WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,701–5,750 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 115 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High SoJ Soundslides Plugin soj-soundslides Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2.2 CVE-2025-2249 Wordfence
8.8 High Inline Image Upload for BBPress Plugin image-upload-for-bbpress Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.1.19 CVE-2025-2006 Wordfence
7.3 High So-Called Air Quotes Plugin so-called-air-quotes Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.1 CVE-2025-2803 Wordfence
7.1 High GlobalPayments WooCommerce Plugin global-payments-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2025-22767 Patchstack
7.1 High SUPER RESPONSIVE SLIDER Plugin super-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22575 Patchstack
7.1 High ULTIMATE VIDEO GALLERY Plugin ultimate-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22566 Patchstack
7.1 High Improve My City Plugin improve-my-city Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-22501 Patchstack
7.1 High WP Azure offload Plugin wp-azure-offload Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-22360 Patchstack
7.1 High Stencies Plugin stencies Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.58 CVE-2025-22356 Patchstack
8.1 High GetShop ecommerce Plugin getshop-ecommerce Path Traversal No login needed ≤ 1.3 CVE-2024-54362 Patchstack
8.6 High PluginPass Plugin pluginpass-pro-plugintheme-licensing Path Traversal Arbitrary File Download/Delete No login needed ≤ 0.9.10 CVE-2024-54291 Patchstack
7.1 High Já-Já Pagamentos for WooCommerce Plugin wc-ja-ja-pagamentos-multicaixa-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51624 Patchstack
7.5 High Pop-Up Chop Chop Plugin pop-up Local File Inclusion ≤ 2.1.7 CVE-2025-31432 Patchstack
7.1 High Microblog Poster Plugin microblog-poster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.6 CVE-2025-31435 Patchstack
7.1 High KK I Like It Plugin kk-i-like-it Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.5.3 CVE-2025-31443 Patchstack
7.1 High Terms of Use Plugin terms-of-use-2 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.0 CVE-2025-31440 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
7.1 High The Visitor Counter Plugin the-visitor-counter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4.3 CVE-2025-31449 Patchstack
7.1 High Video Embedder Plugin video-embedder Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.7.1 Fixed in 1.8 CVE-2025-31458 Patchstack
7.1 High Login Alert Plugin login-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.1 CVE-2025-31459 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
8.5 High Duplicate Page and Post Plugin duplicate-post-and-page SQL Injection ≤ 1.0 CVE-2025-31466 Patchstack
8.8 High Administrator Z Plugin administrator-z Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 2025.03.24 CVE-2025-2815 Wordfence
7.6 High Slider by BestWebSoft Plugin slider-bws SQL Injection ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-31099 Patchstack
7.1 High Hostel Plugin hostel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5.5 Fixed in 1.1.5.6 CVE-2025-31102 Patchstack
7.5 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion No login needed ≤ 1.3.8.8 CVE-2025-2485 Wordfence
8.8 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Deletion No login needed ≤ 1.3.8.7 CVE-2025-2328 Wordfence
8.2 High Traveler Plugin traveler Broken Access Control No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26733 Patchstack
7.1 High MemberSpace Plugin memberspace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2025-26874 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.6.4 Fixed in 1.3.6.5 CVE-2025-26890 Patchstack
7.6 High Traveler Plugin traveler Broken Access Control ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26956 Patchstack
8.5 High SEO Plugin by Squirrly SEO Plugin squirrly-seo SQL Injection ≤ 12.4.03 Fixed in 12.4.06 CVE-2025-22783 Patchstack
7.1 High Filled In Plugin filled-in Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-22628 Patchstack
7.6 High Payment Forms for Paystack Plugin payment-forms-for-paystack SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-22652 Patchstack
7.1 High Listings for Appfolio Plugin listings-for-appfolio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22658 Patchstack
7.1 High Secret Meta Plugin facebook-secret-meta Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-25086 Patchstack
7.1 High Cazamba Plugin cazamba Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25100 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.9.9.7 Fixed in 4.9.9.8 CVE-2025-30921 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
7.5 High WpEvently Plugin mage-eventpress PHP Object Injection ≤ 4.2.9 Fixed in 4.3.0 CVE-2025-30895 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager Local File Inclusion ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30891 Patchstack
7.5 High Login Widget for Ultimate Member Plugin login-widget-for-ultimate-member Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-30890 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.8.9 Fixed in 1.9.0 CVE-2025-30879 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-30871 Patchstack
7.5 High Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.23 Fixed in 2.2.0 CVE-2025-30868 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
8.8 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-30846 Patchstack
7.5 High The Pack Elementor addons Plugin the-pack-addon Local File Inclusion ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30845 Patchstack
7.6 High bizcalendar-web Plugin bizcalendar-web SQL Injection ≤ 1.1.0.34 Fixed in 1.1.0.35 CVE-2025-30843 Patchstack
7.5 High Themify Event Post Plugin themify-event-post Local File Inclusion ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-30831 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only