WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–45 of 45 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | Business Essentials for Contact Form 7 | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed |
≤ 1.2.1 |
CVE-2026-97661 |
Wordfence | |
| 7.6 High | Business Directory | SQL Injection |
≤ 6.4.27 Fixed in 6.4.28 |
CVE-2026-62097 |
Patchstack | |
| 8.8 High | Consulting - Business, Finance | Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX |
≤ 6.7.16 |
CVE-2026-14805 |
Wordfence | |
| 7.2 High | Listdom: AI-powered Business Directory with Classifieds Ads Listings | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter No login needed |
≤ 5.8.1 |
CVE-2026-19796 |
Wordfence | |
| 8.5 High | WP Project Manager Pro | SQL Injection |
≤ 4.0.1 |
CVE-2026-32478 |
Patchstack | |
| 7.2 High | Online Booking & Scheduling Calendar for WordPress by vcita | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed |
≤ 4.6.0 |
CVE-2026-14433 |
Wordfence | |
| 7.1 High | Business Directory | Cross-Site Scripting No login needed |
≤ 6.4.25 Fixed in 6.4.26 |
CVE-2026-28004 |
Patchstack | |
| 8.0 High | WP Business Intelligence Lite | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification |
≤ 3.2.0 |
CVE-2026-15293 |
Wordfence | |
| 7.1 High | Automotive Car Dealership Business | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 13.3.3 |
CVE-2026-27426 |
Patchstack | |
| 8.1 High | Pearl - Corporate Business | Local File Inclusion Corporate Business theme <= 3.4.10 - Local File Inclusion No login needed |
≤ 3.4.10 |
CVE-2026-27412 |
Patchstack | |
| 8.8 High | Entrepreneur - Booking for Small Businesses | PHP Object Injection Booking for Small Businesses WordPress Theme theme < 3.1.5 - PHP Object Injection |
< 3.1.5 Fixed in 3.1.5 |
CVE-2025-69130 |
Patchstack | |
| 7.5 High | DirectoryPress – Business Directory And Classified Ad Listing | SQL Injection Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' No login needed |
≤ 3.6.26 |
CVE-2026-3489 |
Wordfence | |
| 8.1 High | PJ | Life & Business Coaching | Local File Inclusion No login needed |
≤ 3.0.0 |
CVE-2025-69409 |
Patchstack | |
| 7.1 High | Business Template Blocks for WPBakery (Visual Composer) Page Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.2 |
CVE-2025-69390 |
Patchstack | |
| 7.5 High | Business Directory | SQL Injection Unauthenticated SQL Injection via payment Parameter No login needed |
≤ 6.4.21 |
CVE-2026-2576 |
Wordfence | |
| 7.1 High | WP-BusinessDirectory | Cross-Site Scripting No login needed |
≤ 4.0.1 |
CVE-2025-68887 |
Patchstack | |
| 8.1 High | Brook | Local File Inclusion Agency Business Creative theme <= 2.9.0 - Local File Inclusion No login needed |
≤ 2.9.0 |
CVE-2025-14430 |
Patchstack | |
| 7.1 High | WP Business Hours | Cross-Site Request Forgery No login needed |
≤ 1.4 |
CVE-2025-62934 |
Patchstack | |
| 8.1 High | Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings | Remote Code Execution Authenticated (Subscriber+) Arbitrary File Move |
≤ 8.4.8 |
CVE-2025-10488 |
Wordfence | |
| 7.1 High | Simple Business Directory Pro | Cross-Site Scripting No login needed |
≤ 15.5.1 Fixed in 15.5.2 |
CVE-2025-48162 |
Patchstack | |
| 7.5 High | Maya Business | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 1.2.0 Fixed in 1.3.0 |
CVE-2025-53208 |
Patchstack | |
| 8.1 High | Widget for Google Reviews | Local File Inclusion No login needed |
≤ 1.0.15 Fixed in 1.0.16 |
CVE-2025-53565 |
Patchstack | |
| 7.5 High | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | SQL Injection WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection No login needed |
≤ 2.8.97 |
CVE-2024-13507 |
Wordfence | |
| 7.1 High | Ofiz - WordPress Business Consulting | Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed |
≤ 2.0 |
CVE-2025-31072 |
Patchstack | |
| 7.1 High | Invico - WordPress Consulting Business | Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed |
≤ 1.9 |
CVE-2025-31427 |
Patchstack | |
| 8.1 High | Vizeon - Business Consulting | Local File Inclusion No login needed |
≤ 1.2.1 Fixed in 1.2.1 |
CVE-2025-31064 |
Patchstack | |
| 8.1 High | Enzio - Responsive Business | Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed |
≤ 1.2.6 Fixed in 1.2.6 |
CVE-2025-31912 |
Patchstack | |
| 8.1 High | Kiamo - Responsive Business Service | Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed |
≤ 1.3.3 |
CVE-2025-31633 |
Patchstack | |
| 7.3 High | Create custom forms for WordPress with a smart form plugin for smart businesses | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.4 |
CVE-2025-2801 |
Wordfence | |
| 7.1 High | WP-BusinessDirectory | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2025-32630 |
Patchstack | |
| 8.6 High | WP-BusinessDirectory | Arbitrary File Deletion No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2025-32629 |
Patchstack | |
| 7.5 High | Apptivo Business Site CRM | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 5.3 Fixed in 5.4 |
CVE-2025-31909 |
Patchstack | |
| 8.1 High | Pearl - Corporate Business | Local File Inclusion No login needed |
≤ 3.4.8 Fixed in 3.4.8 |
CVE-2025-26986 |
Patchstack | |
| 8.1 High | Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings | Privilege Escalation Privilege Escalation and Account Takeover via Weak OTP No login needed |
≤ 8.1 |
CVE-2025-1570 |
Wordfence | |
| 7.1 High | Dyn Business Panel | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 1.0.0 |
CVE-2024-13057 |
WPScan | |
| 7.1 High | Dyn Business Panel | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.0.0 |
CVE-2024-13056 |
WPScan | |
| 7.1 High | Dyn Business Panel | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.0.0 |
CVE-2024-13055 |
WPScan | |
| 7.3 High | Quiz Maker Business, Developer, and Agency <= (Multiple Versions) | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed |
≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 |
CVE-2024-10633 |
Wordfence | |
| 7.2 High | Quiz Maker Business, Developer, and Agency <= (Multiple Versions) | Broken Access Control Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting No login needed |
≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 |
CVE-2024-10574 |
Wordfence | |
| 7.5 High | Quiz Maker Business, Developer, and Agency <= (Multiple Versions) | SQL Injection Unauthenticated SQL Injection via id No login needed |
7.0.0 – 8.8.0, 20.0.0 – 21.8.0, 30.0.0 – 31.8.0 |
CVE-2024-10628 |
Wordfence | |
| 7.1 High | Youtube Video Grid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.9 |
CVE-2025-23634 |
Patchstack | |
| 8.8 High | Classified Listing – Classified ads & Business Directory | Broken Access Control Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update |
≤ 3.1.15.1 |
CVE-2024-11194 |
Wordfence | |
| 7.2 High | Business Card | Arbitrary File Upload Admin+ File Upload |
≤ 1.0.0 |
CVE-2024-5807 |
WPScan | |
| 7.4 High | Business Directory | Content Injection Authenticated (Author+) CSV Injection |
≤ 6.4.3 |
CVE-2023-5527 |
Wordfence | |
| 7.1 High | Business Card | Cross-Site Request Forgery Card Edit via CSRF No login needed |
≤ 1.0.0 |
CVE-2024-4531 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.