WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 5,401–5,450 of 9,029 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | Ultimate Bootstrap Elements for Elementor | Local File Inclusion No login needed |
≤ 1.4.9 Fixed in 1.5.0 |
CVE-2025-32672 |
Patchstack | |
| 7.5 High | Print Science Designer | Path Traversal Arbitrary File Download No login needed |
≤ 1.3.155 |
CVE-2025-32671 |
Patchstack | |
| 8.1 High | FAT Cooming Soon | Local File Inclusion No login needed |
≤ 1.1 |
CVE-2025-32663 |
Patchstack | |
| 8.1 High | Testimonial Slider And Showcase Pro | Local File Inclusion No login needed |
≤ 2.3.15 |
CVE-2025-32656 |
Patchstack | |
| 8.1 High | Motors | Local File Inclusion No login needed |
≤ 1.4.71 Fixed in 1.4.72 |
CVE-2025-32654 |
Patchstack | |
| 8.5 High | Accessibility Suite | SQL Injection |
≤ 4.18 Fixed in 4.19 |
CVE-2025-32650 |
Patchstack | |
| 8.6 High | Database Toolset | Arbitrary File Deletion No login needed |
≤ 1.8.4 |
CVE-2025-32633 |
Patchstack | |
| 7.1 High | Automatic Ban IP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.7 |
CVE-2025-32632 |
Patchstack | |
| 8.6 High | Oxygen MyData for WooCommerce | Arbitrary File Deletion No login needed |
≤ 1.0.64 Fixed in 1.0.65 |
CVE-2025-32631 |
Patchstack | |
| 8.6 High | WP-BusinessDirectory | Arbitrary File Deletion No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2025-32629 |
Patchstack | |
| 8.1 High | JS Job Manager | Local File Inclusion No login needed |
≤ 2.0.2 |
CVE-2025-32627 |
Patchstack | |
| 8.5 High | Wishlist | SQL Injection |
≤ 1.0.46 |
CVE-2025-32618 |
Patchstack | |
| 8.8 High | EventON | Local File Inclusion No login needed |
≤ 2.4 Fixed in 2.4.1 |
CVE-2025-32614 |
Patchstack | |
| 7.1 High | Twispay Credit Card Payments | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.2 |
CVE-2025-32601 |
Patchstack | |
| 7.1 High | Tournamatch | Cross-Site Scripting No login needed |
≤ 4.7.0 |
CVE-2025-32600 |
Patchstack | |
| 7.1 High | Task Scheduler | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.3 |
CVE-2025-32599 |
Patchstack | |
| 7.1 High | WP Table Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2025-32598 |
Patchstack | |
| 8.1 High | Flexi – Guest Submit | Local File Inclusion Guest Submit Plugin <= 4.28 - Local File Inclusion No login needed |
≤ 4.28 |
CVE-2025-32589 |
Patchstack | |
| 8.1 High | WooCommerce Pickupp | Local File Inclusion No login needed |
≤ 2.4.3 |
CVE-2025-32587 |
Patchstack | |
| 7.1 High | ABA PayWay Payment Gateway for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.4 Fixed in 2.1.5 |
CVE-2025-32586 |
Patchstack | |
| 7.5 High | Shop Products Filter | Local File Inclusion |
≤ 1.2 |
CVE-2025-32585 |
Patchstack | |
| 8.5 High | Easy Post Duplicator | SQL Injection |
≤ 1.0.1 |
CVE-2025-32567 |
Patchstack | |
| 8.5 High | Duplicate Title Checker | SQL Injection |
≤ 1.2 |
CVE-2025-32558 |
Patchstack | |
| 7.1 High | RestroPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.8.4 |
CVE-2025-32553 |
Patchstack | |
| 7.1 High | Connector to CiviCRM with CiviMcRestFace | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.8 Fixed in 1.0.9 |
CVE-2025-32551 |
Patchstack | |
| 8.8 High | Eazy Plugin Manager | Broken Access Control |
≤ 4.3.0 Fixed in 4.4.0 |
CVE-2025-32542 |
Patchstack | |
| 7.1 High | WooCommerce Sales MIS Report | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.3 |
CVE-2025-32541 |
Patchstack | |
| 7.1 High | Store Exporter | Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed |
≤ 2.7.4 Fixed in 2.7.5 |
CVE-2025-32539 |
Patchstack | |
| 7.1 High | Easy Post Duplicator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-32538 |
Patchstack | |
| 7.1 High | Lock Your Updates | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-32537 |
Patchstack | |
| 7.1 High | HTML5 Video Player with Playlist | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.50 |
CVE-2025-32536 |
Patchstack | |
| 7.1 High | Workbox Video from Vimeo & Youtube | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.2 |
CVE-2025-32534 |
Patchstack | |
| 7.1 High | Interactive Geo Maps | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.24 Fixed in 1.6.25 |
CVE-2025-32525 |
Patchstack | |
| 7.1 High | MyWorks WooCommerce Sync for QuickBooks Online | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2025-32524 |
Patchstack | |
| 7.1 High | WooCommerce – Payphone Gateway | Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.0 Fixed in 3.2.1 |
CVE-2025-32523 |
Patchstack | |
| 8.1 High | IDonate | Local File Inclusion No login needed |
≤ 2.1.18 |
CVE-2025-32519 |
Patchstack | |
| 7.1 High | MultiMailer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.3 |
CVE-2025-32517 |
Patchstack | |
| 7.5 High | Simple WP Events | Arbitrary File Deletion No login needed |
≤ 1.8.17 Fixed in 1.9.0 |
CVE-2025-32509 |
Patchstack | |
| 8.8 High | Job Board Manager | PHP Object Injection |
≤ 2.1.61 |
CVE-2025-32144 |
Patchstack | |
| 8.8 High | Accordion | PHP Object Injection |
≤ 2.3.11 Fixed in 2.3.12 |
CVE-2025-32143 |
Patchstack | |
| 7.1 High | Insert HTML Here | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-31379 |
Patchstack | |
| 7.1 High | Oppso Unit Converter | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.1 |
CVE-2025-31378 |
Patchstack | |
| 7.5 High | AnyTrack Affiliate Link Manager | Broken Access Control No login needed |
≤ 1.0.4 Fixed in 1.5.5 |
CVE-2025-31041 |
Patchstack | |
| 8.1 High | WP Food ordering and Restaurant Menu | Local File Inclusion No login needed |
≤ 2.7 |
CVE-2025-31040 |
Patchstack | |
| 7.1 High | WP Hide Categories | Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-31028 |
Patchstack | |
| 7.1 High | Mobile Smart | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ v1.3.16 |
CVE-2025-31021 |
Patchstack | |
| 7.5 High | WordPress SMTP Service, Email Delivery Solved! — MailHawk | Local File Inclusion No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-31015 |
Patchstack | |
| 7.5 High | Material Dashboard | Local File Inclusion |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2025-31014 |
Patchstack | |
| 7.2 High | SMTP for Amazon SES – YaySMTP | Cross-Site Scripting YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed |
≤ 1.8 |
CVE-2025-3434 |
Wordfence | |
| 8.1 High | InstaWP Connect | Local File Inclusion Unauthenticated Local PHP File Inclusion No login needed |
≤ 0.1.0.85 |
CVE-2025-2636 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.