WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Custom API for WP Plugin custom-api-for-wp Privilege Escalation ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54049 Patchstack
9.1 Critical Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Arbitrary File Upload ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54677 Patchstack
9.3 Critical JS Archive List Plugin jquery-archive-list-widget SQL Injection No login needed ≤ 6.1.6 Fixed in 6.1.6 CVE-2025-54726 Patchstack
9.8 Critical Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-54713 Patchstack
9.8 Critical Real Spaces - WordPress Properties Directory Theme Privilege Escalation WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register' No login needed ≤ 3.6 CVE-2025-6758 Wordfence
9.3 Critical MDTF Plugin wp-meta-data-filter-and-taxonomy-filter SQL Injection No login needed ≤ 1.3.3.7 Fixed in 1.3.3.8 CVE-2025-54707 Patchstack
9.0 Critical Form Block Plugin form-block Arbitrary File Upload No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-54693 Patchstack
9.8 Critical Exertio Plugin exertio PHP Object Injection No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-54686 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 3.8.15 Fixed in 3.8.16 CVE-2025-54678 Patchstack
9.3 Critical MapSVG Plugin mapsvg SQL Injection No login needed ≤ 8.7.4 Fixed in 8.7.4 CVE-2025-54669 Patchstack
9.9 Critical Forms Plugin forms-by-made-it Arbitrary File Upload ≤ 2.9.0 CVE-2025-24775 Patchstack
10.0 Critical BeeTeam368 Extensions Plugin beeteam368-extensions Local File Inclusion No login needed ≤ 1.9.4 CVE-2025-25174 Patchstack
9.8 Critical Geo Mashup Plugin geo-mashup Local File Inclusion No login needed ≤ 1.13.16 Fixed in 1.13.17 CVE-2025-48293 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.20 Fixed in 1.5.21 CVE-2025-49059 Patchstack
9.9 Critical Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Remote Code Execution ≤ 2.9.3 Fixed in 2.9.4 CVE-2025-49887 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.5 Fixed in 7.6 CVE-2025-52720 Patchstack
9.3 Critical WordPress Plugin wp-property Arbitrary File Upload WordPress Plugin WP-Property <= 1.35.0 PHP File Upload No login needed ≤ 1.35.0 CVE-2012-10027 VulnCheck
10.0 Critical asset-manager Plugin asset-manager Arbitrary File Upload WordPress Plugin Asset-Manager <= 2.0 PHP File Upload No login needed ≤ 2.0 CVE-2012-10026 VulnCheck
10.0 Critical WordPress Plugin advanced-custom-fields Local File Inclusion WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion No login needed ≤ 3.5.1 CVE-2012-10025 VulnCheck
9.8 Critical LoginPress Pro Plugin Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 5.0.1 CVE-2025-7444 Wordfence
9.3 Critical WP-BusinessDirectory Plugin wp-businessdirectory SQL Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-24759 Patchstack
9.8 Critical URL Shortener Plugin exact-links PHP Object Injection No login needed ≤ 3.0.7 CVE-2025-28961 Patchstack
9.3 Critical URL Shortener Plugin exact-links SQL Injection No login needed ≤ 3.0.7 CVE-2025-28959 Patchstack
9.3 Critical WP Pipes Plugin wp-pipes SQL Injection No login needed ≤ 1.4.3 CVE-2025-28982 Patchstack
10.0 Critical Medical Prescription Attachment Plugin for WooCommerce Plugin medical-prescription-attachment-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 1.2.3 CVE-2025-29009 Patchstack
9.8 Critical Site Chat on Telegram Plugin site-chat-on-telegram PHP Object Injection No login needed ≤ 1.0.4 Fixed in 1.0.6 CVE-2025-30949 Patchstack
9.3 Critical Torod Plugin torod SQL Injection No login needed ≤ 2.1 CVE-2025-30936 Patchstack
9.8 Critical CoSchool LMS Plugin coschool PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-30973 Patchstack
9.1 Critical Groundhogg Plugin groundhogg Arbitrary File Upload ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-48300 Patchstack
9.3 Critical Traveler Plugin traveler SQL Injection No login needed ≤ 3.2.2 Fixed in 3.2.2 CVE-2025-52714 Patchstack
9.8 Critical The E-Commerce ERP Plugin profitori Privilege Escalation No login needed ≤ 2.1.1.3 CVE-2025-52836 Patchstack
9.6 Critical FluentSnippets Plugin easy-code-manager Cross-Site Request Forgery No login needed ≤ 10.50 Fixed in 10.51 CVE-2025-54010 Patchstack
9.8 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed ≤ 7.8.3 CVE-2025-5394 Wordfence
9.1 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed ≤ 7.8.5 CVE-2025-5393 Wordfence
9.8 Critical Premium Age Verification / Restriction Plugin Path Traversal Unauthenticated Arbitrary File Read and Write via remote_tunnel.php No login needed ≤ 3.0.2 CVE-2025-7401 Wordfence
9.8 Critical Sala - Startup & SaaS Theme Privilege Escalation Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 1.1.4 CVE-2025-4606 Wordfence
10.0 Critical Pie Register Plugin pie-register Authentication Bypass WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE No login needed ≤ 3.7.1.4 CVE-2025-34077 VulnCheck
9.8 Critical Service Finder Booking Plugin sf-booking Privilege Escalation No login needed ≤ 6.1 CVE-2025-23970 Patchstack
9.8 Critical Click & Pledge Connect Plugin click-pledge-connect Privilege Escalation Privilege Escalation via SQL Injection No login needed 25.04010101 – WP6.8 CVE-2025-28983 Patchstack
10.0 Critical LogisticsHub Plugin logistics-hub Arbitrary File Upload No login needed ≤ 1.1.6 CVE-2025-30933 Patchstack
10.0 Critical Easy Stripe Plugin easy-stripe Remote Code Execution No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-49302 Patchstack
9.8 Critical RealHomes Plugin realhomes Privilege Escalation No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-49867 Patchstack
9.3 Critical Video List Manager Plugin video-list-manager SQL Injection No login needed ≤ 1.7 CVE-2025-52831 Patchstack
9.3 Critical bSecure – Your Universal Checkout Plugin bsecure SQL Injection Your Universal Checkout plugin <= 1.7.9 - SQL Injection No login needed ≤ 1.7.9 CVE-2025-52830 Patchstack
9.3 Critical LMS Plugin lms SQL Injection No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52833 Patchstack
9.3 Critical NGG Smart Image Search Plugin ngg-smart-image-search SQL Injection No login needed ≤ 3.4.1 Fixed in 3.4.3 CVE-2025-52832 Patchstack
9.8 Critical WooCommerce Product Multi-Action Plugin woo-product-multiaction PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3 CVE-2025-49417 Patchstack
10.0 Critical FW Gallery Plugin fw-gallery Arbitrary File Upload No login needed ≤ 8.0.0 CVE-2025-49414 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-28951 Patchstack
9.1 Critical AiBud WP Plugin aibuddy-openai-chatgpt Arbitrary File Upload ≤ 1.9 CVE-2025-23968 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only