WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Pets Club Theme petclub PHP Object Injection No login needed ≤ 2.3 CVE-2026-22453 Patchstack
9.8 Critical Handyman Theme handyman-services PHP Object Injection No login needed ≤ 1.4.7 CVE-2026-22451 Patchstack
9.8 Critical Grand Wedding Theme grandwedding PHP Object Injection No login needed ≤ 3.1.11 Fixed in 3.1.11 CVE-2026-22417 Patchstack
9.9 Critical Builderall Builder Plugin builderall-cheetah-for-wp Remote Code Execution ≤ 3.0.1 CVE-2026-22390 Patchstack
9.3 Critical Riode Core Plugin riode-core SQL Injection No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2025-69338 Patchstack
9.9 Critical Nutrie Theme nutrie Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68555 Patchstack
9.9 Critical Keenarch Theme keenarch Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68554 Patchstack
9.9 Critical Lendiz Theme lendiz Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68553 Patchstack
9.8 Critical Classter Theme classter PHP Object Injection No login needed ≤ 2.5 CVE-2025-54001 Patchstack
9.3 Critical Download Manager Addons for Elementor Plugin wpdm-elementor SQL Injection No login needed ≤ 1.3.0 Fixed in 2.0.0 CVE-2026-24956 Patchstack
9.8 Critical Applay - Shortcodes Plugin applay-shortcodes PHP Object Injection Shortcodes plugin <= 3.7 - PHP Object Injection No login needed ≤ 3.7 CVE-2026-22384 Patchstack
9.8 Critical Lorem Ipsum | Books & Media Store Theme lorem-ipsum-books-media-store PHP Object Injection No login needed ≤ 1.2.11 CVE-2025-69405 Patchstack
9.8 Critical Extreme Store Theme extremestore PHP Object Injection No login needed ≤ 1.5.10 CVE-2025-69404 Patchstack
9.9 Critical Bravis Addons Plugin bravis-addons Arbitrary File Upload ≤ 1.3.0 CVE-2025-69403 Patchstack
9.8 Critical Themesflat Elementor Plugin themesflat-elementor PHP Object Injection No login needed ≤ 1.0.1 CVE-2025-69382 Patchstack
9.8 Critical SevenHills Theme sevenhills PHP Object Injection No login needed ≤ 1.6.2 CVE-2025-69372 Patchstack
9.8 Critical KindlyCare Theme kindlycare PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-69371 Patchstack
9.8 Critical Capella Theme capella PHP Object Injection No login needed ≤ 2.5.5 CVE-2025-69370 Patchstack
9.3 Critical Emerce Core Plugin emerce-core SQL Injection No login needed ≤ 1.8 CVE-2025-69366 Patchstack
9.3 Critical Uroan Core Plugin uroan-core SQL Injection No login needed ≤ 1.4.4 CVE-2025-69365 Patchstack
9.3 Critical Wolmart Core Plugin wolmart-core SQL Injection No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-69337 Patchstack
9.8 Critical Prestige Theme prestige PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.1 CVE-2025-69329 Patchstack
9.3 Critical Woodly Core Plugin woodly-core SQL Injection No login needed ≤ 1.4 CVE-2025-69310 Patchstack
9.3 Critical Saasplate Core Plugin saasplate-core SQL Injection No login needed ≤ 1.2.8 CVE-2025-69309 Patchstack
9.3 Critical Nestbyte Core Plugin nestbyte-core SQL Injection No login needed ≤ 1.2 CVE-2025-69308 Patchstack
9.3 Critical Medinik Core Plugin medinik-core SQL Injection No login needed ≤ 1.3.6 CVE-2025-69307 Patchstack
9.3 Critical Electio Core Plugin electio-core SQL Injection No login needed ≤ 1.4 CVE-2025-69306 Patchstack
9.3 Critical Crete Core Plugin crete-core SQL Injection No login needed ≤ 1.4.3 CVE-2025-69305 Patchstack
9.3 Critical Allmart Plugin allmart-core SQL Injection No login needed ≤ 1.1 CVE-2025-69304 Patchstack
9.8 Critical PhotoMe Theme photome PHP Object Injection No login needed ≤ 5.6.11 CVE-2025-69301 Patchstack
9.3 Critical Coven Core Plugin coven-core SQL Injection No login needed ≤ 1.3 CVE-2025-69295 Patchstack
9.9 Critical Wiguard Theme wiguard Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68549 Patchstack
9.8 Critical Ippsum Theme ippsum PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-68541 Patchstack
9.8 Critical Travelicious Theme travelicious PHP Object Injection No login needed ≤ 1.6.7 Fixed in 1.6.7 CVE-2025-67997 Patchstack
9.8 Critical Nestin Theme nestin PHP Object Injection No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-67996 Patchstack
9.8 Critical PatioTime Theme patiotime PHP Object Injection No login needed ≤ 2.1 Fixed in 2.1 CVE-2025-67995 Patchstack
9.9 Critical WPForms Google Sheet Connector Plugin gsheetconnector-wpforms Remote Code Execution ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-67979 Patchstack
9.8 Critical WpEvently Plugin mage-eventpress PHP Object Injection No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-23549 Patchstack
9.8 Critical Grand Restaurant Plugin grandrestaurant PHP Object Injection No login needed ≤ 7.0.10 Fixed in 7.0.11 CVE-2026-23542 Patchstack
9.1 Critical Xpro Elementor Addons Plugin xpro-elementor-addons Arbitrary File Upload ≤ 1.4.19.1 Fixed in 1.4.20 CVE-2025-69312 Patchstack
9.8 Critical Workreap Core Plugin workreap_core Authentication Bypass Broken Authentication No login needed ≤ 3.4.1 CVE-2025-69101 Patchstack
9.8 Critical Sound | Musical Instruments Online Store Theme musicplace PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.6.9 CVE-2025-69079 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin registration-login-with-mobile-phone-number Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-69052 Patchstack
9.9 Critical Miion Plugin miion Arbitrary File Upload ≤ 1.2.7 CVE-2025-68986 Patchstack
9.9 Critical Blogzee Plugin blogzee Arbitrary File Upload ≤ 1.0.5 CVE-2025-68910 Patchstack
9.9 Critical Blogistic Plugin blogistic Arbitrary File Upload ≤ 1.0.5 CVE-2025-68909 Patchstack
9.8 Critical LazyTasks Plugin lazytasks-project-task-management Privilege Escalation No login needed ≤ 1.2.37 Fixed in 1.3.01 CVE-2025-68869 Patchstack
9.3 Critical Paid Downloads Plugin paid-downloads SQL Injection No login needed ≤ 3.15 CVE-2025-68857 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.21 Fixed in 1.5.22 CVE-2025-68034 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only