WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–45 of 45 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
7.6 High Business Directory Plugin business-directory-plugin SQL Injection ≤ 6.4.27 Fixed in 6.4.28 CVE-2026-62097 Patchstack
8.8 High Consulting - Business, Finance Theme Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX ≤ 6.7.16 CVE-2026-14805 Wordfence
7.2 High Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter No login needed ≤ 5.8.1 CVE-2026-19796 Wordfence
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
7.1 High Business Directory Plugin business-directory-plugin Cross-Site Scripting No login needed ≤ 6.4.25 Fixed in 6.4.26 CVE-2026-28004 Patchstack
8.0 High WP Business Intelligence Lite Plugin wp-business-intelligence-lite Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification ≤ 3.2.0 CVE-2026-15293 Wordfence
7.1 High Automotive Car Dealership Business Theme automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.3.3 CVE-2026-27426 Patchstack
8.1 High Pearl - Corporate Business Theme pearl Local File Inclusion Corporate Business theme <= 3.4.10 - Local File Inclusion No login needed ≤ 3.4.10 CVE-2026-27412 Patchstack
8.8 High Entrepreneur - Booking for Small Businesses Theme entrepreneurx PHP Object Injection Booking for Small Businesses WordPress Theme theme < 3.1.5 - PHP Object Injection < 3.1.5 Fixed in 3.1.5 CVE-2025-69130 Patchstack
7.5 High DirectoryPress – Business Directory And Classified Ad Listing Plugin directorypress SQL Injection Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' No login needed ≤ 3.6.26 CVE-2026-3489 Wordfence
8.1 High PJ | Life & Business Coaching Theme pj Local File Inclusion No login needed ≤ 3.0.0 CVE-2025-69409 Patchstack
7.1 High Business Template Blocks for WPBakery (Visual Composer) Page Builder Plugin templates-and-addons-for-wpbakery-page-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-69390 Patchstack
7.5 High Business Directory Plugin business-directory-plugin SQL Injection Unauthenticated SQL Injection via payment Parameter No login needed ≤ 6.4.21 CVE-2026-2576 Wordfence
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-68887 Patchstack
8.1 High Brook Plugin brook Local File Inclusion Agency Business Creative theme <= 2.9.0 - Local File Inclusion No login needed ≤ 2.9.0 CVE-2025-14430 Patchstack
7.1 High WP Business Hours Plugin wp-business-hours Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62934 Patchstack
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Remote Code Execution Authenticated (Subscriber+) Arbitrary File Move ≤ 8.4.8 CVE-2025-10488 Wordfence
7.1 High Simple Business Directory Pro Plugin simple-business-directory-pro Cross-Site Scripting No login needed ≤ 15.5.1 Fixed in 15.5.2 CVE-2025-48162 Patchstack
7.5 High Maya Business Plugin paymaya-checkout-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-53208 Patchstack
8.1 High Widget for Google Reviews Plugin business-reviews-wp Local File Inclusion No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-53565 Patchstack
7.5 High GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory SQL Injection WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection No login needed ≤ 2.8.97 CVE-2024-13507 Wordfence
7.1 High Ofiz - WordPress Business Consulting Plugin ofiz Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31072 Patchstack
7.1 High Invico - WordPress Consulting Business Plugin invico Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-31427 Patchstack
8.1 High Vizeon - Business Consulting Plugin vizeon Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.2.1 CVE-2025-31064 Patchstack
8.1 High Enzio - Responsive Business Plugin enzio Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-31912 Patchstack
8.1 High Kiamo - Responsive Business Service Theme kiamo Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-31633 Patchstack
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32630 Patchstack
8.6 High WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Deletion No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32629 Patchstack
7.5 High Apptivo Business Site CRM Plugin apptivo-business-site Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.3 Fixed in 5.4 CVE-2025-31909 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Privilege Escalation Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 8.1 CVE-2025-1570 Wordfence
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-13057 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13056 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13055 WPScan
7.3 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10633 Wordfence
7.2 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Broken Access Control Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10574 Wordfence
7.5 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin SQL Injection Unauthenticated SQL Injection via id No login needed 7.0.0 – 8.8.0, 20.0.0 – 21.8.0, 30.0.0 – 31.8.0 CVE-2024-10628 Wordfence
7.1 High Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-23634 Patchstack
8.8 High Classified Listing – Classified ads & Business Directory Plugin classified-listing Broken Access Control Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 3.1.15.1 CVE-2024-11194 Wordfence
7.2 High Business Card Plugin Arbitrary File Upload Admin+ File Upload ≤ 1.0.0 CVE-2024-5807 WPScan
7.4 High Business Directory Plugin business-directory-plugin Content Injection Authenticated (Author+) CSV Injection ≤ 6.4.3 CVE-2023-5527 Wordfence
7.1 High Business Card Plugin Cross-Site Request Forgery Card Edit via CSRF No login needed ≤ 1.0.0 CVE-2024-4531 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only