WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,151–5,200 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 104 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Arrival Plugin arrival Local File Inclusion No login needed ≤ 1.4.5 CVE-2025-32921 Patchstack
7.5 High Grace Mag Plugin grace-mag Local File Inclusion No login needed ≤ 1.1.5 CVE-2025-39360 Patchstack
7.5 High CWW Portfolio Plugin cww-portfolio Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-39359 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Local File Inclusion Light plugin <= 2.4.37 - Local File Inclusion No login needed ≤ 2.4.37 CVE-2025-39378 Patchstack
8.5 High Appsero Helper Plugin appsero-helper SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-39377 Patchstack
7.1 High KiotViet Sync Plugin kiotvietsync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8.4 CVE-2025-39381 Patchstack
7.5 High Capturly Plugin capturly-optimize-your-website Local File Inclusion No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-39379 Patchstack
7.1 High ACF: Google Font Selector Plugin acf-google-font-selector-field Cross-Site Scripting No login needed ≤ 3.0.1 CVE-2025-39382 Patchstack
7.5 High Product Lister for eBay Plugin product-lister-ebay Local File Inclusion No login needed ≤ 2.0.9 CVE-2025-39384 Patchstack
7.5 High Xews Lite Plugin xews-lite Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-39383 Patchstack
7.5 High Opstore Plugin opstore Local File Inclusion No login needed ≤ 1.4.5 CVE-2025-39387 Patchstack
7.1 High Anything Popup Plugin anything-popup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.3 CVE-2025-39397 Patchstack
7.5 High Checkout Field Visibility for WooCommerce Plugin checkout-field-visibility-for-woocommerce Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.4.0 CVE-2025-39391 Patchstack
7.1 High User Registration Plugin user-registration Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-39400 Patchstack
7.5 High License For Envato Plugin license-envato Local File Inclusion No login needed ≤ 1.0.0 Fixed in 1.1.0 CVE-2025-39399 Patchstack
7.1 High BruteGuard – Brute Force Login Protection Plugin bruteguard Cross-Site Scripting Brute Force Login Protection plugin <= 0.1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.4 CVE-2025-39408 Patchstack
7.1 High Control Listings Plugin control-listings Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4.1 Fixed in 1.0.5 CVE-2025-46234 Patchstack
7.5 High Popup Builder Plugin easy-notify-lite Local File Inclusion ≤ 1.1.35 Fixed in 1.1.37 CVE-2025-46230 Patchstack
8.3 High Verification SMS with TargetSMS Plugin verification-sms-targetsms Remote Code Execution Unauthenticated Limited Remote Code Execution No login needed ≤ 1.5 CVE-2025-3776 Wordfence
7.2 High WPMasterToolKit (WPMTK) – All in one Plugin wpmastertoolkit Path Traversal All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary File Read and Write ≤ 1.15.0 CVE-2025-3300 Wordfence
8.8 High Frontend Login and Registration Blocks Plugin frontend-login-and-registration-blocks Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Reset ≤ 1.0.8 CVE-2025-3607 Wordfence
8.8 High Configurator Theme Core Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.4.7 CVE-2025-3101 Wordfence
8.8 High Xelion Webchat Plugin xelion-webchat Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update ≤ 9.1.0 CVE-2025-3058 Wordfence
8.8 High My Tickets – Accessible Event Ticketing Plugin my-tickets Privilege Escalation Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation ≤ 2.0.16 CVE-2025-3761 Wordfence
8.6 High The Wound Theme Local File Inclusion Unauthenticated LFI No login needed ≤ 0.0.1 CVE-2025-2558 WPScan
7.5 High WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Price Manipulation Unauthenticated Product Price Manipulation No login needed ≤ 5.1.2 CVE-2025-3530 Wordfence
8.2 High WordPress Simple PayPal Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Information Disclosure Unauthenticated Information Exposure via file_url Parameter No login needed ≤ 5.1.2 CVE-2025-3529 Wordfence
7.6 High Message Filter for Contact Form 7 Plugin cf7-message-filter SQL Injection ≤ 1.6.3.2 Fixed in 1.6.3.3 CVE-2025-46252 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.3 Fixed in 1.4 CVE-2025-46251 Patchstack
7.6 High Watu Quiz Plugin watu SQL Injection ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-46242 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
8.1 High User Registration & Membership Plugin user-registration Authentication Bypass No login needed < 4.1.3 Fixed in 4.1.3 CVE-2025-2594 WPScan
7.1 High Front End Users Plugin front-end-only-users Cross-Site Scripting Reflected XSS No login needed ≤ 3.2.32 CVE-2024-13569 WPScan
8.8 High Greenshift Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload 11.4 – 11.4.5 CVE-2025-3616 Wordfence
8.8 High Download Manager Plugin download-manager Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion ≤ 3.3.12 CVE-2025-3404 Wordfence
7.5 High WP-Syntax Plugin Denial of Service Author+ Potential ReDoS No login needed ≤ 1.2 CVE-2024-13926 WPScan
7.2 High Debug Log Manager Plugin debug-log-manager Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.3.4 CVE-2025-3809 Wordfence
7.5 High WP Headers And Footers Plugin wp-headers-and-footers Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.1.1 CVE-2025-2111 Wordfence
7.5 High CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon Plugin Path Traversal HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon <= 2.4 - Unauthenticated Arbitrary File Read No login needed ≤ 2.4 CVE-2025-3103 Wordfence
7.5 High JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin jobwp SQL Injection Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection No login needed ≤ 2.3.9 CVE-2025-2010 Wordfence
7.1 High Modal Survey Plugin modal-survey Cross-Site Scripting No login needed ≤ 2.0.2.0.1 CVE-2025-39469 Patchstack
8.1 High Ivy School Plugin ivy-school Local File Inclusion No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-39470 Patchstack
8.1 High Avatar Plugin avatar Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 0.1.4 CVE-2025-3520 Wordfence
7.1 High visualslider Sldier Plugin visual-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.4 CVE-2025-23448 Patchstack
7.1 High Author Showcase Plugin author-showcase Cross-Site Scripting No login needed ≤ 1.4.3 CVE-2025-23443 Patchstack
7.1 High SpiderDisplay Plugin spiderdisplay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2025-23855 Patchstack
7.1 High TotalContest Lite Plugin totalcontest-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.1 Fixed in 2.9.0 CVE-2025-23782 Patchstack
7.1 High Custom Users Order Plugin custom-users-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2 CVE-2025-23858 Patchstack
7.1 High DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.5 Fixed in 5.6.6 CVE-2025-24539 Patchstack
7.1 High Autoglot – Automatic WordPress Translation Plugin autoglot Cross-Site Scripting Automatic WordPress Translation plugin <=2.4.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2025-24548 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only