WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical Zippy Plugin zippy Arbitrary File Upload ≤ 1.7.0 CVE-2025-52758 Patchstack
9.3 Critical JetSearch Plugin jet-search SQL Injection No login needed ≤ 3.5.10 Fixed in 3.5.10.1 CVE-2025-49931 Patchstack
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection No login needed ≤ 3.8.5 Fixed in 3.8.6 CVE-2025-49915 Patchstack
9.8 Critical Simple Link Directory Plugin qc-simple-link-directory Authentication Bypass Broken Authentication No login needed ≤ 14.8.1 Fixed in 14.8.1 CVE-2025-49901 Patchstack
9.8 Critical WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder PHP Object Injection No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49380 Patchstack
10.0 Critical Wastia Plugin wastia Arbitrary File Upload No login needed ≤ 1.1.3 Fixed in 1.1.3 CVE-2025-49060 Patchstack
10.0 Critical Clanora Theme clanora Arbitrary File Upload No login needed ≤ 1.3.1 Fixed in 1.3.1 CVE-2025-48106 Patchstack
9.3 Critical is-human Plugin is-human Remote Code Execution WordPress Plugin is-human <= v1.4.2 Eval Injection RCE No login needed ≤ 1.4.2 CVE-2011-10033 VulnCheck
9.8 Critical Search & Go - Directory Theme Authentication Bypass Directory WordPress Theme <= 2.7 - Authentication Bypass to Privilege Escalation via Account Takeover No login needed ≤ 2.7 CVE-2025-11522 Wordfence
10.0 Critical WooCommerce Designer Pro Plugin wc-designer-pro Arbitrary File Upload No login needed ≤ 1.9.24 CVE-2025-60219 Patchstack
9.6 Critical AR Plugin ar-for-wordpress Cross-Site Request Forgery No login needed ≤ 8.34 CVE-2025-60156 Patchstack
9.8 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.2.6 CVE-2025-10147 Wordfence
9.6 Critical Custom Post Type Images Plugin custom-post-types-image Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-58255 Patchstack
9.8 Critical Goza - Nonprofit Charity Theme Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed ≤ 3.2.2 CVE-2025-10690 Wordfence
9.6 Critical Mow Plugin mow Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-58997 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-32486 Patchstack
9.3 Critical WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card SQL Injection No login needed ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-47569 Patchstack
9.0 Critical Photography Plugin photography PHP Object Injection No login needed ≤ 7.7.2 CVE-2025-47579 Patchstack
9.1 Critical Goza - Nonprofit Charity Theme Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed 3.2.2 CVE-2025-10134 Wordfence
9.3 Critical Miraculous Plugin miraculous SQL Injection No login needed ≤ 2.0.9 CVE-2025-58628 Patchstack
9.8 Critical smart SEO Theme smartseo Privilege Escalation No login needed ≤ 4.0 CVE-2025-49401 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-58819 Patchstack
9.8 Critical RealHomes Plugin realhomes Privilege Escalation No login needed ≤ 4.3.6 Fixed in 4.3.7 CVE-2024-32444 Patchstack
9.9 Critical School Management Plugin school-management Arbitrary File Upload ≤ 1.93.1 (02-07-2025) CVE-2025-31100 Patchstack
9.8 Critical Login with phone number Plugin login-with-phone-number Broken Access Control No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-32832 Patchstack
9.8 Critical Jobmonster Theme noo-jobmonster Authentication Bypass Broken Authentication No login needed ≤ 4.7.9 Fixed in 4.8.0 CVE-2025-54738 Patchstack
9.8 Critical Golo Plugin golo Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-54725 Patchstack
9.3 Critical Nest Addons Plugin nest-addons SQL Injection No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-54720 Patchstack
9.8 Critical WP Funnel Manager Plugin wp-funnel-manager PHP Object Injection No login needed ≤ 1.4.0 CVE-2025-52761 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Privilege Escalation No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-49388 Patchstack
10.0 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-49387 Patchstack
9.1 Critical bidorbuy Store Integrator Plugin bidorbuystoreintegrator Remote Code Execution ≤ 2.12.0 CVE-2025-48100 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed < 2.9.6 Fixed in 2.9.6 CVE-2025-39496 Patchstack
9.9 Critical Pin WP Theme pin-wp Arbitrary File Upload ≤ 7.2 Fixed in 7.2 CVE-2025-53251 Patchstack
9.6 Critical ads.txt Guru Connect Plugin adstxt-guru-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-49381 Patchstack
9.8 Critical WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting No login needed ≤ 8.2 Fixed in 8.3 CVE-2025-49400 Patchstack
10.0 Critical Templately Plugin templately Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2025-49408 Patchstack
9.8 Critical SensorPress Plugin sensorpress-uptime-monitoring Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49409 Patchstack
10.0 Critical TC Testimonials Plugin tc-testimonial Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2025-49410 Patchstack
9.8 Critical Support Ticket Plugin support-ticket Privilege Escalation No login needed ≤ 1.9 CVE-2025-49422 Patchstack
9.8 Critical Cars4Rent Theme cars4rent PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-49434 Patchstack
9.8 Critical Organic Beauty Theme organic-beauty PHP Object Injection No login needed ≤ 1.4.6 CVE-2025-49890 Patchstack
10.0 Critical StoreKeeper for WooCommerce Plugin storekeeper-for-woocommerce Arbitrary File Upload No login needed ≤ 14.4.4 Fixed in 14.4.5 CVE-2025-48148 Patchstack
9.9 Critical Code Engine Plugin code-engine Remote Code Execution ≤ 0.3.3 Fixed in 0.3.4 CVE-2025-48169 Patchstack
9.9 Critical ReachShip WooCommerce Multi-Carrier & Conditional Shipping Plugin elex-reachship-multi-carrier-conditional-shipping Arbitrary File Upload ≤ 4.3.1 Fixed in 4.3.2 CVE-2025-53213 Patchstack
9.8 Critical ThemeMakers Visual Content Composer Plugin tmm_content_composer PHP Object Injection No login needed ≤ 1.5.8 CVE-2025-53299 Patchstack
10.0 Critical Global DNS Plugin global-dns Remote Code Execution No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-53577 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-53580 Patchstack
9.8 Critical MediCenter - Health Medical Clinic Plugin medicenter PHP Object Injection Health Medical Clinic <= 15.1 - PHP Object Injection No login needed ≤ 15.1 Fixed in 15.2 CVE-2025-54014 Patchstack
9.3 Critical Custom API for WP Plugin custom-api-for-wp SQL Injection No login needed ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54048 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only