WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,851–5,900 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 118 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium YOP Poll Plugin yop-poll Broken Access Control No login needed ≤ 6.5.38 Fixed in 6.5.39 CVE-2025-64370 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control ≤ 1.3.58 Fixed in 1.3.59 CVE-2025-64369 Patchstack
6.5 Medium Analytics Germanized for Google Analytics Plugin ga-germanized Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-64292 Patchstack
5.3 Medium ChatBot Plugin chatbot Broken Access Control No login needed ≤ 7.3.9 Fixed in 7.4.0 CVE-2025-64277 Patchstack
6.5 Medium Survey Maker Plugin survey-maker Broken Access Control ≤ 5.1.9.4 Fixed in 5.1.9.5 CVE-2025-64276 Patchstack
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.17 Fixed in 2.1.18 CVE-2025-64275 Patchstack
4.3 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Broken Access Control ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-64274 Patchstack
4.3 Medium WP Plugin Manager Plugin wp-plugin-manager Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-64271 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Broken Access Control ≤ 1.2.150 Fixed in 1.2.151 CVE-2025-64269 Patchstack
4.3 Medium WooCommerce Ultimate Points And Rewards Plugin woocommerce-ultimate-points-and-rewards Information Disclosure Sensitive Data Exposure ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-64267 Patchstack
4.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control ≤ 23.2 Fixed in 23.3 CVE-2025-64265 Patchstack
5.9 Medium Popup addon for Ninja Forms Plugin popup-addon-for-ninja-forms Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-64264 Patchstack
5.4 Medium WP Content Pilot Plugin wp-content-pilot Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2025-64263 Patchstack
6.5 Medium Auto Prune Posts Plugin auto-prune-posts Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64262 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack
5.3 Medium Theater Plugin theatre Broken Access Control No login needed ≤ 0.18.8 Fixed in 0.19 CVE-2025-64259 Patchstack
6.4 Medium WordPress Content Flipper Plugin wp-flipper Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11769 Wordfence
6.4 Medium Angel – Fashion Model Agency WordPress CMS Theme Cross-Site Scripting Fashion Model Agency WordPress CMS Theme <= 3.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.2.3 CVE-2025-10295 Wordfence
8.8 High Import any XML, CSV or Excel File to WordPress (WP All Import) Plugin wp-all-import Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Conditional Logic ≤ 3.9.6 CVE-2025-12733 Wordfence
7.6 High 0 Day Analytics Plugin 0-day-analytics SQL Injection ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-64293 Patchstack
4.3 Medium WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer Broken Access Control Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure ≤ 7.33 CVE-2025-12732 Wordfence
6.4 Medium Live Photos on Plugin live-photos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.1 CVE-2025-12651 Wordfence
9.8 Critical EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin easycommerce Privilege Escalation AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 - Unauthenticated Privilege Escalation No login needed ≤ 1.8.2 CVE-2025-11457 Wordfence
6.4 Medium Nonaki – Drag and Drop Email Template builder and Newsletter Plugin nonaki-email-template-customizer Cross-Site Scripting Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields ≤ 1.0.11 CVE-2025-12644 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion ≤ 1.11.0 CVE-2025-11448 Wordfence
7.2 High Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy PHP Object Injection WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' ≤ 3.3.8 CVE-2025-12099 Wordfence
8.1 High Alloggio - Hotel Booking Theme alloggio Local File Inclusion Hotel Booking Theme theme <= 1.8 - Local File Inclusion No login needed ≤ 1.8 CVE-2025-64287 Patchstack
7.1 High Import from YML Plugin import-from-yml Cross-Site Scripting No login needed ≤ 3.1.17 Fixed in 4.0.0 CVE-2025-64232 Patchstack
7.1 High Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-64224 Patchstack
7.1 High Easy Social Share Buttons Plugin easy-social-share-buttons3 Cross-Site Scripting No login needed ≤ 10.7.1 Fixed in 10.7.1 CVE-2025-64198 Patchstack
7.1 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting No login needed ≤ 7.2.5 Fixed in 7.2.6 CVE-2025-64196 Patchstack
10.0 Critical King Addons for Elementor Plugin king-addons Arbitrary File Upload No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6327 Patchstack
9.8 Critical King Addons for Elementor Plugin king-addons Privilege Escalation No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6325 Patchstack
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Broken Access Control ≤ 1.2.1 CVE-2025-62914 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62076 Patchstack
7.5 High Simple Payment Plugin simple-payment Local File Inclusion No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62075 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting No login needed ≤ 11.71 Fixed in 11.72 CVE-2025-62074 Patchstack
8.1 High Savory Plugin savory Local File Inclusion No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-62067 Patchstack
7.5 High Revolution Plugin revolution Local File Inclusion ≤ 2.5.8 Fixed in 2.5.8 CVE-2025-62066 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Arbitrary File Upload ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-62065 Patchstack
9.8 Critical Search & Go Plugin search-and-go Authentication Bypass Broken Authentication No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-62064 Patchstack
7.1 High SureRank Plugin surerank Cross-Site Scripting No login needed ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-62059 Patchstack
7.1 High Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62057 Patchstack
8.1 High Academist Theme academist Local File Inclusion No login needed ≤ 1.3 Fixed in 1.3 CVE-2025-62055 Patchstack
8.1 High Houzez Plugin houzez Local File Inclusion No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62053 Patchstack
6.5 Medium UDesign Core Plugin u-design-core Cross-Site Scripting ≤ 4.14.1 Fixed in 4.14.2 CVE-2025-62051 Patchstack
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control No login needed ≤ 3.5.32 Fixed in 3.5.33 CVE-2025-62049 Patchstack
9.9 Critical Case Addons Plugin case-addons Arbitrary File Upload ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-62047 Patchstack
6.5 Medium TheGem Demo Import (for WPBakery) Plugin thegem-importer Broken Access Control Arbitrary Content Deletion ≤ 5.10.5 Fixed in 5.10.5.2 CVE-2025-62046 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only