WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical EasyEat Theme easyeat Local File Inclusion No login needed ≤ 1.9.0 CVE-2025-53433 Patchstack
9.8 Critical Fox LMS – WordPress LMS Plugin fox-lms Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed 1.0.4.7 – 1.0.5.1 CVE-2025-14156 Wordfence
9.8 Critical URL Shortener Plugin exact-links SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.0.7 CVE-2025-10738 Wordfence
9.8 Critical ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.1 CVE-2025-11456 Wordfence
9.8 Critical EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin easycommerce Privilege Escalation AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 - Unauthenticated Privilege Escalation No login needed ≤ 1.8.2 CVE-2025-11457 Wordfence
10.0 Critical King Addons for Elementor Plugin king-addons Arbitrary File Upload No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6327 Patchstack
9.8 Critical King Addons for Elementor Plugin king-addons Privilege Escalation No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6325 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Arbitrary File Upload ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-62065 Patchstack
9.8 Critical Search & Go Plugin search-and-go Authentication Bypass Broken Authentication No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-62064 Patchstack
9.9 Critical Case Addons Plugin case-addons Arbitrary File Upload ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-62047 Patchstack
9.9 Critical KALLYAS Theme kallyas Arbitrary File Upload ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62016 Patchstack
9.8 Critical WP User Manager Plugin wp-user-manager PHP Object Injection No login needed ≤ 2.9.12 Fixed in 2.9.13 CVE-2025-60245 Patchstack
9.8 Critical Selling Commander for WooCommerce Plugin selling-commander-connector Privilege Escalation No login needed ≤ 1.2.46 CVE-2025-60243 Patchstack
10.0 Critical Support Ticket System for WooCommerce (Premium) Plugin support-ticket-system-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.7 CVE-2025-60235 Patchstack
10.0 Critical Custom User Registration Fields for WooCommerce Plugin user-registration-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 2.1.2 CVE-2025-60207 Patchstack
9.8 Critical Atarim Plugin atarim-visual-collaboration Privilege Escalation No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60195 Patchstack
9.8 Critical s2Member Plugin s2member PHP Object Injection No login needed ≤ 250701 Fixed in 250905 CVE-2025-58998 Patchstack
9.1 Critical Advanced Settings Plugin advanced-settings Arbitrary File Upload ≤ 3.1.1 Fixed in 3.2.0 CVE-2025-58996 Patchstack
9.8 Critical WP Gravity Forms Keap/Infusionsoft Plugin gf-infusionsoft PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-58636 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2025-58627 Patchstack
10.0 Critical Drop Uploader for CF7 - Drag&Drop File Uploader Addon Plugin drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon Arbitrary File Upload Drag&Drop File Uploader Addon Plugin <= 2.4.1 - Arbitrary File Upload No login needed ≤ 2.4.1 CVE-2025-53283 Patchstack
9.8 Critical Seil Theme seil PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.7.1 CVE-2025-53242 Patchstack
9.3 Critical HieCOR Payment Gateway Plugin hcv4-payment-gateway SQL Injection No login needed ≤ 1.5.11 Fixed in 2.0.0 CVE-2025-52773 Patchstack
9.8 Critical Sign-up Sheets Plugin sign-up-sheets PHP Object Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-49393 Patchstack
10.0 Critical HAPPY Plugin happy-helpdesk-support-ticket-system Remote Code Execution No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49372 Patchstack
9.3 Critical Education WordPress Theme | HiStudy Theme histudy SQL Injection No login needed ≤ 3.1.0 Fixed in 3.1.0 CVE-2025-48089 Patchstack
9.1 Critical Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Remote Code Execution Arbitrary Code Execution ≤ 4.5.9 Fixed in 4.5.10 CVE-2025-47588 Patchstack
9.9 Critical Widget Logic Plugin widget-logic Remote Code Execution ≤ 6.0.5 Fixed in 6.0.6 CVE-2025-32222 Patchstack
9.8 Critical Jobmonster - Job Board Theme Authentication Bypass Job Board WordPress Theme <= 4.8.1 - Authentication Bypass No login needed ≤ 4.8.1 CVE-2025-5397 Wordfence
9.6 Critical CFDB7 Plugin contact-form-cfdb7 SQL Injection WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization… No login needed 0.0.0 – 1.3.2 Fixed in 1.3.3 CVE-2025-4665 Mandiant
9.1 Critical Paid Videochat Turnkey Site Plugin ppv-live-webcams Remote Code Execution ≤ 7.3.23 Fixed in 7.3.24 CVE-2025-62959 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-62025 Patchstack
9.0 Critical s2Member Plugin s2member Remote Code Execution No login needed ≤ 250905 Fixed in 251005 CVE-2025-62023 Patchstack
9.8 Critical UNIVERSAM Plugin universam-demo PHP Object Injection No login needed ≤ 9.04.02 CVE-2025-60238 Patchstack
9.8 Critical KBx Pro Ultimate Plugin knowledgebase-helpdesk-pro PHP Object Injection No login needed ≤ 8.0.5 CVE-2025-60232 Patchstack
9.8 Critical White Rabbit Theme whiterabbit PHP Object Injection No login needed ≤ 1.5.2 CVE-2025-60226 Patchstack
9.8 Critical BugsPatrol Theme bugspatrol PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60225 Patchstack
9.8 Critical Subscribe to Download Plugin subscribe-to-download PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60224 Patchstack
9.8 Critical Captivate Sync Plugin captivatesync-trade PHP Object Injection No login needed ≤ 3.0.3 Fixed in 3.2.2 CVE-2025-60221 Patchstack
9.8 Critical CouponXxL Plugin couponxxl Privilege Escalation No login needed ≤ 3.0.0 CVE-2025-60220 Patchstack
9.8 Critical Addison Plugin addison PHP Object Injection No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2025-60216 Patchstack
9.8 Critical Goldenblatt Plugin goldenblatt PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-60214 Patchstack
9.8 Critical Scape Plugin scape PHP Object Injection No login needed ≤ 1.5.13 CVE-2025-60213 Patchstack
9.8 Critical Everest Forms - Frontend Listing Plugin everest-forms-frontend-listing PHP Object Injection Frontend Listing plugin <= 1.0.5 - PHP Object Injection No login needed ≤ 1.0.5 CVE-2025-60210 Patchstack
9.8 Critical Connector for Gravity Forms and Google Sheets Plugin wp-gravity-forms-spreadsheets PHP Object Injection No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60209 Patchstack
10.0 Critical Alone Plugin alone Remote Code Execution No login needed ≤ 7.8.3 CVE-2025-60206 Patchstack
9.8 Critical Noisa Plugin noisa PHP Object Injection No login needed ≤ 2.6.0 Fixed in 2.6.3 CVE-2025-60039 Patchstack
9.3 Critical Learts Addons Plugin learts-addons SQL Injection No login needed ≤ 1.7.5 Fixed in 1.7.5 CVE-2025-59557 Patchstack
9.8 Critical TF Woo Product Grid Addon For Elementor Plugin tf-woo-product-grid PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.0.1 CVE-2025-59007 Patchstack
10.0 Critical Medcity Plugin medcity Arbitrary File Upload No login needed ≤ 1.1.9 Fixed in 1.1.9 CVE-2025-58963 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only