WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,401–5,450 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 109 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-32672 Patchstack
7.5 High Print Science Designer Plugin print-science-designer Path Traversal Arbitrary File Download No login needed ≤ 1.3.155 CVE-2025-32671 Patchstack
8.1 High FAT Cooming Soon Plugin fat-coming-soon Local File Inclusion No login needed ≤ 1.1 CVE-2025-32663 Patchstack
8.1 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion No login needed ≤ 2.3.15 CVE-2025-32656 Patchstack
8.1 High Motors Plugin motors-car-dealership-classified-listings Local File Inclusion No login needed ≤ 1.4.71 Fixed in 1.4.72 CVE-2025-32654 Patchstack
8.5 High Accessibility Suite Plugin online-accessibility SQL Injection ≤ 4.18 Fixed in 4.19 CVE-2025-32650 Patchstack
8.6 High Database Toolset Plugin database-toolset Arbitrary File Deletion No login needed ≤ 1.8.4 CVE-2025-32633 Patchstack
7.1 High Automatic Ban IP Plugin automatic-ban-ip Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 CVE-2025-32632 Patchstack
8.6 High Oxygen MyData for WooCommerce Plugin oxygen-mydata Arbitrary File Deletion No login needed ≤ 1.0.64 Fixed in 1.0.65 CVE-2025-32631 Patchstack
8.6 High WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Deletion No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32629 Patchstack
8.1 High JS Job Manager Plugin js-jobs Local File Inclusion No login needed ≤ 2.0.2 CVE-2025-32627 Patchstack
8.5 High Wishlist Plugin wishlist SQL Injection ≤ 1.0.46 CVE-2025-32618 Patchstack
8.8 High EventON Plugin eventon-lite Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4.1 CVE-2025-32614 Patchstack
7.1 High Twispay Credit Card Payments Plugin twispay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-32601 Patchstack
7.1 High Tournamatch Plugin tournamatch Cross-Site Scripting No login needed ≤ 4.7.0 CVE-2025-32600 Patchstack
7.1 High Task Scheduler Plugin task-scheduler Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-32599 Patchstack
7.1 High WP Table Builder Plugin wp-table-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-32598 Patchstack
8.1 High Flexi – Guest Submit Plugin flexi Local File Inclusion Guest Submit Plugin <= 4.28 - Local File Inclusion No login needed ≤ 4.28 CVE-2025-32589 Patchstack
8.1 High WooCommerce Pickupp Plugin wc-pickupp Local File Inclusion No login needed ≤ 2.4.3 CVE-2025-32587 Patchstack
7.1 High ABA PayWay Payment Gateway for WooCommerce Plugin aba-payway-woocommerce-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-32586 Patchstack
7.5 High Shop Products Filter Plugin trusty-woo-products-filter Local File Inclusion ≤ 1.2 CVE-2025-32585 Patchstack
8.5 High Easy Post Duplicator Plugin easy-post-duplicator SQL Injection ≤ 1.0.1 CVE-2025-32567 Patchstack
8.5 High Duplicate Title Checker Plugin duplicate-title-checker SQL Injection ≤ 1.2 CVE-2025-32558 Patchstack
7.1 High RestroPress Plugin restropress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.8.4 CVE-2025-32553 Patchstack
7.1 High Connector to CiviCRM with CiviMcRestFace Plugin connector-civicrm-mcrestface Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-32551 Patchstack
8.8 High Eazy Plugin Manager Plugin plugins-on-steroids Broken Access Control ≤ 4.3.0 Fixed in 4.4.0 CVE-2025-32542 Patchstack
7.1 High WooCommerce Sales MIS Report Plugin woocommerce-mis-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 CVE-2025-32541 Patchstack
7.1 High Store Exporter Plugin woocommerce-exporter Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-32539 Patchstack
7.1 High Easy Post Duplicator Plugin easy-post-duplicator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-32538 Patchstack
7.1 High Lock Your Updates Plugin lock-your-updates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-32537 Patchstack
7.1 High HTML5 Video Player with Playlist Plugin html5-video-player-with-playlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.50 CVE-2025-32536 Patchstack
7.1 High Workbox Video from Vimeo & Youtube Plugin workbox-video-from-vimeo-youtube-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.2 CVE-2025-32534 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.24 Fixed in 1.6.25 CVE-2025-32525 Patchstack
7.1 High MyWorks WooCommerce Sync for QuickBooks Online Plugin myworks-woo-sync-for-quickbooks-online Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-32524 Patchstack
7.1 High WooCommerce – Payphone Gateway Plugin wc-payphone-gateway Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32523 Patchstack
8.1 High IDonate Plugin idonate Local File Inclusion No login needed ≤ 2.1.18 CVE-2025-32519 Patchstack
7.1 High MultiMailer Plugin scand-multi-mailer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-32517 Patchstack
7.5 High Simple WP Events Plugin simple-wp-events Arbitrary File Deletion No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32509 Patchstack
8.8 High Job Board Manager Plugin job-board-manager PHP Object Injection ≤ 2.1.61 CVE-2025-32144 Patchstack
8.8 High Accordion Plugin accordions PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-32143 Patchstack
7.1 High Insert HTML Here Plugin insert-html-here Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-31379 Patchstack
7.1 High Oppso Unit Converter Plugin oppso-unit-converter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-31378 Patchstack
7.5 High AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.5.5 CVE-2025-31041 Patchstack
8.1 High WP Food ordering and Restaurant Menu Plugin wp-food Local File Inclusion No login needed ≤ 2.7 CVE-2025-31040 Patchstack
7.1 High WP Hide Categories Plugin wp-hide-categories Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-31028 Patchstack
7.1 High Mobile Smart Plugin mobile-smart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v1.3.16 CVE-2025-31021 Patchstack
7.5 High WordPress SMTP Service, Email Delivery Solved! — MailHawk Plugin mailhawk Local File Inclusion No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-31015 Patchstack
7.5 High Material Dashboard Plugin material-dashboard Local File Inclusion ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31014 Patchstack
7.2 High SMTP for Amazon SES – YaySMTP Plugin smtp-amazon-ses Cross-Site Scripting YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed ≤ 1.8 CVE-2025-3434 Wordfence
8.1 High InstaWP Connect Plugin instawp-connect Local File Inclusion Unauthenticated Local PHP File Inclusion No login needed ≤ 0.1.0.85 CVE-2025-2636 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only