WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,951–5,000 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 100 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Hospital Management System Plugin hospital-management SQL Injection ≤ 47.0(20-11-2023) CVE-2025-39357 Patchstack
7.1 High wProject Theme wproject Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.8.0 Fixed in 5.8.0 CVE-2025-39365 Patchstack
8.8 High wProject Theme wproject Privilege Escalation Subscriber+ Privilege Escalation < 5.8.0 Fixed in 5.8.0 CVE-2025-39366 Patchstack
7.1 High WordPress Events Calendar Registration & Tickets Plugin wpeventplus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-39372 Patchstack
7.1 High WPAMS Plugin apartment-management Cross-Site Scripting No login needed ≤ 44.0 (17-08-2023) CVE-2025-39392 Patchstack
7.1 High Hospital Management System Plugin hospital-management Cross-Site Scripting No login needed ≤ 47.0(20-11-2023) CVE-2025-39393 Patchstack
8.5 High WPAMS Plugin apartment-management SQL Injection ≤ 44.0 (17-08-2023) CVE-2025-39403 Patchstack
8.8 High WPAMS Plugin apartment-management Privilege Escalation ≤ 44.0 (17-08-2023) CVE-2025-39405 Patchstack
7.1 High Memberpress Plugin memberpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 1.12.0 Fixed in 1.12.0 CVE-2025-39407 Patchstack
7.1 High WordPress Video Robot - The Ultimate Video Importer Plugin wp-video-robot Cross-Site Scripting The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.0 CVE-2025-39409 Patchstack
7.5 High WhatsApp Click to Chat Plugin wpt-whatsapp Local File Inclusion No login needed ≤ 2.2.12 CVE-2025-39411 Patchstack
7.1 High Booster Plus for WooCommerce Plugin booster-plus-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.4 Fixed in 7.2.5 CVE-2025-39446 Patchstack
7.5 High JetElements For Elementor Plugin jet-elements Broken Access Control No login needed ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39447 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-39449 Patchstack
7.5 High JetBlocks For Elementor Plugin jet-blocks Broken Access Control No login needed ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-39451 Patchstack
8.1 High Foton Plugin foton Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.6.1 CVE-2025-39458 Patchstack
7.3 High Real Estate 7 Plugin realestate-7 Privilege Escalation No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2025-39459 Patchstack
7.1 High Remote Images Grabber Plugin remote-images-grabber Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6 CVE-2025-43832 Patchstack
7.1 High Syndicate Out Plugin syndicate-out Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-43836 Patchstack
7.1 High Total Donations Plugin total-donations Cross-Site Scripting No login needed ≤ 3.0.8 CVE-2025-43837 Patchstack
7.1 High BP Messages Tool Plugin bp-messages-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 Fixed in 2.5 CVE-2025-43839 Patchstack
8.1 High Tastyc Theme tastyc Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.5.2 CVE-2025-27010 Patchstack
7.1 High Wireless Butler Plugin wireless-butler Cross-Site Scripting No login needed ≤ 1.0.11 CVE-2025-26997 Patchstack
7.5 High Grip Theme grip Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-26735 Patchstack
7.6 High Absolute Links Plugin absolute-links SQL Injection ≤ 1.1.1 CVE-2025-43833 Patchstack
7.5 High JetReviews Plugin jet-reviews Local File Inclusion ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39396 Patchstack
7.1 High CheckBot Plugin checkbot Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.05 CVE-2025-43840 Patchstack
7.1 High Best Posts Summary Plugin best-posts-summary Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-39374 Patchstack
7.6 High iCafe Library Plugin icafe-library SQL Injection ≤ 1.8.3 CVE-2025-39370 Patchstack
7.5 High Product Category Slider for WooCommerce Plugin woo-category-slider-by-pluginever Local File Inclusion ≤ 4.3.4 Fixed in 4.3.5 CVE-2025-39364 Patchstack
8.8 High Bimber - Viral Magazine Theme bimber Local File Inclusion Viral Magazine WordPress Theme theme <= 9.2.5 - Local File Inclusion ≤ 9.2.5 CVE-2025-47576 Patchstack
7.1 High Ghostwriter Theme ghostwriter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23988 Patchstack
7.1 High Tiki Time Theme tiki-time Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23986 Patchstack
7.1 High Tijaji Plugin tijaji Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.43 CVE-2025-23983 Patchstack
7.1 High CarZine Theme carzine Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-23981 Patchstack
7.1 High Flashy Theme flashy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23979 Patchstack
7.1 High Js O3 Lite Theme js-o3-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.8.2 CVE-2025-22792 Patchstack
7.1 High offset writing Theme offset-writing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-22791 Patchstack
7.1 High moseter Theme moseter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 CVE-2025-22790 Patchstack
7.1 High polka dots Theme polka-dots Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-22789 Patchstack
7.1 High Tuaug4 Theme tuaug4 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22687 Patchstack
7.1 High my white Theme my-white Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 CVE-2025-22678 Patchstack
7.6 High AutomatorWP Plugin automatorwp SQL Injection ≤ 5.2.1.3 Fixed in 5.2.2 CVE-2025-48280 Patchstack
8.5 High RSVPMarker Plugin rsvpmaker SQL Injection ≤ 11.5.6 Fixed in 11.5.7 CVE-2025-48278 Patchstack
7.1 High AWcode Toolkit Plugin awcode-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-48238 Patchstack
8.5 High bunny.net Plugin bunnycdn Cross-Site Scripting ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-48236 Patchstack
7.1 High Affiliates Manager Google reCAPTCHA Integration Plugin affiliates-manager-google-recaptcha-integration Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-48233 Patchstack
7.5 High Wise Chat Plugin wise-chat Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 3.3.2 CVE-2024-13613 Wordfence
7.2 High CSV Mass Importer Plugin Arbitrary File Upload Admin+ Arbitrary File Upload ≤ 1.2 CVE-2025-4190 WPScan
8.1 High WPBot Pro Wordpress Chatbot Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 13.6.2 CVE-2025-3812 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only