WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,051–6,100 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 122 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) Plugin oopspam-anti-spam Other Unauthenticated IP Header Spoofing No login needed ≤ 1.2.53 CVE-2025-12094 Wordfence
8.8 High WordPress User Extra Fields Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function ≤ 16.7 CVE-2025-7846 Wordfence
9.8 Critical Jobmonster - Job Board Theme Authentication Bypass Job Board WordPress Theme <= 4.8.1 - Authentication Bypass No login needed ≤ 4.8.1 CVE-2025-5397 Wordfence
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Broken Access Control WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation ≤ 1.1.23.0 CVE-2025-11975 Wordfence
5.3 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Broken Access Control Weglot <= 5.1 - Missing Authorization to Unauthenticated Limited Transient Deletion No login needed ≤ 5.1 CVE-2025-10008 Wordfence
5.9 Medium Premmerce User Roles Plugin premmerce-user-roles Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-64291 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
7.5 High Majestic Support Plugin majestic-support Local File Inclusion ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-64284 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-64283 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-64234 Patchstack
4.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.7 Fixed in 20.8.8 CVE-2025-64229 Patchstack
4.3 Medium SUMO Affiliates Pro Plugin affs Information Disclosure Sensitive Data Exposure ≤ 11.0.0 Fixed in 11.1.0 CVE-2025-64228 Patchstack
4.3 Medium Stockie Extra Plugin stockie-extra Cross-Site Request Forgery No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64226 Patchstack
6.5 Medium Rey Core Plugin rey-core Cross-Site Scripting ≤ 3.1.8 Fixed in 3.1.9 CVE-2025-64220 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Broken Access Control ≤ 6.4.18 Fixed in 6.4.19 CVE-2025-64219 Patchstack
7.5 High SmartMag Theme smart-mag Local File Inclusion ≤ 10.3.0 Fixed in 10.3.1 CVE-2025-64216 Patchstack
5.4 Medium MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64212 Patchstack
5.3 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-64211 Patchstack
5.4 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-64210 Patchstack
6.5 Medium Jannah - Extensions Plugin jannah-extensions Cross-Site Scripting Extensions plugin <= 1.1.4 - Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-64208 Patchstack
6.5 Medium SmartMag Theme smart-mag Cross-Site Scripting ≤ 10.3.1 Fixed in 10.3.2 CVE-2025-64204 Patchstack
6.5 Medium Sahifa Plugin sahifa Cross-Site Scripting ≤ 5.8.6 Fixed in 5.8.6 CVE-2025-64202 Patchstack
4.3 Medium PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.13.12 Fixed in 11.14 CVE-2025-64201 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-64200 Patchstack
5.3 Medium wpresidence Theme wpresidence Broken Access Control No login needed ≤ 5.3.2 Fixed in 5.3.2.1 CVE-2025-64199 Patchstack
6.5 Medium Rehub Plugin rehub-theme Cross-Site Scripting ≤ 19.9.9.1 Fixed in 19.9.9.1 CVE-2025-64197 Patchstack
7.5 High Eduma Plugin eduma Local File Inclusion ≤ 5.7.6 Fixed in 5.7.7 CVE-2025-64195 Patchstack
6.5 Medium Eduma Plugin eduma Cross-Site Scripting ≤ 5.7.6 Fixed in 5.7.7 CVE-2025-64194 Patchstack
7.1 High hpb seo Plugin hpbseo Cross-Site Request Forgery No login needed ≤ 3.0.1 CVE-2025-60075 Patchstack
4.3 Medium Super Store Finder Plugin superstorefinder-wp Cross-Site Request Forgery No login needed ≤ 7.5 CVE-2025-58939 Patchstack
5.3 Medium Blog Designer PRO Plugin blog-designer-pro Broken Access Control No login needed ≤ 3.4.8 CVE-2025-58711 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 10.0.2 Fixed in 10.0.3 CVE-2025-49042 Patchstack
5.3 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Broken Access Control Broken Access Control to Notice Dismissal No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-64296 Patchstack
5.3 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2025-57931 Patchstack
9.6 Critical CFDB7 Plugin contact-form-cfdb7 SQL Injection WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization… No login needed 0.0.0 – 1.3.2 Fixed in 1.3.3 CVE-2025-4665 Mandiant
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Cross-Site Scripting ≤ 3.21.1 Fixed in 3.21.1 CVE-2025-48088 Patchstack
4.3 Medium Entrada Theme entrada Cross-Site Request Forgery No login needed ≤ 5.7.7 CVE-2025-58918 Patchstack
4.9 Medium Slider Templates Plugin slider-templates Server-Side Request Forgery ≤ 1.0.3 CVE-2025-62988 Patchstack
6.5 Medium Builderall Builder Plugin builderall-cheetah-for-wp Cross-Site Scripting ≤ 3.0.1 CVE-2025-62987 Patchstack
7.1 High FanBridge signup Plugin fanbridge-signup Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-62986 Patchstack
6.5 Medium Simple Pull Quote Plugin simple-pull-quote Cross-Site Scripting ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-62985 Patchstack
6.5 Medium WP AdCenter Plugin wpadcenter Cross-Site Scripting ≤ 2.6.1 CVE-2025-62984 Patchstack
6.5 Medium Posts By Tag Plugin posts-by-tag Cross-Site Scripting ≤ 3.2.1 CVE-2025-62983 Patchstack
5.9 Medium Dynamic User Directory Plugin dynamic-user-directory Cross-Site Scripting ≤ 2.3 Fixed in 2.4 CVE-2025-62982 Patchstack
4.7 Medium WP Gravity Forms Zoho CRM and Bigin Plugin gf-zoho Open Redirect No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-62981 Patchstack
5.4 Medium Persian Admnin Fonts Plugin persian-admin-fonts Broken Access Control ≤ 4.1.03 Fixed in 4.1.05 CVE-2025-62980 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only