WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,901–5,950 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 119 of 345
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High TheGem Theme Elements (for WPBakery) Plugin thegem-elements Local File Inclusion No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62045 Patchstack
6.5 Medium TheGem Theme Elements (for WPBakery) Plugin thegem-elements Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62044 Patchstack
7.1 High TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62041 Patchstack
7.1 High YOP Poll Plugin yop-poll Cross-Site Scripting No login needed ≤ 6.5.37 Fixed in 6.5.38 CVE-2025-62040 Patchstack
7.5 High AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2025-62039 Patchstack
6.5 Medium MeetingHub Plugin meetinghub Information Disclosure Sensitive Data Exposure ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62038 Patchstack
6.5 Medium Togo Plugin togo Broken Access Control ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62037 Patchstack
7.1 High Togo Plugin togo Cross-Site Scripting No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62036 Patchstack
8.8 High Togo Plugin togo PHP Object Injection ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62035 Patchstack
8.8 High Togo Plugin togo Privilege Escalation ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62034 Patchstack
6.5 Medium Togo Plugin togo Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62033 Patchstack
6.5 Medium tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.2 CVE-2025-62032 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62031 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62030 Patchstack
4.3 Medium Salient Plugin salient Broken Access Control ≤ 17.4.0 Fixed in 17.4.0 CVE-2025-62028 Patchstack
5.3 Medium KALLYAS Theme kallyas Broken Access Control No login needed ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62018 Patchstack
5.4 Medium KALLYAS Theme kallyas Broken Access Control ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62017 Patchstack
9.9 Critical KALLYAS Theme kallyas Arbitrary File Upload ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62016 Patchstack
8.1 High ITok Plugin itok Local File Inclusion No login needed ≤ 1.1.42 Fixed in 1.1.43.1 CVE-2025-62014 Patchstack
6.5 Medium TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62012 Patchstack
6.5 Medium TheGem Plugin thegem Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62011 Patchstack
8.1 High Famita Plugin famita Local File Inclusion No login needed ≤ 1.54 Fixed in 1.55.1 CVE-2025-62010 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Local File Inclusion ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-60248 Patchstack
6.5 Medium Bux Woocommerce Plugin bux-woocommerce Broken Access Control No login needed ≤ 1.2.3 CVE-2025-60247 Patchstack
9.8 Critical WP User Manager Plugin wp-user-manager PHP Object Injection No login needed ≤ 2.9.12 Fixed in 2.9.13 CVE-2025-60245 Patchstack
7.1 High TableOn Plugin posts-table-filterable Content Injection No login needed ≤ 1.0.5.1 CVE-2025-60244 Patchstack
9.8 Critical Selling Commander for WooCommerce Plugin selling-commander-connector Privilege Escalation No login needed ≤ 1.2.46 CVE-2025-60243 Patchstack
7.5 High Download Counter Plugin download-counter Path Traversal Arbitrary File Download No login needed ≤ 1.4 CVE-2025-60242 Patchstack
7.5 High Premmerce Plugin premmerce Local File Inclusion No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-60241 Patchstack
7.5 High AnyComment Plugin anycomment Local File Inclusion No login needed ≤ 0.3.6 CVE-2025-60240 Patchstack
8.5 High CoSchool LMS Plugin coschool SQL Injection ≤ 1.4.3 CVE-2025-60239 Patchstack
10.0 Critical Support Ticket System for WooCommerce (Premium) Plugin support-ticket-system-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.7 CVE-2025-60235 Patchstack
10.0 Critical Custom User Registration Fields for WooCommerce Plugin user-registration-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 2.1.2 CVE-2025-60207 Patchstack
7.5 High WooCommerce Store Toolkit Plugin woocommerce-store-toolkit Local File Inclusion No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-60204 Patchstack
7.5 High Store Exporter Plugin woocommerce-exporter Local File Inclusion No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2025-60203 Patchstack
7.5 High Favorites Plugin favorites Local File Inclusion No login needed ≤ 2.3.6 CVE-2025-60202 Patchstack
7.5 High WP Customer Area Plugin customer-area Local File Inclusion No login needed < 8.3.4 Fixed in 8.3.4 CVE-2025-60201 Patchstack
7.5 High LearnPress Export Import Plugin learnpress-import-export Local File Inclusion No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2025-60200 Patchstack
8.1 High InHype - Blog & Magazine Plugin inhype Local File Inclusion Blog & Magazine WordPress Theme theme <= 1.5.2 - Local File Inclusion No login needed ≤ 1.5.2 CVE-2025-60199 Patchstack
8.1 High Saxon - Viral Content Blog & Magazine Marketing Plugin saxon Local File Inclusion Viral Content Blog & Magazine Marketing WordPress Theme theme <= 1.9.3 - Local File Inclusion No login needed ≤ 1.9.3 CVE-2025-60198 Patchstack
8.1 High Simple Contact Forms Plugin simple-contact-forms Local File Inclusion No login needed ≤ 1.6.4 CVE-2025-60197 Patchstack
7.5 High Clearblue® Ovulation Calculator Plugin clearblue-ovulation-calculator Local File Inclusion No login needed ≤ 1.2.4 CVE-2025-60196 Patchstack
9.8 Critical Atarim Plugin atarim-visual-collaboration Privilege Escalation No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60195 Patchstack
7.5 High Premmerce Product Search for WooCommerce Plugin premmerce-search Local File Inclusion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-60194 Patchstack
7.5 High Premmerce User Roles Plugin premmerce-user-roles Local File Inclusion No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-60193 Patchstack
7.5 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60192 Patchstack
7.5 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60191 Patchstack
8.1 High Immocaster Plugin immocaster Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-60190 Patchstack
7.5 High PoloPag – Pix Automático para Woocommerce Plugin wc-polo-payments Local File Inclusion Pix Automático para Woocommerce plugin <= 2.0.9 - Local File Inclusion No login needed ≤ 2.0.9 Fixed in 3.0.0 CVE-2025-60189 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60188 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only