WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,001–5,050 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 101 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High SHOUT Plugin lbg-audio8-html5-radio_ads SQL Injection ≤ 3.5.3 CVE-2025-31637 Patchstack
8.5 High UberSlider Plugin uber-classic SQL Injection ≤ 2.6 Fixed in 2.6 CVE-2025-31641 Patchstack
8.5 High Magic Responsive Slider and Carousel Plugin magic-carousel SQL Injection ≤ 1.6 Fixed in 1.6 CVE-2025-31640 Patchstack
7.1 High CSS3 Accordions Plugin css3_accordions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-31922 Patchstack
8.5 High Multimedia Responsive Carousel with Image Video Audio Support Plugin multimedia-carousel SQL Injection ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-31928 Patchstack
8.5 High Sticky Radio Player Plugin lbg-audio5-html5-shoutcast_sticky SQL Injection ≤ 3.4 CVE-2025-31926 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) ≤ 1.25 CVE-2025-32245 Patchstack
8.5 High Sticky HTML5 Music Player Plugin lbg-audio3-html5 SQL Injection ≤ 3.1.6 CVE-2025-32290 Patchstack
8.5 High Responsive HTML5 Audio Player PRO With Playlist Plugin lbg-audio2-html5 SQL Injection ≤ 3.5.7 CVE-2025-32287 Patchstack
8.5 High Radio Player Shoutcast & Icecast Plugin audio4-html5 SQL Injection ≤ 4.4.6 Fixed in 4.4.7 CVE-2025-32306 Patchstack
8.5 High CountDown Pro WP Plugin circular_countdown SQL Injection ≤ 2.7 CVE-2025-32301 Patchstack
8.8 High QuickCal - Appointment Booking Calendar Plugin quickcal Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32310 Patchstack
8.5 High Chameleon HTML5 Audio Player With/Without Playlist Plugin lbg-audio1-html5 SQL Injection ≤ 3.5.6 CVE-2025-32307 Patchstack
8.1 High WHMpress Plugin whmpress Local File Inclusion No login needed 6.2 – revision CVE-2025-39491 Patchstack
7.5 High WHMpress Plugin whmpress Local File Inclusion 6.2 – revision CVE-2025-39492 Patchstack
7.5 High Nasa Core Plugin nasa-core Local File Inclusion ≤ 6.4.4 Fixed in 6.4.4 CVE-2025-39507 Patchstack
7.1 High Better Customer List for WooCommerce Plugin woo-better-customer-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-39537 Patchstack
7.6 High Video Player & FullScreen Video Background Plugin universal-video-player-and-bg SQL Injection ≤ 2.4.1 CVE-2025-47567 Patchstack
7.5 High FAT Services Booking Plugin fat-services-booking Local File Inclusion ≤ 5.5 CVE-2025-47693 Patchstack
7.1 High SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.1 Fixed in 3.0.0 CVE-2025-48146 Patchstack
7.1 High Import Export For WooCommerce Plugin import-export-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.2 CVE-2025-48144 Patchstack
8.5 High Interview Plugin interview SQL Injection ≤ 1.01 CVE-2025-48137 Patchstack
7.5 High Mortgage Calculator Estatik Plugin estatik-mortgage-calculator Local File Inclusion ≤ 2.0.12 CVE-2025-48136 Patchstack
7.2 High WP Tabs Plugin wp-expand-tabs-free PHP Object Injection ≤ 2.2.12 Fixed in 2.2.13 CVE-2025-48134 Patchstack
7.1 High ShayanWeb Admin FontChanger Plugin shayanweb-admin-fontchanger Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.9.1 Fixed in 1.10 CVE-2025-48114 Patchstack
7.1 High Dot html,php,xml etc pages Plugin dot-htmlphpxml-etc-pages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-48112 Patchstack
8.8 High coreActivity Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.8.1 Fixed in 1.8.1 CVE-2024-0852 WPScan
7.1 High Advanced Schedule Posts Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.1.8 CVE-2024-0249 WPScan
7.5 High wp-dashboard-notes Plugin Broken Access Control Contributor+ Arbitrary Private Notes Update via IDOR No login needed < 1.0.11 Fixed in 1.0.11 CVE-2023-7239 WPScan
7.3 High illi Link Party! Plugin Broken Access Control Unauthenticated Arbitrary Link Deletion No login needed ≤ 1.0 CVE-2023-7231 WPScan
7.1 High Marketing Twitter Bot Plugin Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed ≤ 1.11 CVE-2023-7197 WPScan
7.1 High aBitGone CommentSafe Plugin Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2023-7174 WPScan
7.3 High Travelpayouts Plugin travelpayouts Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.1.13 Fixed in 1.1.13 CVE-2023-5934 WPScan
7.2 High Taskbuilder Plugin taskbuilder SQL Injection Admin+ SQL Injection < 3.0.9 Fixed in 3.0.9 CVE-2024-9831 WPScan
7.5 High Event Calendar Plugin Broken Access Control Unauthenticated Arbitrary Calendar Deletion No login needed ≤ 1.0.4 CVE-2024-8700 WPScan
7.2 High Z-Downloads Plugin z-downloads Arbitrary File Upload Admin+ Arbitrary File Upload < 1.11.5 Fixed in 1.11.5 CVE-2024-8699 WPScan
8.1 High Offload Videos – Bunny.net, AWS S3 Plugin offload-videos-bunny-netaws-s3 Cross-Site Request Forgery Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF No login needed < 1.0.1 Fixed in 1.0.1 CVE-2024-6719 WPScan
7.2 High ImageMagick Engine Plugin imagemagick-engine Remote Code Execution Administrator+ OS Command Injection < 1.7.11 Fixed in 1.7.11 CVE-2024-6486 WPScan
7.5 High WP ERP Plugin Broken Access Control Custom+ Unauthorized Access to Terminated Employee Information No login needed < 1.13.4 Fixed in 1.13.4 CVE-2024-12812 WPScan
7.2 High Advance Post Prefix Plugin SQL Injection Admin+ SQL Injection ≤ 1.1.1 CVE-2024-12735 WPScan
7.2 High Connexion Logs Plugin SQL Injection Admin+ SQL Injection ≤ 3.0.2 CVE-2024-11372 WPScan
7.2 High AHAthat Plugin SQL Injection Admin+ SQL Injection ≤ 1.6 CVE-2024-11269 WPScan
8.8 High JSP Store Locator Plugin SQL Injection Contributor+ SQL Injection ≤ 1.0 CVE-2024-11267 WPScan
7.1 High WP2LEADS Plugin wp2leads Cross-Site Request Forgery No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-32922 Patchstack
7.2 High File Manager Advanced Shortcode <= Multiple Versions Plugin Local File Inclusion Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode ≤ 2.5.4, ≤ 2.5.6 CVE-2024-13914 Wordfence
8.8 High UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Remote Code Execution Authenticated (Subscriber+) Remote Code Execution ≤ 3.5.07 CVE-2025-3053 Wordfence
7.2 High WP Content Security Plugin wp-content-security-policy Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via CSP-Report Fields No login needed ≤ 2.3 CVE-2025-4579 Wordfence
7.5 High Eventin Plugin wp-event-solution Path Traversal Arbitrary File Download No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2025-47445 Patchstack
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function Function 1.0 – 2.2.7 CVE-2025-4474 Wordfence
8.8 High TheGem Theme Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.10.3 CVE-2025-4317 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only