Generate Post Thumbnails Plugin generate-post-thumbnails Cross-Site Request Forgery No login needed ≤ 0.8 CVE-2025-30585 Patchstack
5.3 Medium Top Bar Plugin ultimate-bar Broken Access Control No login needed ≤ 3.3 CVE-2025-30581 Patchstack
4.3 Medium Hacklog Remote Image Autosave Plugin hacklog-remote-image-autosave Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-30576 Patchstack
5.9 Medium Login Redirect Plugin login-redirect Cross-Site Scripting WordPress Login Redirect plugin <= - 1.0.5 Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2025-30575 Patchstack
5.9 Medium Mobile Navigation Plugin mobile-navigation Cross-Site Scripting WordPress Mobile Navigation plugin <= - 1.5 Cross Site Scripting (XSS) ≤ 1.5 CVE-2025-30574 Patchstack
5.9 Medium My Default Post Content Plugin my-default-post-content Cross-Site Scripting WordPress My Default Post Content plugin <= - 0.7.3 Cross Site Scripting (XSS) ≤ 0.7.3 CVE-2025-30573 Patchstack
4.3 Medium Super Static Cache Plugin super-static-cache Cross-Site Request Forgery No login needed ≤ 3.3.5 CVE-2025-30568 Patchstack
6.5 Medium Clink Plugin clink Cross-Site Scripting ≤ 1.2.2 CVE-2025-30566 Patchstack
4.3 Medium Easy 301 Redirects Plugin odihost-easy-redirect-301 Cross-Site Request Forgery No login needed ≤ 1.33 CVE-2025-30557 Patchstack
4.3 Medium Fix Rss Feeds Plugin fix-rss-feed Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-30556 Patchstack
6.5 Medium GMO Font Agent Plugin gmo-font-agent Cross-Site Scripting ≤ 1.6 CVE-2025-30553 Patchstack
6.5 Medium Pretty file links Plugin pretty-file-links Cross-Site Scripting ≤ 0.9 CVE-2025-30551 Patchstack
4.3 Medium Yummly Rich Recipes Plugin yummly-rich-recipes Cross-Site Request Forgery No login needed ≤ 4.2 CVE-2025-30549 Patchstack
4.3 Medium Cackle Plugin cackle Cross-Site Request Forgery No login needed ≤ 4.33 CVE-2025-30546 Patchstack
5.9 Medium issuuPress Plugin issuupress Cross-Site Scripting ≤ 1.3.2 CVE-2025-30545 Patchstack
4.3 Medium Menu Duplicator Plugin copy-menu Broken Access Control ≤ 1.0 CVE-2025-30543 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack
5.9 Medium AvaiBook Plugin avaibook Cross-Site Scripting ≤ 1.2 CVE-2025-30540 Patchstack
5.9 Medium BMo Expo Plugin bmo-expo Cross-Site Scripting ≤ 1.0.15 CVE-2025-30539 Patchstack
4.3 Medium Simple Optimizer Plugin simple-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-30538 Patchstack
5.9 Medium Upload Quota per User Plugin upload-quota-per-user Cross-Site Scripting ≤ 1.3 CVE-2025-30537 Patchstack
5.9 Medium Beautiful Link Preview Plugin beautiful-link-preview Cross-Site Scripting ≤ 1.5.0 CVE-2025-30536 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
4.3 Medium Image Captcha Plugin image-captcha Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-30534 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only