Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

3 vulnerability records

MediumCVE-2026-0867

Essential Widgets <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes

Essential Widgets: Currently marked unpatched

Affected versions: *-3.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortcodes in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially fixed in version 3.0.

Essential Widgets

Affected versions: *-3.0

Patched versions: 3.0.1

Researcher credit: Muhammad Yudha - DJ

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 4, 2026
CVSS
6.4
MediumCVE-2025-67543

Essential Widgets <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Essential Widgets: Currently marked unpatched

Affected versions: *-2.2.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Essential Widgets

Affected versions: *-2.2.2

Patched versions: 2.3

Researcher credit: Mdr

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 26, 2025
CVSS
6.4
MediumCVE-2021-24752

CatchThemes Plugins (Various Versions) - Missing Authorization

Header Enhancement: Currently marked unpatchedGenerate Child Theme: Currently marked unpatchedSocial Gallery and Widget: Currently marked unpatchedCatch Import Export: Currently marked unpatchedCatch Under Construction: Currently marked unpatchedCatch Duplicate Switcher: Currently marked unpatchedCatch IDs: Currently marked unpatchedCatch Sticky Menu: Currently marked unpatchedEssential Widgets: Currently marked unpatchedCatch Infinite Scroll: Currently marked unpatchedTo Top: Currently marked unpatchedCatch Themes Demo Import: Currently marked unpatchedCatch Breadcrumb: Currently marked unpatchedEssential Content Types: Currently marked unpatchedCatch Gallery: Currently marked unpatchedCatch Web Tools: Currently marked unpatchedCatch Scroll Progress Bar: Currently marked unpatched

Affected versions: [*, 1.5); [*, 1.6); [*, 2.3); [*, 1.9); [*, 1.4); [*, 1.6); [*, 2.4); [*, 1.7)

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before 1.7, Catch Scroll Progress Bar WordPress plugin before 1.6, Social Gallery and Widget WordPress plugin before 2.3, Catch Infinite Scroll WordPress plugin before 1.9, Catch Import Export WordPress plugin before 1.9, Catch Gallery WordPress plugin before 1.7, Catch Duplicate Switcher WordPress plugin before 1.6, Catch Breadcrumb WordPress plugin before 1.7, Catch IDs WordPress plugin before 2.4's configurations.

Header Enhancement

Affected versions: [*, 1.5)

Patched versions: 1.5

Generate Child Theme

Affected versions: [*, 1.6)

Patched versions: 1.6

Social Gallery and Widget

Affected versions: [*, 2.3)

Patched versions: 2.3

Catch Import Export

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Under Construction

Affected versions: [*, 1.4)

Patched versions: 1.4

Catch Duplicate Switcher

Affected versions: [*, 1.6)

Patched versions: 1.6

Catch IDs

Affected versions: [*, 2.4)

Patched versions: 2.4

Catch Sticky Menu

Affected versions: [*, 1.7)

Patched versions: 1.7

Essential Widgets

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Infinite Scroll

Affected versions: [*, 1.9)

Patched versions: 1.9

To Top

Affected versions: [*, 2.3)

Patched versions: 2.3

Catch Themes Demo Import

Affected versions: [*, 1.6)

Patched versions: 1.6

Catch Breadcrumb

Affected versions: [*, 1.7)

Patched versions: 1.7

Essential Content Types

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Gallery

Affected versions: [*, 1.7)

Patched versions: 1.7

Catch Web Tools

Affected versions: [*, 2.7)

Patched versions: 2.7

Catch Scroll Progress Bar

Affected versions: [*, 1.6)

Patched versions: 1.6

Researcher credit: apple502j

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 20, 2021
CVSS
5.4

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.