Vendor CVEs
WordPress
All CVEs
36,868 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-39442 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. | ||
| CVE-2025-69189 | Hig | 0.00 | 7.3 | 0.00 | Jun 17, 2026 | Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3. | ||
| CVE-2025-69175 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. | ||
| CVE-2025-69174 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Etude <= 1.6 versions. | ||
| CVE-2025-69170 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions. | ||
| CVE-2025-69166 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. | ||
| CVE-2025-69164 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Skyward <= 1.10 versions. | ||
| CVE-2025-69158 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Granola <= 1.13 versions. | ||
| CVE-2025-69157 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Gamic <= 1.15 versions. | ||
| CVE-2025-69144 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. | ||
| CVE-2025-69140 | Hig | 0.00 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | ||
| CVE-2025-69130 | Hig | 0.00 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. | ||
| CVE-2025-69128 | Hig | 0.00 | 8.6 | 0.00 | Jun 17, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3. | ||
| CVE-2025-69127 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | ||
| CVE-2025-69126 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. | ||
| CVE-2025-69123 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. | ||
| CVE-2025-69120 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. | ||
| CVE-2025-69115 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions. | ||
| CVE-2025-69111 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. | ||
| CVE-2025-69106 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. | ||
| CVE-2025-68524 | Hig | 0.00 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. | ||
| CVE-2025-60236 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. | ||
| CVE-2025-60231 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. | ||
| CVE-2025-60230 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | ||
| CVE-2025-60229 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. | ||
| CVE-2025-59554 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | ||
| CVE-2025-15657 | Med | 0.00 | 5.3 | 0.00 | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. | ||
| CVE-2025-15546 | 0.00 | — | 0.00 | Jun 14, 2026 | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file… | |||
| CVE-2025-7504 | Hig | 0.00 | 7.5 | 0.01 | Jul 12, 2025 | The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known… | ||
| CVE-2024-10222 | Med | 0.00 | 6.4 | 0.00 | Feb 21, 2025 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | ||
| CVE-2024-23825 | Low | 0.00 | 3.0 | 0.01 | Jan 30, 2024 | TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and… | ||
| CVE-2022-0402 | Med | 0.00 | 6.1 | 0.00 | Jan 16, 2024 | The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting.… | ||
| CVE-2023-51700 | Med | 0.00 | 6.4 | 0.01 | Dec 27, 2023 | Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,… | ||
| CVE-2023-48300 | Med | 0.00 | 6.3 | 0.01 | Nov 20, 2023 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping… | ||
| CVE-2023-1979 | Med | 0.00 | 4.9 | 0.00 | May 8, 2023 | The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't… | ||
| CVE-2017-20183 | Low | 0.00 | 3.5 | 0.01 | May 5, 2023 | A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument… | ||
| CVE-2023-30616 | Med | 0.00 | 6.5 | 0.00 | Apr 20, 2023 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to… | ||
| CVE-2017-20177 | Low | 0.00 | 3.5 | 0.01 | Feb 6, 2023 | A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument… | ||
| CVE-2022-4631 | Low | 0.00 | 3.5 | 0.00 | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is… | ||
| CVE-2021-4252 | Low | 0.00 | 3.5 | 0.00 | Dec 18, 2022 | A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated… | ||
| CVE-2022-4604 | Med | 0.00 | 4.3 | 0.00 | Dec 18, 2022 | A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched… | ||
| CVE-2022-4207 | Med | 0.00 | 5.5 | 0.01 | Dec 13, 2022 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2022-3966 | Med | 0.00 | 4.3 | 0.01 | Nov 13, 2022 | A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to… | ||
| CVE-2022-3506 | Med | 0.00 | 5.4 | 0.01 | Oct 14, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | ||
| CVE-2022-2433 | Hig | 0.00 | 7.5 | 0.01 | Sep 6, 2022 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR… | ||
| CVE-2022-29450 | Med | 0.00 | 5.4 | 0.00 | Jun 15, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress. | ||
| CVE-2021-24892 | Hig | 0.00 | 8.8 | 0.02 | Nov 23, 2021 | Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To… | ||
| CVE-2021-24884 | Cri | 0.00 | 9.6 | 0.03 | Oct 25, 2021 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick… | ||
| CVE-2021-24366 | Med | 0.00 | 5.4 | 0.01 | Jun 21, 2021 | The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | ||
| CVE-2020-29171 | Med | 0.00 | 6.1 | 0.01 | Feb 10, 2021 | Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress. |
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- risk 0.00cvss 7.3epss 0.00
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
- risk 0.00cvss 8.6epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
- CVE-2025-15546Jun 14, 2026risk 0.00cvss —epss 0.00
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…
- risk 0.00cvss 7.5epss 0.01
The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known…
- risk 0.00cvss 6.4epss 0.00
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
- risk 0.00cvss 3.0epss 0.01
TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and…
- risk 0.00cvss 6.1epss 0.00
The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting.…
- risk 0.00cvss 6.4epss 0.01
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,…
- risk 0.00cvss 6.3epss 0.01
The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping…
- risk 0.00cvss 4.9epss 0.00
The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't…
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument…
- risk 0.00cvss 6.5epss 0.00
Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to…
- risk 0.00cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument…
- risk 0.00cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…
- risk 0.00cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated…
- risk 0.00cvss 4.3epss 0.00
A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched…
- risk 0.00cvss 5.5epss 0.01
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.00cvss 4.3epss 0.01
A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
- risk 0.00cvss 7.5epss 0.01
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR…
- risk 0.00cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
- risk 0.00cvss 8.8epss 0.02
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To…
- risk 0.00cvss 9.6epss 0.03
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…
- risk 0.00cvss 5.4epss 0.01
The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…
- risk 0.00cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
Page 724 of 738