WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–12 of 12 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Simple Business Directory Pro Plugin simple-business-directory-pro SQL Injection No login needed ≤ 15.9.4 Fixed in 15.9.5 CVE-2026-57707 Patchstack
9.1 Critical Five Star Business Profile and Schema Plugin business-profile Remote Code Execution Arbitrary Code Execution ≤ 2.3.19 CVE-2026-27436 Patchstack
9.1 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter No login needed ≤ 4.0.1 CVE-2026-6070 Wordfence
9.9 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Upload ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-39591 Patchstack
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via claim_business No login needed ≤ 6.0 CVE-2025-5948 Wordfence
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-53580 Patchstack
9.3 Critical WP-BusinessDirectory Plugin wp-businessdirectory SQL Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-24759 Patchstack
9.8 Critical FLAP - Business Theme flap PHP Object Injection Business WordPress Theme <= 1.5 - PHP Object Injection No login needed ≤ 1.5 CVE-2025-31396 Patchstack
9.8 Critical HotStar – Multi-Purpose Business Theme hotstar PHP Object Injection Multi-Purpose Business Theme <= 1.4 - PHP Object Injection No login needed ≤ 1.4 CVE-2025-31069 Patchstack
9.8 Critical The Business Theme nrgbusiness PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-31430 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-31918 Patchstack
9.8 Critical Business Directory Plugin – Easy Listing Directories Plugin business-directory-plugin SQL Injection Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter No login needed ≤ 6.4.2 CVE-2024-4443 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only