WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,001–6,050 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 121 of 345
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Sign-up Sheets Plugin sign-up-sheets PHP Object Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-49393 Patchstack
7.1 High Cookie Notice & Consent Plugin cookie-notice-consent Cross-Site Scripting No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-49390 Patchstack
8.8 High Preserve Code Formatting Plugin preserve-code-formatting PHP Object Injection ≤ 4.0.1 Fixed in 5.0 CVE-2025-49386 Patchstack
10.0 Critical HAPPY Plugin happy-helpdesk-support-ticket-system Remote Code Execution No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49372 Patchstack
7.5 High Real Time Validation for Gravity Forms Plugin real-time-validation-for-gravity-forms Local File Inclusion No login needed ≤ 1.7.0 CVE-2025-48330 Patchstack
8.1 High Kinsley Plugin kinsley Local File Inclusion No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-48290 Patchstack
8.1 High Blanka - One Page Plugin blanka-wp Local File Inclusion One Page WordPress Theme Theme < 1.5 - Local File Inclusion No login needed ≤ 1.5 CVE-2025-48090 Patchstack
9.3 Critical Education WordPress Theme | HiStudy Theme histudy SQL Injection No login needed ≤ 3.1.0 Fixed in 3.1.0 CVE-2025-48089 Patchstack
5.5 Medium Ajax Search Lite Plugin ajax-search-lite PHP Object Injection ≤ 4.13.3 Fixed in 4.13.4 CVE-2025-48086 Patchstack
7.1 High Simple Stripe Plugin simple-stripe Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.9.17 CVE-2025-48085 Patchstack
7.1 High wpNamedUsers Plugin wpnamedusers Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.5 CVE-2025-48083 Patchstack
7.1 High Slick Google Map Plugin slick-google-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.3 CVE-2025-48078 Patchstack
7.1 High Block Country Plugin block-country Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48077 Patchstack
9.1 Critical Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Remote Code Execution Arbitrary Code Execution ≤ 4.5.9 Fixed in 4.5.10 CVE-2025-47588 Patchstack
8.1 High Modal Survey Plugin modal-survey Local File Inclusion No login needed ≤ 2.0.2.0.1 CVE-2025-39468 Patchstack
8.1 High Wanderland Plugin wanderland Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2025-39467 Patchstack
8.1 High Dør Plugin dor Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4.1 CVE-2025-39466 Patchstack
4.3 Medium Advanced Google Maps Plugin wp-google-map-gold Broken Access Control ≤ 5.8.4 Fixed in 5.8.5 CVE-2025-39465 Patchstack
7.5 High Dessau Plugin dessau Local File Inclusion ≤ 1.9 Fixed in 1.9 CVE-2025-39463 Patchstack
9.9 Critical Widget Logic Plugin widget-logic Remote Code Execution ≤ 6.0.5 Fixed in 6.0.6 CVE-2025-32222 Patchstack
7.1 High replyMail Plugin replymail Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-31029 Patchstack
8.5 High smart SEO Theme smartseo SQL Injection ≤ 4.0 CVE-2025-28953 Patchstack
4.1 Medium Smush Image Compression and Optimization Plugin wp-smushit Path Traversal Directory Traversal ≤ 3.17.0 Fixed in 3.17.1 CVE-2025-22288 Patchstack
4.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 3.6.4.1 CVE-2025-12469 Wordfence
5.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.6.4.1 CVE-2025-12468 Wordfence
7.5 High File Manager for Google Drive – Integrate Google Drive with Plugin integrate-google-drive Information Disclosure Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure No login needed ≤ 1.5.3 CVE-2025-12139 Wordfence
6.1 Medium SMS Plugin sms4wp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2025-12580 Wordfence
4.4 Medium Multi-language Responsive Portfolio Plugin bootstrap-multi-language-responsive-portfolio Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11753 Wordfence
6.4 Medium TablePress – Tables in WordPress made easy Plugin tablepress Cross-Site Scripting Tables in WordPress made easy <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.2.4 CVE-2025-12324 Wordfence
5.3 Medium WP Snow Effect Plugin wp-snow-effect Broken Access Control No login needed ≤ 1.1.19 CVE-2025-64294 Patchstack
4.9 Medium Import WP – Export and Import CSV and XML files to Plugin jc-importer Path Traversal Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read ≤ 2.14.16 CVE-2025-12137 Wordfence
5.3 Medium Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages Plugin wplegalpages Broken Access Control Missing Authorization to Unauthenticated API Disconnect No login needed ≤ 3.5.1 CVE-2025-11816 Wordfence
5.4 Medium Bard Theme bardwp Cross-Site Request Forgery No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64368 Patchstack
6.5 Medium Groundhogg Plugin groundhogg Cross-Site Scripting ≤ 4.2.6 Fixed in 4.2.6.1 CVE-2025-64367 Patchstack
7.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection ≤ 3.6.27 Fixed in 3.6.28 CVE-2025-64366 Patchstack
6.5 Medium Ohio Extra Plugin ohio-extra Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-64365 Patchstack
7.5 High Masterstudy Theme masterstudy Local File Inclusion ≤ 4.8.126 Fixed in 4.8.126 CVE-2025-64364 Patchstack
7.5 High Kleo Plugin kleo Local File Inclusion ≤ 5.5.0 Fixed in 5.5.0 CVE-2025-64363 Patchstack
6.5 Medium K Elements Plugin k-elements Cross-Site Scripting ≤ 5.5.0 Fixed in 5.5.0 CVE-2025-64362 Patchstack
6.5 Medium Consulting Elementor Widgets Plugin consulting-elementor-widgets Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-64361 Patchstack
7.5 High Consulting Elementor Widgets Plugin consulting-elementor-widgets Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-64360 Patchstack
7.5 High Consulting Theme consulting Local File Inclusion ≤ 6.7.5 Fixed in 6.7.5 CVE-2025-64359 Patchstack
4.3 Medium Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-64358 Patchstack
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-64357 Patchstack
4.3 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Broken Access Control ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64356 Patchstack
6.5 Medium Gutenberg Plugin gutenberg Cross-Site Scripting ≤ 21.8.2 Fixed in 21.9.0 CVE-2025-64354 Patchstack
8.8 High Polylang Plugin polylang PHP Object Injection Deserialization of untrusted data ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-64353 Patchstack
2.7 Low Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control ≤ 6.2.4 Fixed in 6.3.0 CVE-2025-64352 Patchstack
4.3 Medium Rank Math SEO Plugin seo-by-rank-math Information Disclosure Sensitive Data Exposure ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64351 Patchstack
3.8 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64350 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only