WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Education Center | LMS & Online Courses Theme PHP Object Injection No login needed ≤ 3.6.10 CVE-2024-13786 Wordfence
9.8 Critical Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin Local File Inclusion Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion to Remote Code Execution No login needed ≤ 4.89 CVE-2025-4689 Wordfence
9.1 Critical Custom Login And Signup Widget Plugin custom-login-and-signup-widget Remote Code Execution Arbitrary Code Execution ≤ 1.0 CVE-2025-49029 Patchstack
9.6 Critical WP Optimizer Plugin wp-optimizer Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2025-53314 Patchstack
9.1 Critical File Manager Plugin file-manager-plugin-for-wordpress Arbitrary File Upload ≤ 7.5 CVE-2025-53260 Patchstack
9.8 Critical WP Optimize By xTraffic Plugin wp-optimize-by-xtraffic PHP Object Injection No login needed ≤ 5.1.6 CVE-2025-28970 Patchstack
9.3 Critical Amely Theme amely SQL Injection No login needed ≤ 3.1.4 Fixed in 3.2.0 CVE-2025-39474 Patchstack
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
9.3 Critical LifterLMS Plugin lifterlms SQL Injection No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-52717 Patchstack
9.3 Critical Classiera Theme classiera SQL Injection No login needed ≤ 4.0.34 Fixed in 4.0.35 CVE-2025-52722 Patchstack
9.8 Critical CouponXxL Plugin couponxxl PHP Object Injection No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-52725 Patchstack
9.8 Critical Amwerk Theme amwerk PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-52724 Patchstack
9.3 Critical Homey Plugin homey SQL Injection No login needed ≤ 2.4.7 CVE-2025-52834 Patchstack
9.3 Critical DirectIQ Email Marketing Plugin directiq-wp SQL Injection No login needed ≤ 2.0 CVE-2025-52829 Patchstack
9.3 Critical GG Bought Together for WooCommerce Plugin gg-bought-together SQL Injection No login needed ≤ 1.0.2 CVE-2025-23967 Patchstack
9.8 Critical DWT - Directory & Listing Theme Privilege Escalation Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password Reset No login needed ≤ 3.3.6 CVE-2024-12827 Wordfence
10.0 Critical Flozen Plugin flozen-theme Arbitrary File Upload No login needed ≤ 1.5.1 Fixed in 1.5.1 CVE-2025-49071 Patchstack
9.3 Critical PostaPanduri Plugin postapanduri SQL Injection No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-49452 Patchstack
9.3 Critical WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm SQL Injection CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection No login needed ≤ 3.2.0 CVE-2025-24773 Patchstack
9.8 Critical Rapyd Payment Extension for WooCommerce Plugin rapyd-payments PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-30618 Patchstack
9.8 Critical Spare Theme spare PHP Object Injection No login needed ≤ 1.7 CVE-2025-31919 Patchstack
10.0 Critical Ovatheme Events Manager Plugin ova-events-manager Arbitrary File Upload No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-32510 Patchstack
9.3 Critical Smart Notification Plugin smio-push-notification SQL Injection No login needed ≤ 10.3 CVE-2025-39479 Patchstack
9.9 Critical WP VR Plugin wpvr Arbitrary File Upload ≤ 8.5.26 Fixed in 8.5.27 CVE-2025-47452 Patchstack
9.9 Critical MapSVG Plugin mapsvg Arbitrary File Upload ≤ 8.7.4 Fixed in 8.7.4 CVE-2025-47559 Patchstack
9.3 Critical School Management Plugin school-management SQL Injection No login needed ≤ 92.0.0 CVE-2025-47573 Patchstack
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48274 Patchstack
9.8 Critical Integration for Contact Form 7 and Zoho CRM, Bigin Plugin cf7-zoho PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-49330 Patchstack
10.0 Critical Reformer for Elementor Plugin reformer-elementor Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2025-49444 Patchstack
10.0 Critical FW Food Menu Plugin fw-food-menu Arbitrary File Upload No login needed ≤ 6.0.0 CVE-2025-49447 Patchstack
9.3 Critical WordPress-WPJobBoard Plugin click-pledge-wpjobboard SQL Injection No login needed ≤ 25.07010000-WP6.8.1-JB5.11.5 Fixed in 25.09000000-WP6.8.2-JB5.12.0 CVE-2025-49455 Patchstack
9.8 Critical CozyStay Theme cozystay PHP Object Injection No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2025-49507 Patchstack
9.3 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai SQL Injection No login needed ≤ 3.19 Fixed in 3.21 CVE-2025-24767 Patchstack
9.8 Critical PayU India Plugin payu-india Privilege Escalation Account Takeover No login needed ≤ 3.8.8 Fixed in 3.8.8 CVE-2025-31022 Patchstack
9.1 Critical Category Icon Plugin category-icon XML External Entity ≤ 1.0.3 CVE-2025-31039 Patchstack
9.8 Critical The Fashion - Model Agency One Page Beauty Plugin nrgfashion PHP Object Injection Model Agency One Page Beauty Theme plugin <= 1.4.4 - Deserialization of untrusted data No login needed ≤ 1.4.4 CVE-2025-31052 Patchstack
9.3 Critical WBW Product Table PRO Plugin woo-producttables-pro SQL Injection No login needed ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-31059 Patchstack
9.8 Critical PIMP - Creative MultiPurpose Theme pimp PHP Object Injection Creative MultiPurpose <= 1.7 - Deserialization of untrusted data No login needed ≤ 1.7 CVE-2025-31398 Patchstack
9.8 Critical FLAP - Business Theme flap PHP Object Injection Business WordPress Theme <= 1.5 - PHP Object Injection No login needed ≤ 1.5 CVE-2025-31396 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin leadcapture SQL Injection No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31424 Patchstack
9.8 Critical PressGrid - Frontend Publish Reaction & Multimedia Theme press-grid PHP Object Injection Frontend Publish Reaction & Multimedia Theme <= 1.3.1 - Deserialization of untrusted data No login needed ≤ 1.3.1 CVE-2025-31429 Patchstack
10.0 Critical SUMO Affiliates Pro Plugin affs Arbitrary File Upload No login needed ≤ 11.1.0 Fixed in 11.1.0 CVE-2025-32291 Patchstack
9.3 Critical Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart SQL Injection No login needed ≤ 2.5 CVE-2025-47608 Patchstack
9.3 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light SQL Injection Light plugin <= 2.4.37 - SQL Injection No login needed ≤ 2.4.37 CVE-2025-48122 Patchstack
10.0 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Remote Code Execution Light plugin <= 2.4.37 - Remote Code Execution (RCE) No login needed ≤ 2.4.37 CVE-2025-48123 Patchstack
9.8 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Privilege Escalation Light plugin <= 2.4.37 - Privilege Escalation No login needed ≤ 2.4.37 CVE-2025-48129 Patchstack
9.9 Critical MetalpriceAPI Plugin metalpriceapi Remote Code Execution ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-48140 Patchstack
9.3 Critical Multi CryptoCurrency Payments Plugin multi-crypto-currency-payment SQL Injection No login needed ≤ 2.0.7 CVE-2025-48141 Patchstack
9.3 Critical MyStyle Custom Product Designer Plugin mystyle-custom-product-designer SQL Injection No login needed ≤ 3.21.1 Fixed in 3.21.2 CVE-2025-48281 Patchstack
9.8 Critical Mr. Murphy Theme mr-murphy PHP Object Injection No login needed ≤ 1.2.12.1 Fixed in 1.2.12.1 CVE-2025-49072 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only