WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,401–7,450 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 149 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32288 Patchstack
7.5 High WP Lead Capturing Pages Plugin leadcapture Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31425 Patchstack
8.5 High Pinterest Automatic Pin Plugin wp-pinterest-automatic SQL Injection ≤ 4.19.0 Fixed in 4.19.0 CVE-2025-39510 Patchstack
6.5 Medium Eventer Plugin eventer Content Injection No login needed ≤ 3.9.9.1 Fixed in 3.9.9.1 CVE-2025-39483 Patchstack
7.2 High Content Egg Plugin content-egg PHP Object Injection ≤ 7.0.0 Fixed in 8.0.0 CVE-2025-47536 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-47689 Patchstack
6.5 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Cross-Site Scripting ≤ 4.5.6 Fixed in 4.5.7 CVE-2025-47610 Patchstack
7.5 High Gutenberg Blocks Plugin advanced-gutenberg Local File Inclusion No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-48332 Patchstack
9.8 Critical Geo Mashup Plugin geo-mashup Local File Inclusion No login needed ≤ 1.13.16 Fixed in 1.13.17 CVE-2025-48293 Patchstack
8.1 High Premium Addons for KingComposer Plugin premium-addons-for-kingcomposer Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-49036 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.3 Fixed in 5.9.5.4 CVE-2025-49033 Patchstack
7.1 High WP Dynamic Links Plugin wp-dynamic-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-49038 Patchstack
7.1 High Authentication and xmlrpc log writer Plugin authentication-and-xmlrpc-log-writer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-49037 Patchstack
7.1 High Simple Poll Plugin simple-poll Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-49044 Patchstack
5.9 Medium Inspectlet – User Session Recording and Heatmaps Plugin inspectlet-heatmaps-and-user-session-recording Cross-Site Scripting User Session Recording and Heatmaps plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 3.0 CVE-2025-49048 Patchstack
5.9 Medium DigitalOcean Spaces Sync Plugin do-spaces-sync Cross-Site Scripting ≤ 2.2.1 CVE-2025-49047 Patchstack
4.3 Medium Netease Music Plugin netease-music Broken Access Control ≤ 3.2.1 CVE-2025-49052 Patchstack
6.5 Medium Hide Text Shortcode Plugin hide-text-shortcode Cross-Site Scripting ≤ 1.1 CVE-2025-49051 Patchstack
5.9 Medium WP Airdrop Manager Plugin airdrop Cross-Site Scripting ≤ 1.0.5 CVE-2025-49053 Patchstack
7.1 High Time Sheets Plugin time-sheets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.3 CVE-2025-49054 Patchstack
7.1 High 多说社会化评论框 Plugin duoshuo Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-49056 Patchstack
7.1 High SoundSt SEO Search Plugin soundst-seo-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-49058 Patchstack
7.1 High WP Voting Plugin wp-voting Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-49057 Patchstack
6.5 Medium Porn Videos Embed Plugin porn-videos-embed Cross-Site Scripting ≤ 0.9.1 CVE-2025-49061 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.20 Fixed in 1.5.21 CVE-2025-49059 Patchstack
7.1 High BaiduXZH Submit(百度熊掌号) Plugin i3geek-baiduxzh Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-49063 Patchstack
7.1 High WP-jScrollPane Plugin wp-jscrollpane Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-49062 Patchstack
7.1 High Visit Counter Plugin visit-counter Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49065 Patchstack
7.1 High User Language Switch Plugin user-language-switch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.10 CVE-2025-49064 Patchstack
8.5 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element SQL Injection ≤ 3.28.3 Fixed in 3.28.5 CVE-2025-49267 Patchstack
7.5 High Cloud SAML SSO - Single Sign On Login Plugin cloud-sso-single-sign-on Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-49264 Patchstack
7.5 High GravityWP - Merge Tags Plugin gravitywp-merge-tags Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-49271 Patchstack
6.5 Medium WP LOL Rotation Plugin league-of-legends-rotation Cross-Site Scripting ≤ 1.0 CVE-2025-49437 Patchstack
6.5 Medium Supermalink Plugin supermalink Cross-Site Scripting ≤ 1.1 CVE-2025-49433 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.0.31 Fixed in 4.0.32 CVE-2025-49869 Patchstack
6.5 Medium AI Tools Plugin artificial-intelligence-auto-content-generator Broken Access Control Arbitrary Content Deletion ≤ 4.0.7 CVE-2025-50029 Patchstack
9.9 Critical Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Remote Code Execution ≤ 2.9.3 Fixed in 2.9.4 CVE-2025-49887 Patchstack
6.5 Medium CF7 Spreadsheets Plugin cf7-spreadsheets Cross-Site Scripting ≤ 2.3.2 CVE-2025-50040 Patchstack
6.5 Medium DB Backup Plugin db-backup Broken Access Control ≤ 6.0 CVE-2025-50031 Patchstack
7.5 High WP REST Cache Plugin wp-rest-cache Local File Inclusion No login needed ≤ 2025.1.0 Fixed in 2025.1.1 CVE-2025-52716 Patchstack
4.2 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Visual Drag and Drop Editor <= 1.27.8 - Path Traversal ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52712 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.5 Fixed in 7.6 CVE-2025-52720 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.0 Fixed in 15.1 CVE-2025-52728 Patchstack
6.5 Medium Global Gallery Plugin global-gallery Broken Access Control No login needed ≤ 9.2.3 Fixed in 9.2.4 CVE-2025-52721 Patchstack
7.5 High Event Manager, Event Calendar and Booking Plugin eventin-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52731 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
7.1 High Project Cost Calculator Plugin project-cost-calculator Broken Access Control ≤ 1.0.0 CVE-2025-52775 Patchstack
8.8 High GMap Targeting Plugin gmap-targeting Local File Inclusion ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-52732 Patchstack
7.1 High SMM API Plugin smm-api Broken Access Control ≤ 6.0.31 CVE-2025-52785 Patchstack
7.3 High The E-Commerce ERP Plugin profitori Broken Access Control No login needed ≤ 2.1.1.3 CVE-2025-52800 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only