WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,101–5,150 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 103 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Smart Framework <= Multiple Plugins Theme Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.0.0, ≤ 5.1, ≤ 6.0.6, … CVE-2024-13418 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.88 - Unauthenticated SQL Injection No login needed ≤ 4.88 CVE-2024-13322 Wordfence
7.5 High Advance Seat Reservation Management for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.3 CVE-2024-13344 Wordfence
7.3 High Flynax Bridge Plugin flynax-bridge Privilege Escalation Unauthenticated Limited Privilege Escalation No login needed ≤ 2.2.0 CVE-2025-4179 Wordfence
8.1 High Projectopia – WordPress Project Management Plugin projectopia-core Broken Access Control WordPress Project Management <= 5.1.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 5.1.16 CVE-2025-3952 Wordfence
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed ≤ 0.2.5.4 CVE-2025-1305 Wordfence
8.8 High NewsBlogger Theme newsblogger Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 0.2.5.1 CVE-2025-1304 Wordfence
8.1 High Page View Count Plugin page-views-count Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Options Update 2.8.0 – 2.8.4 CVE-2025-2816 Wordfence
7.2 High boot-store Theme boot-store Cross-Site Scripting The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. No login needed 1.6.4 CVE-2015-4582 mitre
8.1 High Edumall Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.2.4 CVE-2025-2101 Wordfence
8.8 High Aeropage Sync for Airtable Plugin aeropage-sync-for-airtable Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 3.2.0 CVE-2025-3914 Wordfence
8.8 High Integração entre Eduzz e Woocommerce Plugin integracao-entre-eduzz-e-wc-powers Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.7.5 CVE-2025-3906 Wordfence
7.2 High Add custom page template Plugin add-custom-page-template Remote Code Execution Authenticated (Administrator+) PHP Code Injection to Remote Code Execution ≤ 2.0.1 CVE-2025-3491 Wordfence
8.1 High Jupiter X Core Plugin jupiterx-core PHP Object Injection Unauthenticated PHP Object Injection via PHAR No login needed ≤ 4.8.11 CVE-2025-2105 Wordfence
8.8 High Xpro Elementor Addons - Pro Plugin Remote Code Execution Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution ≤ 1.4.9 CVE-2024-13808 Wordfence
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
8.1 High JobSearch WP Job Board Plugin Authentication Bypass Authentication Bypass via Social Logins No login needed ≤ 2.9.2 CVE-2024-11917 Wordfence
7.5 High Mayosis Core Plugin Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 5.4.1 CVE-2025-1565 Wordfence
8.8 High BM Content Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.16.2.1 CVE-2025-1279 Wordfence
8.8 High Vikinger Theme Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'vikinger_user_meta_update_ajax' ≤ 1.9.30 CVE-2025-2238 Wordfence
7.2 High eForm Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.18.0 CVE-2025-1294 Wordfence
7.2 High Social Counter Plugin social-counter PHP Object Injection ≤ 2.0.5 Fixed in 2.1 CVE-2025-46473 Patchstack
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
7.2 High Flickr Shortcode Importer Plugin flickr-shortcode-importer PHP Object Injection ≤ 2.2.3 CVE-2025-46481 Patchstack
7.1 High Loan Calculator Plugin repayment-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-46442 Patchstack
7.1 High Wp Custom CMS Block Plugin wp-custom-cms-block Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-46457 Patchstack
7.1 High WoWHead Tooltips Plugin wowhead-tooltips Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2025-46449 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High Milat jQuery Automatic Popup Plugin milat-jquery-automatic-popup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2025-46514 Patchstack
7.1 High Custom Functions Plugin custom-functions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-46512 Patchstack
7.1 High Contact Form 7 Calendar Plugin cf7-calendar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.1 CVE-2025-46510 Patchstack
7.1 High Advanced lazy load Plugin advanced-lazy-load Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.0 CVE-2025-46508 Patchstack
7.1 High WpZon – Amazon Affiliate Plugin wpzon Cross-Site Request Forgery Amazon Affiliate Plugin plugin <= 1.3 - CSRF to XSS No login needed ≤ 1.3 CVE-2025-46506 Patchstack
7.1 High Vasaio QR Code Plugin vasaio-qr-code Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.2.5 CVE-2025-46504 Patchstack
7.1 High LSD Custom taxonomy and category meta Plugin custom-taxonomy-category-and-term-fields Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.2 CVE-2025-46502 Patchstack
7.1 High PayPal Express Checkout Plugin paypal-express-checkout Cross-Site Request Forgery No login needed ≤ 2.1.2 CVE-2025-46499 Patchstack
7.1 High Navegg Analytics Plugin navegg Cross-Site Request Forgery No login needed ≤ 3.3.3 CVE-2025-46497 Patchstack
7.1 High Call Now PHT Blog Plugin call-now-coccoc-pht-blog Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.4.1 CVE-2025-46492 Patchstack
7.1 High Dropdown Content Plugin dropdown-content Cross-Site Scripting No login needed ≤ 1.0.2 CVE-2025-46478 Patchstack
7.1 High Modern Polls Plugin modern-polls Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.10 CVE-2025-46466 Patchstack
7.1 High Print Science Designer Plugin print-science-designer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.155 CVE-2025-46465 Patchstack
7.1 High Google News Plugin google-news Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-46452 Patchstack
7.1 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.3.0 CVE-2025-46450 Patchstack
7.4 High Plugin Central Plugin plugin-central Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.5.1 CVE-2025-46439 Patchstack
7.1 High Time Based Greeting Plugin time-based-greeting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-46435 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only