WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,051–5,100 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 102 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via ajax_request Function 1.5.10 – 2.2.7 CVE-2025-4473 Wordfence
7.5 High Relevanssi Plugin relevanssi SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.27.5, ≤ 4.24.4 CVE-2025-4396 Wordfence
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Privilege Escalation WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function ≤ 3.8.1 CVE-2025-3876 Wordfence
8.8 High WordPress Review Plugin: The Ultimate Solution for Building a Review Website Plugin wp-review Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Custom Fields ≤ 5.3.5 CVE-2025-2158 Wordfence
7.2 High WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg Plugin groundhogg Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion ≤ 4.1.1.2 CVE-2025-4206 Wordfence
8.8 High 1 Click WordPress Migration Plugin – 100% FREE for a limited time Plugin 1-click-migration Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.2 CVE-2025-3455 Wordfence
7.5 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Path Traversal Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read No login needed ≤ 4.0.26 CVE-2025-3419 Wordfence
7.3 High Wolmart | Multi-Vendor Marketplace WooCommerce Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed ≤ 1.8.11 CVE-2024-13793 Wordfence
7.1 High Contribuinte Checkout Plugin contribuinte-checkout Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0.03 Fixed in 2.0.04 CVE-2025-47685 Patchstack
7.2 High WP Maintenance Plugin wp-maintenance PHP Object Injection ≤ 6.1.9.7 Fixed in 6.1.9.8 CVE-2025-47683 Patchstack
7.1 High theMarketer Plugin themarketer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47655 Patchstack
7.5 High WP-Recall Plugin wp-recall Local File Inclusion ≤ 16.26.14 CVE-2025-47653 Patchstack
8.8 High Open Close WooCommerce Store Plugin woc-open-close Local File Inclusion ≤ 4.9.9 CVE-2025-47649 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.6 High ELEX Product Feed for WooCommerce Plugin elex-product-feed SQL Injection ≤ 3.1.2 CVE-2025-47643 Patchstack
7.1 High Supertext Translation and Proofreading Plugin polylang-supertext Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.26 CVE-2025-47639 Patchstack
7.5 High List category posts Plugin list-category-posts Local File Inclusion ≤ 0.91.0 Fixed in 0.92.0 CVE-2025-47636 Patchstack
7.2 High WP-CRM System Plugin wp-crm-system PHP Object Injection ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-47629 Patchstack
7.1 High Martins Free Monetized Ad Exchange Network Plugin martins-free-and-easy-ad-network-get-more-visitors Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-47620 Patchstack
7.6 High YaySMTP Plugin yaysmtp SQL Injection ≤ 2.6.4 Fixed in 2.6.5 CVE-2025-47587 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47546 Patchstack
7.6 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing SQL Injection ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-47544 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
7.5 High XT Event Widget for Social Events Plugin xt-facebook-events Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-47531 Patchstack
7.1 High Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2025-47517 Patchstack
7.1 High ELI's Related Posts Footer Links and Widget Plugin spostarbust Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.04.20 Fixed in 1.2.04.25 CVE-2025-47514 Patchstack
7.5 High Display Eventbrite Events Plugin widget-for-eventbrite-api Local File Inclusion ≤ 6.3 Fixed in 6.3 CVE-2025-47510 Patchstack
7.5 High GamiPress Plugin gamipress Local File Inclusion ≤ 7.3.7 Fixed in 7.3.8 CVE-2025-47508 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.6 Fixed in 3.7 CVE-2025-47498 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Local File Inclusion ≤ 4.7.5 Fixed in 4.7.6 CVE-2025-47496 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-47494 Patchstack
7.4 High Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47491 Patchstack
8.5 High Ultimate WP Mail Plugin ultimate-wp-mail SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-47490 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
7.6 High TrackShip for WooCommerce Plugin trackship-for-woocommerce SQL Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47460 Patchstack
7.5 High WPAdverts Plugin wpadverts Local File Inclusion ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-47440 Patchstack
7.5 High Download Monitor Plugin download-monitor Local File Inclusion ≤ 5.0.22 Fixed in 5.0.23 CVE-2025-47439 Patchstack
8.8 High Woocommerce Multiple Addresses Plugin woocommerce-multiple-addresses Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.7.1 CVE-2025-4335 Wordfence
8.2 High PeproDev Ultimate Profile Solutions Plugin peprodev-ups Broken Access Control Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function No login needed 1.9.1 – 7.5.2 CVE-2025-3921 Wordfence
8.8 High WPshop Plugin wpshop Privilege Escalation E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover 2.0.0 – 2.6.0 CVE-2025-3852 Wordfence
7.3 High PGS Core Plugin Broken Access Control Missing Authorization via Multiple Functions No login needed ≤ 5.8.0 CVE-2025-0856 Wordfence
7.5 High PGS Core Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.8.0 CVE-2025-0853 Wordfence
7.5 High Slider & Popup Builder by Depicter Plugin depicter SQL Injection Unauthenticated SQL Injection via 's' Parameter No login needed ≤ 3.6.1 CVE-2025-2011 Wordfence
7.3 High LayoutBoxx Plugin layoutboxx Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.3.1 CVE-2025-2802 Wordfence
8.8 High Reales WP STPT Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Update ≤ 2.1.2 CVE-2025-3610 Wordfence
8.8 High External image replace Plugin external-image-replace Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.8 CVE-2025-4279 Wordfence
7.3 High Motors - Car Dealer, Rental & Listing Theme Arbitrary Shortcode Execution Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.6.65 CVE-2024-13738 Wordfence
7.5 High Ultimate Auction Pro Plugin SQL Injection Unauthenticated SQL Injection via 'auction_id' No login needed ≤ 1.5.2 CVE-2025-4204 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only