WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,751–5,800 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 116 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.31 Fixed in 2.2.32 CVE-2025-30829 Patchstack
7.5 High WishSuite Plugin wishsuite Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-30820 Patchstack
8.5 High Simple Giveaways Plugin giveasap SQL Injection ≤ 2.48.1 Fixed in 2.48.2 CVE-2025-30819 Patchstack
7.5 High The Post Grid Plugin the-post-grid Local File Inclusion ≤ 7.7.17 Fixed in 7.7.18 CVE-2025-30814 Patchstack
8.5 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm SQL Injection ≤ 3.0.1 Fixed in 3.1 CVE-2025-30810 Patchstack
8.5 High Vimeotheque Plugin codeflavors-vimeo-video-post-lite SQL Injection ≤ 2.3.4.2 Fixed in 2.3.4.3 CVE-2025-30806 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
7.5 High Subscribe to Download Lite Plugin subscribe-to-download-lite Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-30785 Patchstack
8.5 High WP Subscription Forms Plugin wp-subscription-forms SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-30784 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
8.5 High WPGuppy Plugin wpguppy-lite SQL Injection ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-30775 Patchstack
7.2 High TranslatePress Plugin translatepress-multilingual PHP Object Injection ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-30773 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 30.1 Fixed in 30.1 CVE-2025-27014 Patchstack
7.5 High Hostiko Plugin hostiko Local File Inclusion ≤ 30.1 Fixed in 30.1 CVE-2025-27015 Patchstack
8.5 High WP Google Calendar Manager Plugin wp-gcalendar SQL Injection ≤ 2.1 CVE-2025-28939 Patchstack
7.1 High Fancybox Plus Plugin fancybox-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-28935 Patchstack
7.1 High Simple Post Series Plugin simple-post-series Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-28934 Patchstack
7.1 High Are you robot google recaptcha Plugin are-you-robot-recaptcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-28928 Patchstack
7.1 High ZenphotoPress Plugin zenphotopress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-28924 Patchstack
7.1 High SpatialMatch IDX Plugin spatialmatch-free-lifestyle-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 CVE-2025-28921 Patchstack
7.1 High Custom Smilies Plugin custom-smilies-se Cross-Site Scripting No login needed ≤ 2.9.2 CVE-2025-28917 Patchstack
7.1 High Gravity 2 PDF Plugin gf2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28911 Patchstack
7.1 High Driving Directions Plugin ddirections Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2025-28903 Patchstack
7.1 High WP Event Ticketing Plugin wpeventticketing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 CVE-2025-28899 Patchstack
7.1 High Lightview Plus Plugin lightview-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28890 Patchstack
7.1 High Custom Product Stickers for Woocommerce Plugin custom-product-stickers-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 CVE-2025-28889 Patchstack
7.1 High Omnify Plugin omnify-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-28882 Patchstack
7.1 High Blue Captcha Plugin blue-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.4 Fixed in 2.0.0 CVE-2025-28880 Patchstack
7.1 High Key4ce osTicket Bridge Plugin key4ce-osticket-bridge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-28877 Patchstack
8.5 High Shuffle Theme shuffle SQL Injection ≤ 0.5 CVE-2025-28873 Patchstack
7.1 High NextGEN Gallery Voting Plugin nextgen-gallery-voting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 CVE-2025-28869 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.1 High Arrow Maps Plugin ap-google-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28858 Patchstack
7.1 High Teleport Plugin teleport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2025-28855 Patchstack
7.1 High Random Quotes Plugin random-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-27267 Patchstack
7.1 High TBTestimonials Plugin tb-testimonials Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-26584 Patchstack
7.1 High Video Share VOD Plugin video-share-vod Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2025-26583 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.1 High MicroPayments Plugin paid-membership Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-26579 Patchstack
7.1 High WP Simple Slideshow Plugin wp-simple-slideshow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26576 Patchstack
7.1 High Display Post Meta Plugin display-post-meta Cross-Site Scripting WordPress Display Post Meta plugin <= 1.5- Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-26575 Patchstack
7.1 High Rizzi Guestbook Plugin rizzi-guestbook Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-26573 Patchstack
7.1 High In Stock Mailer for WooCommerce Plugin in-stock-mailer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-26566 Patchstack
7.1 High GNUPress Plugin gnupress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-26565 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only