WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,251–6,300 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 126 of 345
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Privilege Escalation Custom Signup Fields plugin <= 3.2.3 - Privilege Escalation ≤ 3.2.3 CVE-2025-60211 Patchstack
9.8 Critical Everest Forms - Frontend Listing Plugin everest-forms-frontend-listing PHP Object Injection Frontend Listing plugin <= 1.0.5 - PHP Object Injection No login needed ≤ 1.0.5 CVE-2025-60210 Patchstack
9.8 Critical Connector for Gravity Forms and Google Sheets Plugin wp-gravity-forms-spreadsheets PHP Object Injection No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60209 Patchstack
8.8 High Advanced Custom Fields : CPT Options Pages Plugin acf-cpt-options-pages Cross-Site Request Forgery No login needed ≤ 2.0.9 CVE-2025-60208 Patchstack
10.0 Critical Alone Plugin alone Remote Code Execution No login needed ≤ 7.8.3 CVE-2025-60206 Patchstack
5.9 Medium WP Tesseract Plugin wp-tesseract Cross-Site Scripting ≤ 1.0.2 CVE-2025-60176 Patchstack
7.1 High HotelRunner Booking Widget Plugin hotelrunner Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-60168 Patchstack
4.7 Medium WP Gravity Forms HubSpot Plugin gf-hubspot Open Redirect No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-60151 Patchstack
5.9 Medium WeShare Buttons Plugin e-mailit Cross-Site Scripting ≤ 13.0.0 CVE-2025-60135 Patchstack
4.3 Medium WP Media Categories Plugin wp-media-categories Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-60134 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60132 Patchstack
5.9 Medium Werk aan de Muur Plugin werk-aan-de-muur Cross-Site Scripting ≤ 1.5 Fixed in 1.5.1 CVE-2025-60131 Patchstack
8.8 High Emails Catch All Plugin emails-catch-all Authentication Bypass Broken Authentication ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-60041 Patchstack
9.8 Critical Noisa Plugin noisa PHP Object Injection No login needed ≤ 2.6.0 Fixed in 2.6.3 CVE-2025-60039 Patchstack
5.9 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.334 Fixed in 1.0.334 CVE-2025-59593 Patchstack
8.8 High Goodlayers Core Plugin goodlayers-core Privilege Escalation ≤ 2.1.7 Fixed in 2.1.7 CVE-2025-59580 Patchstack
7.5 High Simple Job Board Plugin simple-job-board Information Disclosure Sensitive Data Exposure No login needed ≤ 2.13.7 Fixed in 2.13.8 CVE-2025-59579 Patchstack
5.8 Medium ShopMagic Plugin shopmagic-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-59578 Patchstack
4.9 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Information Disclosure Sensitive Data Exposure ≤ 3.6.20 Fixed in 3.6.21 CVE-2025-59575 Patchstack
7.1 High WorkScout-Core Plugin workscout-core Cross-Site Scripting No login needed ≤ 1.7.06 Fixed in 1.7.06 CVE-2025-59571 Patchstack
7.7 High Workreap (theme's plugin) Plugin workreap Arbitrary File Deletion ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-59566 Patchstack
8.1 High EduMall Theme edumall Local File Inclusion No login needed ≤ 4.4.5 Fixed in 4.4.5 CVE-2025-59564 Patchstack
8.1 High Billey Theme billey Local File Inclusion No login needed ≤ 2.1.6 Fixed in 2.1.6 CVE-2025-59558 Patchstack
9.3 Critical Learts Addons Plugin learts-addons SQL Injection No login needed ≤ 1.7.5 Fixed in 1.7.5 CVE-2025-59557 Patchstack
8.1 High Medizin Plugin medizin Local File Inclusion No login needed ≤ 1.9.7 Fixed in 1.9.7 CVE-2025-59555 Patchstack
8.1 High Xcare Theme xcare Local File Inclusion No login needed ≤ 6.5 Fixed in 6.5 CVE-2025-59550 Patchstack
9.8 Critical TF Woo Product Grid Addon For Elementor Plugin tf-woo-product-grid PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.0.1 CVE-2025-59007 Patchstack
7.1 High Easy Woocommerce Customizer Plugin easy-woocommerce-customizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-59006 Patchstack
7.1 High WC Return products Plugin wc-return-product Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-59004 Patchstack
7.1 High Doctreat Plugin doctreat Cross-Site Scripting No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-58971 Patchstack
6.3 Medium Doctreat Plugin doctreat Content Injection ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-58970 Patchstack
8.1 High Businext Plugin businext Local File Inclusion No login needed ≤ 2.4.4 Fixed in 2.4.4 CVE-2025-58967 Patchstack
7.1 High NEX-Forms LITE Plugin nex-forms-lite Cross-Site Scripting No login needed ≤ 8.2 Fixed in 8.2 CVE-2025-58966 Patchstack
10.0 Critical Medcity Plugin medcity Arbitrary File Upload No login needed ≤ 1.1.9 Fixed in 1.1.9 CVE-2025-58963 Patchstack
7.1 High CF7 Auto Responder Addon Plugin cf7-autoresponder-addon Cross-Site Scripting No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-58961 Patchstack
7.7 High Taskbot Plugin taskbot Arbitrary File Deletion ≤ 6.4 Fixed in 6.5 CVE-2025-58959 Patchstack
8.1 High SmilePure Plugin smilepure Local File Inclusion No login needed ≤ 1.8.5 Fixed in 1.8.5 CVE-2025-58958 Patchstack
8.1 High Karzo Theme karzo Local File Inclusion No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-58955 Patchstack
7.1 High WP Tactical Popup Plugin wp-tactical-popup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-58921 Patchstack
7.1 High Author: Munzir Plugin myshouts-shoutbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9 CVE-2025-58916 Patchstack
8.8 High Simple User Registration Plugin wp-registration Privilege Escalation ≤ 6.8 CVE-2025-53428 Patchstack
7.1 High SEO Pyramid Plugin seo-pyramid Cross-Site Scripting No login needed ≤ 1.9.8 CVE-2025-53427 Patchstack
7.1 High Likert Survey Master Plugin likert-survey-master Cross-Site Scripting No login needed ≤ 0.8.0.1 CVE-2025-53426 Patchstack
7.2 High Dokan Plugin dokan-lite Privilege Escalation ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-53425 Patchstack
6.5 Medium WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei Broken Access Control ≤ 5.4 CVE-2025-53424 Patchstack
7.1 High Triss Plugin triss Cross-Site Scripting No login needed ≤ 2.6 CVE-2025-53423 Patchstack
7.1 High WhatsApp Chat for WordPress and WooCommerce Plugin tw-whatsapp-chat-rotator Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-53422 Patchstack
6.5 Medium Accordion Plugin accordions Broken Access Control ≤ 2.3.14 Fixed in 2.3.16 CVE-2025-53421 Patchstack
7.1 High WPLMS Plugin wplms_plugin Cross-Site Scripting No login needed ≤ 1.9.9.8 CVE-2025-53420 Patchstack
7.1 High Grid Plus Plugin grid-plus Cross-Site Scripting No login needed ≤ 3.3 CVE-2025-53352 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only