WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,151–6,200 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 124 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Privilege Escalation Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 8.1 CVE-2025-1570 Wordfence
7.2 High Tabs for WooCommerce Plugin wc-tabs PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs ≤ 1.0.0 CVE-2024-13831 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
8.8 High Traveler Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.1.9 CVE-2024-12811 Wordfence
8.8 High Cardealer Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Update via update_user_profile No login needed ≤ 1.6.4 CVE-2025-1687 Wordfence
8.8 High Cardealer Theme Privilege Escalation Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation ≤ 1.6.4 CVE-2025-1682 Wordfence
7.1 High Woo Store Mode Plugin woo-store-mode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23687 Patchstack
7.6 High DefendWP Firewall Plugin defend-wp-firewall Broken Access Control ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-22280 Patchstack
8.8 High Car Dealer Automotive WordPress Theme – Responsive Theme Arbitrary File Deletion Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read ≤ 1.6.3 CVE-2025-1282 Wordfence
8.1 High Login Me Now Plugin login-me-now Authentication Bypass No login needed ≤ 1.7.2 CVE-2025-1717 Wordfence
7.1 High Bricksbuilder Theme Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave ≤ 1.9.6.1 CVE-2024-2297 Wordfence
8.8 High Templines Elementor Helper Core Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.7 CVE-2025-1295 Wordfence
7.1 High Simple Catalogue Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.2 CVE-2024-13633 WPScan
7.1 High WP Extra Fields Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1 CVE-2024-13632 WPScan
7.1 High OM Stripe Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 02.00.00 CVE-2024-13631 WPScan
7.1 High WPMovieLibrary Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.1.4.8 CVE-2024-13624 WPScan
7.1 High Post Timeline Plugin post-timeline Cross-Site Scripting Reflected XSS No login needed < 2.3.10 Fixed in 2.3.10 CVE-2024-13571 WPScan
7.1 High Custom Block Builder – Lazy Blocks Plugin lazy-blocks Cross-Site Scripting Lazy Blocks < 3.8.3 - Reflected XSS No login needed < 3.8.3 Fixed in 3.8.3 CVE-2024-12878 WPScan
7.1 High SimplePress Forum Plugin Cross-Site Scripting Reflected XSS No login needed < 6.10.11 Fixed in 6.10.11 CVE-2024-10483 WPScan
7.1 High Simple Certain Time to Show Content Plugin Cross-Site Scripting Reflected XSS No login needed < 1.3.1 Fixed in 1.3.1 CVE-2024-10152 WPScan
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-26993 Patchstack
7.1 High WPPizza Plugin wppizza Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.19.4 Fixed in 3.19.5 CVE-2025-26991 Patchstack
7.1 High Web Accessibility By accessiBe Plugin accessibe Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-26981 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2025-26979 Patchstack
7.6 High Poll Maker Plugin poll-maker SQL Injection ≤ 5.6.5 Fixed in 5.6.6 CVE-2025-26971 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion ≤ 4.0.20 Fixed in 4.0.21 CVE-2025-26964 Patchstack
7.5 High Affiliate Coupons Plugin affiliate-coupons Local File Inclusion ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-26957 Patchstack
7.6 High WP Yelp Review Slider Plugin wp-yelp-review-slider SQL Injection ≤ 8.1 Fixed in 8.2 CVE-2025-26946 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-26935 Patchstack
7.5 High ChatBot Plugin chatbot Local File Inclusion ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-26932 Patchstack
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
8.5 High Wishlist Plugin wishlist SQL Injection ≤ 1.0.41 Fixed in 1.0.42 CVE-2025-26915 Patchstack
7.5 High Mortgage Calculator Estatik Plugin estatik-mortgage-calculator Local File Inclusion ≤ 2.0.12 CVE-2025-26907 Patchstack
7.5 High Estatik Plugin estatik Local File Inclusion ≤ 4.3.0 CVE-2025-26905 Patchstack
7.1 High Fast Flow Plugin fast-flow-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.16 Fixed in 1.2.18 CVE-2025-26868 Patchstack
7.5 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Path Traversal Arbitrary File Download No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26753 Patchstack
8.6 High Broadcast Live Video Plugin videowhisper-live-streaming-integration Arbitrary File Deletion No login needed ≤ 6.2 Fixed in 6.2.1 CVE-2025-26752 Patchstack
7.1 High Alphabetic Pagination Plugin alphabetic-pagination Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-26751 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.25.17 Fixed in 3.25.18 CVE-2025-26987 Patchstack
8.1 High Majestic Support Plugin majestic-support Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-26985 Patchstack
7.5 High Yawave Plugin yawave SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.1 CVE-2025-1648 Wordfence
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
7.1 High 无觅相关文章插件 Plugin wumii-related-posts Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.5.7 CVE-2025-27352 Patchstack
7.1 High Smart Maintenance & Countdown Plugin smart-maintenance-countdown Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-27332 Patchstack
7.1 High Blightly Explorer Plugin blighty-explorer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.0 CVE-2025-27321 Patchstack
8.5 High WP Sitemap Plugin wp-sitemap SQL Injection ≤ 1.0 CVE-2025-27312 Patchstack
7.2 High NHR Options Table Manager Plugin nhrrob-options-table-manager PHP Object Injection Deserialization of untrusted data ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-27301 Patchstack
7.2 High ADFO Plugin admin-form PHP Object Injection Deserialization of untrusted data ≤ 1.9.1 CVE-2025-27300 Patchstack
8.3 High WP Video Posts Plugin wp-video-posts Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 3.5.1 CVE-2025-27298 Patchstack
7.6 High Bravo Search & Replace Plugin bravo-search-and-replace SQL Injection ≤ 1.0 CVE-2025-27297 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only