WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.0 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2025-68015 Patchstack
10.0 Critical g-FFL Checkout Plugin g-ffl-checkout Arbitrary File Upload No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-68001 Patchstack
9.9 Critical Real Homes CRM Plugin realhomes-crm Arbitrary File Upload ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-67968 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution Arbitrary Code Execution ≤ 8.1.8 Fixed in 8.2.0 CVE-2025-67944 Patchstack
9.8 Critical Consult Aid Plugin consultaid PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-67617 Patchstack
9.9 Critical News Event Plugin news-event Arbitrary File Upload ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-62056 Patchstack
9.9 Critical Blogmatic Plugin blogmatic Arbitrary File Upload ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-62050 Patchstack
10.0 Critical Energia Plugin energia Arbitrary File Upload No login needed ≤ 1.1.2 CVE-2025-50002 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection No login needed ≤ 2.5 CVE-2025-49055 Patchstack
9.8 Critical Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy Privilege Escalation WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.5.0 CVE-2025-15521 Wordfence
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed 2.5.2 – < 2.6.0 Fixed in 2.6.0 CVE-2026-23800 Patchstack
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-23550 Patchstack
9.3 Critical Automotive Listings Plugin automotive SQL Injection No login needed ≤ 18.6 Fixed in 18.7 CVE-2025-67928 Patchstack
9.9 Critical Corpkit Theme corpkit Arbitrary File Upload ≤ 2.0 Fixed in 2.0.1 CVE-2025-67924 Patchstack
9.8 Critical Newsletters Plugin newsletters-lite PHP Object Injection No login needed ≤ 4.11 Fixed in 4.12 CVE-2025-67911 Patchstack
9.1 Critical Contentstudio Plugin contentstudio Arbitrary File Upload ≤ 1.3.7 Fixed in 1.4.0 CVE-2025-67910 Patchstack
9.3 Critical Felan Framework Plugin felan-framework SQL Injection No login needed ≤ 1.1.3 CVE-2025-23993 Patchstack
9.8 Critical Felan Framework Plugin felan-framework Privilege Escalation Account Takeover No login needed ≤ 1.1.3 CVE-2025-23504 Patchstack
9.8 Critical DZS Video Gallery Plugin dzs-videogallery PHP Object Injection No login needed ≤ 12.37 CVE-2025-47552 Patchstack
9.3 Critical WPCHURCH Plugin church-management SQL Injection No login needed ≤ 2.7.0 CVE-2025-32303 Patchstack
9.9 Critical Themify Sidepane Theme sidepane Arbitrary File Upload Arbitrary File Upload Vulnerability in WordPress themes by Themify ≤ 1.9.8, ≤ 1.9.9, ≤ 1.9.6, … CVE-2025-30996 Patchstack
9.8 Critical InWave Jobs Plugin iwjob Broken Access Control No login needed ≤ 3.5.8 CVE-2025-39477 Patchstack
9.3 Critical Entrada Theme entrada SQL Injection No login needed ≤ 5.7.7 CVE-2025-39484 Patchstack
9.1 Critical Media File Renamer Plugin media-file-renamer Remote Code Execution Arbitrary File Rename lead to RCE ≤ 5.7.7 Fixed in 5.7.8 CVE-2023-50897 Patchstack
9.3 Critical Infility Global Plugin infility-global SQL Injection No login needed ≤ 2.15.06 CVE-2025-68865 Patchstack
9.9 Critical Shopo Theme shopo Arbitrary File Upload ≤ 1.1.4 CVE-2025-31048 Patchstack
9.3 Critical Amazon Native Shopping Recommendations Plugin woozone-contextual SQL Injection No login needed ≤ 1.3 CVE-2025-30633 Patchstack
9.6 Critical WING WordPress Migrator Plugin wing-migrator Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 2.0.0 CVE-2025-52835 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.7.3 Fixed in 8.7.4 CVE-2025-68562 Patchstack
9.8 Critical Mobile builder Plugin mobile-builder Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 CVE-2025-68860 Patchstack
9.9 Critical IF AS Shortcode Plugin if-as-shortcode Remote Code Execution ≤ 1.2 CVE-2025-68897 Patchstack
9.8 Critical Tuturn Plugin tuturn Authentication Bypass Broken Authentication No login needed < 3.6 Fixed in 3.6 CVE-2025-64236 Patchstack
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
9.0 Critical WP Webhooks Plugin wp-webhooks Arbitrary File Upload No login needed ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66074 Patchstack
9.9 Critical Motors Theme motors Arbitrary File Upload ≤ 5.6.81 Fixed in 5.6.82 CVE-2025-64374 Patchstack
9.8 Critical Codiqa Theme codiqa PHP Object Injection No login needed ≤ 1.2.8 Fixed in 1.2.8 CVE-2025-64233 Patchstack
9.9 Critical WordPress Contact Form 7 PDF, Google Sheet & Database Plugin rtwwcfp-wordpress-contact-form-7-pdf Arbitrary File Upload ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64231 Patchstack
9.8 Critical Client Invoicing by Sprout Invoices Plugin sprout-invoices PHP Object Injection No login needed ≤ 20.8.7 Fixed in 20.8.8 CVE-2025-64227 Patchstack
9.8 Critical Jannah Plugin jannah PHP Object Injection No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64206 Patchstack
9.8 Critical Soledad Theme soledad Privilege Escalation No login needed ≤ 8.6.9 Fixed in 8.6.9.1 CVE-2025-64188 Patchstack
9.8 Critical WP Gravity Forms Salesforce Plugin gf-salesforce-crmperks PHP Object Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-60180 Patchstack
9.8 Critical WP Gravity Forms HubSpot Plugin gf-hubspot PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60178 Patchstack
9.8 Critical WP Gravity Forms Constant Contact Plugin gf-constant-contact PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-60174 Patchstack
9.8 Critical WP Gravity Forms Zoho CRM and Bigin Plugin gf-zoho PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-60091 Patchstack
9.8 Critical WP Gravity Forms Insightly Plugin gf-insightly PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-60090 Patchstack
9.8 Critical WP Gravity Forms FreshDesk Plugin gf-freshdesk PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-60089 Patchstack
9.3 Critical tPlayer Plugin tplayer-html5-audio-player-with-playlist SQL Injection No login needed ≤ 1.2.1.6 CVE-2025-60062 Patchstack
9.3 Critical Advance Seat Reservation Management for WooCommerce Plugin scw-seat-reservation SQL Injection No login needed ≤ 3.1 CVE-2025-58951 Patchstack
9.8 Critical DentiCare Plugin denticare PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.3 CVE-2025-54723 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only