WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,201–6,250 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 125 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium MeetingHub Plugin meetinghub Broken Access Control ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62073 Patchstack
4.3 Medium Front End Users Plugin front-end-only-users Broken Access Control ≤ 3.2.33 Fixed in 3.2.34 CVE-2025-62072 Patchstack
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.29 Fixed in 5.30 CVE-2025-62071 Patchstack
4.3 Medium WowRevenue Plugin revenue Broken Access Control ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62070 Patchstack
6.5 Medium MDTF Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting ≤ 1.3.3.8 Fixed in 1.3.3.9 CVE-2025-62069 Patchstack
6.5 Medium e2pdf Plugin e2pdf Cross-Site Scripting ≤ 1.28.09 Fixed in 1.28.10 CVE-2025-62068 Patchstack
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-62063 Patchstack
5.3 Medium Easy Post Submission Plugin easy-post-submission Information Disclosure Sensitive Data Exposure ≤ 1.7.0 Fixed in 2.0.0 CVE-2025-62062 Patchstack
4.3 Medium Product Catalog Simple Plugin post-type-x Cross-Site Request Forgery No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-62061 Patchstack
6.5 Medium Tab Ultimate Plugin tabs-pro Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-62060 Patchstack
6.5 Medium Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62058 Patchstack
7.5 High Houzez Theme - Functionality Plugin houzez-theme-functionality Local File Inclusion Functionality plugin <= 4.1.8 - Local File Inclusion ≤ 4.1.8 Fixed in 4.2.0 CVE-2025-62054 Patchstack
4.3 Medium One Page Express Companion Plugin one-page-express-companion Broken Access Control ≤ 1.6.43 Fixed in 1.6.44 CVE-2025-62052 Patchstack
5.4 Medium SmartCrawl Plugin smartcrawl-seo Broken Access Control ≤ 3.14.3 Fixed in 3.14.4 CVE-2025-62048 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.10.3 Fixed in 5.10.4 CVE-2025-62042 Patchstack
8.1 High Grevo Theme grevo Local File Inclusion No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-62029 Patchstack
5.4 Medium Event Tickets Plugin event-tickets Broken Access Control ≤ 5.26.3 Fixed in 5.26.4 CVE-2025-62027 Patchstack
4.3 Medium Blockspare Plugin blockspare Information Disclosure Sensitive Data Exposure ≤ 3.2.13.2 Fixed in 3.2.14 CVE-2025-62026 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-62025 Patchstack
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-62024 Patchstack
9.0 Critical s2Member Plugin s2member Remote Code Execution No login needed ≤ 250905 Fixed in 251005 CVE-2025-62023 Patchstack
7.5 High BuddyPress Plugin buddypress Broken Access Control No login needed ≤ 14.3.4 Fixed in 14.4.0 CVE-2025-62022 Patchstack
4.3 Medium Acknowledgify Plugin acknowledgify Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-62021 Patchstack
7.1 High VOD Infomaniak Plugin vod-infomaniak Cross-Site Scripting No login needed ≤ 1.5.11 Fixed in 1.5.12 CVE-2025-62020 Patchstack
6.5 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2025-62019 Patchstack
7.6 High Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free SQL Injection ≤ 4.6.8 Fixed in 4.6.9 CVE-2025-62015 Patchstack
4.3 Medium UiChemy Plugin uichemy Broken Access Control ≤ 4.0.0 Fixed in 4.0.1 CVE-2025-62013 Patchstack
4.3 Medium UPC/EAN/GTIN Code Generator Plugin upc-ean-barcode-generator Cross-Site Request Forgery No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-62009 Patchstack
8.8 High Product Table For WooCommerce Plugin product-table-for-woocommerce PHP Object Injection ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-62008 Patchstack
8.8 High Voice Feedback Plugin voice-feedback Privilege Escalation ≤ 1.0.3 Fixed in 2.0.0 CVE-2025-62007 Patchstack
5.4 Medium WP SMS Plugin wp-sms Broken Access Control ≤ 7.0.1 Fixed in 7.0.2 CVE-2025-62006 Patchstack
7.1 High SUMO Memberships for WooCommerce Plugin sumomemberships Cross-Site Request Forgery No login needed ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-62005 Patchstack
7.1 High Simple Finance Calculator Plugin simple-finance-calculator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-60246 Patchstack
9.8 Critical UNIVERSAM Plugin universam-demo PHP Object Injection No login needed ≤ 9.04.02 CVE-2025-60238 Patchstack
8.8 High Single Property Plugin single-property PHP Object Injection ≤ 2.8 CVE-2025-60234 Patchstack
9.8 Critical KBx Pro Ultimate Plugin knowledgebase-helpdesk-pro PHP Object Injection No login needed ≤ 8.0.5 CVE-2025-60232 Patchstack
8.8 High Knowledge Base Plugin kbase PHP Object Injection ≤ 2.9 CVE-2025-60228 Patchstack
8.6 High WP Pipes Plugin wp-pipes Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-60227 Patchstack
9.8 Critical White Rabbit Theme whiterabbit PHP Object Injection No login needed ≤ 1.5.2 CVE-2025-60226 Patchstack
9.8 Critical BugsPatrol Theme bugspatrol PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60225 Patchstack
9.8 Critical Subscribe to Download Plugin subscribe-to-download PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60224 Patchstack
8.8 High SUMO Memberships for WooCommerce Plugin sumomemberships Privilege Escalation ≤ 7.8.0 Fixed in 7.9.0 CVE-2025-60222 Patchstack
9.8 Critical Captivate Sync Plugin captivatesync-trade PHP Object Injection No login needed ≤ 3.0.3 Fixed in 3.2.2 CVE-2025-60221 Patchstack
9.8 Critical CouponXxL Plugin couponxxl Privilege Escalation No login needed ≤ 3.0.0 CVE-2025-60220 Patchstack
7.7 High PT Luxa Addons Plugin pt-luxa-addons Arbitrary File Deletion ≤ 1.2.2 CVE-2025-60217 Patchstack
9.8 Critical Addison Plugin addison PHP Object Injection No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2025-60216 Patchstack
8.8 High Kriya Plugin kriya PHP Object Injection ≤ 3.4 CVE-2025-60215 Patchstack
9.8 Critical Goldenblatt Plugin goldenblatt PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-60214 Patchstack
9.8 Critical Scape Plugin scape PHP Object Injection No login needed ≤ 1.5.13 CVE-2025-60213 Patchstack
8.8 High VEDA Theme veda PHP Object Injection ≤ 4.2 CVE-2025-60212 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only