WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,251–5,300 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 106 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High FV Antispam Plugin fv-antispam Cross-Site Scripting No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-66102 Patchstack
6.5 Medium RestroPress Plugin restropress Broken Access Control ≤ 3.2.3.5 Fixed in 3.2.3.6 CVE-2025-66100 Patchstack
7.5 High PropertyHive Plugin propertyhive Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66088 Patchstack
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
9.0 Critical WP Webhooks Plugin wp-webhooks Arbitrary File Upload No login needed ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66074 Patchstack
7.5 High wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 2.4.10 Fixed in 2.4.11 CVE-2025-66070 Patchstack
6.5 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.1.9 Fixed in 0.1.2.0 CVE-2025-66068 Patchstack
7.5 High LearnPress Plugin learnpress Broken Access Control No login needed ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-66054 Patchstack
7.1 High ListingPro Theme listingpro Broken Access Control ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64378 Patchstack
8.1 High ListingPro Theme listingpro Local File Inclusion No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64377 Patchstack
7.1 High ListingPro Theme listingpro Cross-Site Scripting No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64376 Patchstack
6.5 Medium WP Social Ninja Plugin wp-social-reviews Broken Access Control No login needed ≤ 3.20.1 Fixed in 3.20.2 CVE-2025-64375 Patchstack
9.9 Critical Motors Theme motors Arbitrary File Upload ≤ 5.6.81 Fixed in 5.6.82 CVE-2025-64374 Patchstack
8.1 High Traveler Plugin traveler Local File Inclusion No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64373 Patchstack
7.1 High Traveler Plugin traveler Cross-Site Scripting No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64372 Patchstack
8.5 High Traveler Plugin traveler SQL Injection ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64371 Patchstack
6.5 Medium All In One SEO Pack Plugin all-in-one-seo-pack Information Disclosure Sensitive Data Exposure ≤ 4.8.6.1 Fixed in 4.8.7 CVE-2025-64295 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64273 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Information Disclosure Sensitive Data Exposure ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64272 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
7.5 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.44 Fixed in 1.0.45 CVE-2025-64268 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
7.1 High ANAC XML Bandi di Gara Plugin avcp Cross-Site Scripting No login needed ≤ 7.7 Fixed in 7.7.1 CVE-2025-64260 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-64258 Patchstack
9.8 Critical Codiqa Theme codiqa PHP Object Injection No login needed ≤ 1.2.8 Fixed in 1.2.8 CVE-2025-64233 Patchstack
9.9 Critical WordPress Contact Form 7 PDF, Google Sheet & Database Plugin rtwwcfp-wordpress-contact-form-7-pdf Arbitrary File Upload ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64231 Patchstack
7.7 High Filr Plugin filr-protection Arbitrary File Deletion ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-64230 Patchstack
9.8 Critical Client Invoicing by Sprout Invoices Plugin sprout-invoices PHP Object Injection No login needed ≤ 20.8.7 Fixed in 20.8.8 CVE-2025-64227 Patchstack
6.5 Medium Stockie Extra Plugin stockie-extra Content Injection No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64225 Patchstack
8.1 High PenNews Plugin pennews Local File Inclusion No login needed ≤ 6.7.3 Fixed in 6.7.3 CVE-2025-64223 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
7.1 High Reservation Plugin dt-reservation-plugin Cross-Site Scripting No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64221 Patchstack
7.5 High Passster Plugin content-protector Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.19 Fixed in 4.2.20 CVE-2025-64218 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.2 Fixed in 7.7.4 CVE-2025-64217 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64214 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64213 Patchstack
7.5 High Masterstudy Theme masterstudy Broken Access Control No login needed ≤ 4.8.122 Fixed in 4.8.122 CVE-2025-64209 Patchstack
7.1 High Jannah Plugin jannah Cross-Site Scripting No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64207 Patchstack
9.8 Critical Jannah Plugin jannah PHP Object Injection No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64206 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64205 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting No login needed ≤ 4.1.14 Fixed in 4.1.14 CVE-2025-64203 Patchstack
7.5 High XStore Theme xstore Local File Inclusion ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64193 Patchstack
6.3 Medium XStore Theme xstore Broken Access Control ≤ 9.6 Fixed in 9.6 CVE-2025-64192 Patchstack
7.1 High XStore Theme xstore Cross-Site Scripting No login needed ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64191 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting No login needed ≤ 5.6 Fixed in 5.6 CVE-2025-64189 Patchstack
9.8 Critical Soledad Theme soledad Privilege Escalation No login needed ≤ 8.6.9 Fixed in 8.6.9.1 CVE-2025-64188 Patchstack
6.5 Medium ListingPro Theme listingpro Broken Access Control ≤ 2.9.9 CVE-2025-63039 Patchstack
7.1 High Support Board Plugin supportboard Cross-Site Scripting No login needed ≤ 3.8.7 Fixed in 3.8.7 CVE-2025-60182 Patchstack
9.8 Critical WP Gravity Forms Salesforce Plugin gf-salesforce-crmperks PHP Object Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-60180 Patchstack
9.8 Critical WP Gravity Forms HubSpot Plugin gf-hubspot PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60178 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only