WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,251–7,300 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 146 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg_radio_player_addon_visual_composer Cross-Site Scripting WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.5.2 CVE-2025-53564 Patchstack
7.1 High Youtube Vimeo Video Player and Slider Plugin video_player_youtube_vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-53563 Patchstack
8.1 High Ghost Kit Plugin ghostkit Local File Inclusion No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-53567 Patchstack
8.1 High Widget for Google Reviews Plugin business-reviews-wp Local File Inclusion No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-53565 Patchstack
10.0 Critical Global DNS Plugin global-dns Remote Code Execution No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-53577 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Information Disclosure Sensitive Data Exposure ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53983 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-53580 Patchstack
6.5 Medium JetMenu Plugin jet-menu Information Disclosure Sensitive Data Exposure ≤ 2.4.11.1 Fixed in 2.4.11.2 CVE-2025-53987 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Information Disclosure Sensitive Data Exposure ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53985 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Information Disclosure Sensitive Data Exposure ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53992 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Information Disclosure Sensitive Data Exposure ≤ 1.3.18 Fixed in 1.3.19 CVE-2025-53988 Patchstack
6.5 Medium JetPopup Plugin jet-popup Information Disclosure Sensitive Data Exposure ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53993 Patchstack
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-54007 Patchstack
6.5 Medium JetWooBuilder Plugin jet-woo-builder Information Disclosure Sensitive Data Exposure ≤ 2.1.20 Fixed in 2.1.20.1 CVE-2025-53998 Patchstack
7.2 High Welcart e-Commerce Plugin usc-e-shop PHP Object Injection ≤ 2.11.16 Fixed in 2.11.17 CVE-2025-54012 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Information Disclosure Sensitive Data Exposure ≤ 3.6.7 Fixed in 3.6.7.1 CVE-2025-54008 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions Local File Inclusion No login needed ≤ 2.15.4 Fixed in 2.15.5 CVE-2025-54017 Patchstack
9.8 Critical MediCenter - Health Medical Clinic Plugin medicenter PHP Object Injection Health Medical Clinic <= 15.1 - PHP Object Injection No login needed ≤ 15.1 Fixed in 15.2 CVE-2025-54014 Patchstack
7.5 High Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download No login needed ≤ 6.1.14 Fixed in 6.1.15 CVE-2025-54021 Patchstack
6.5 Medium Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.5 Fixed in 7.8.5 CVE-2025-54019 Patchstack
7.1 High Support Board Plugin supportboard Cross-Site Scripting No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-54027 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control Settings Change No login needed ≤ 6.4.0 Fixed in 6.4.2 CVE-2025-54025 Patchstack
7.5 High CF7 WOW Styler Plugin cf7-styler Local File Inclusion No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-54028 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting No login needed ≤ 12.7.3 Fixed in 12.7.4 CVE-2025-54032 Patchstack
8.1 High Support Board Plugin supportboard Local File Inclusion No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-54031 Patchstack
6.5 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 5.1.20 Fixed in 5.1.22 CVE-2025-54040 Patchstack
7.5 High Newsletters Plugin newsletters-lite Local File Inclusion No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-54034 Patchstack
6.5 Medium Cost Calculator Plugin ql-cost-calculator Cross-Site Scripting ≤ 7.4 Fixed in 7 .5 CVE-2025-54046 Patchstack
7.1 High Elite Video Player Plugin elite-video-player Cross-Site Scripting No login needed ≤ 10.0.5 Fixed in 10.0.7 CVE-2025-54044 Patchstack
9.3 Critical Custom API for WP Plugin custom-api-for-wp SQL Injection No login needed ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54048 Patchstack
7.5 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Local File Inclusion No login needed ≤ 5.0.0 Fixed in 5.0.1 CVE-2025-54052 Patchstack
9.9 Critical Custom API for WP Plugin custom-api-for-wp Privilege Escalation ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54049 Patchstack
7.1 High Druco Plugin druco Cross-Site Scripting No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54055 Patchstack
6.6 Medium Groundhogg Plugin groundhogg PHP Object Injection ≤ 4.2.2 Fixed in 4.2.2.1 CVE-2025-54053 Patchstack
7.1 High oik Plugin oik Cross-Site Scripting No login needed ≤ 4.15.2 Fixed in 4.15.3 CVE-2025-54670 Patchstack
7.1 High Responsive HTML5 Audio Player PRO With Playlist Plugin lbg-audio2-html5 Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2025-54056 Patchstack
9.1 Critical Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Arbitrary File Upload ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54677 Patchstack
9.3 Critical JS Archive List Plugin jquery-archive-list-widget SQL Injection No login needed ≤ 6.1.6 Fixed in 6.1.6 CVE-2025-54726 Patchstack
9.8 Critical Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-54713 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.11.1 Fixed in 3.12.0 CVE-2025-54750 Patchstack
8.8 High CubeWP Plugin cubewp-framework Privilege Escalation ≤ 1.1.24 Fixed in 1.1.25 CVE-2025-54735 Patchstack
7.5 High Otter - Gutenberg Block Plugin otter-blocks Information Disclosure Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-55715 Patchstack
9.8 Critical Real Spaces - WordPress Properties Directory Theme Privilege Escalation WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register' No login needed ≤ 3.6 CVE-2025-6758 Wordfence
8.8 High Real Spaces - WordPress Properties Directory Theme Privilege Escalation WordPress Properties Directory Theme <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member' ≤ 3.5 CVE-2025-8218 Wordfence
8.8 High WPGYM - Wordpress Gym Management System Plugin Local File Inclusion Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 67.7.0 CVE-2025-3671 Wordfence
7.5 High School Management System Plugin wpschoolpress SQL Injection Unauthenticated SQL Injection No login needed ≤ 93.2.0 CVE-2024-12612 Wordfence
6.5 Medium ServerBuddy by PluginBuddy.com Plugin serverbuddy-by-pluginbuddy Cross-Site Request Forgery CSRF to PHP Object Injection ≤ 1.0.5 CVE-2025-49895 Patchstack
7.6 High Dropshix Plugin dropshipping-xox Cross-Site Scripting ≤ 4.0.14 CVE-2025-49898 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
5.3 Medium Ultimate Video Player Plugin fwduvp Broken Access Control No login needed ≤ 10.1 CVE-2025-49432 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only