WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,451–7,500 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 150 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High CaptionPix Plugin captionpix Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-52788 Patchstack
7.5 High JobSearch Plugin wp-jobsearch Local File Inclusion ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-52806 Patchstack
7.3 High TheBooking Plugin thebooking Broken Access Control No login needed ≤ 1.4.4 CVE-2025-52801 Patchstack
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
8.5 High Cube Portfolio Plugin cubeportfolio SQL Injection ≤ 1.16.8 CVE-2025-52823 Patchstack
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Broken Access Control No login needed ≤ 1.32.1 Fixed in 1.32.2 CVE-2025-47444 Patchstack
3.4 Low Advanced Custom Fields Plugin Content Injection An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page… prior to 6.4.3 CVE-2025-54940 jpcert
8.8 High Post SMTP Plugin post-smtp Privilege Escalation Account Takeover ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-24000 Patchstack
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.5 CVE-2025-7502 Wordfence
6.5 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird SQL Injection WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection ≤ 6.4.8 Fixed in 6.4.9 CVE-2025-6986 Wordfence
9.3 Critical WordPress Plugin wp-property Arbitrary File Upload WordPress Plugin WP-Property <= 1.35.0 PHP File Upload No login needed ≤ 1.35.0 CVE-2012-10027 VulnCheck
10.0 Critical asset-manager Plugin asset-manager Arbitrary File Upload WordPress Plugin Asset-Manager <= 2.0 PHP File Upload No login needed ≤ 2.0 CVE-2012-10026 VulnCheck
10.0 Critical WordPress Plugin advanced-custom-fields Local File Inclusion WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion No login needed ≤ 3.5.1 CVE-2012-10025 VulnCheck
7.2 High Use-your-Drive | Google Drive Plugin Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed ≤ 3.3.1 CVE-2025-7050 Wordfence
7.5 High MinimogWP – The High Converting eCommerce Theme Price Manipulation The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation No login needed ≤ 3.9.0 CVE-2025-8198 Wordfence
6.1 Medium WordPress Qwizcards Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.9.4 CVE-2025-6174 WPScan
8.8 High WPLMS Learning Management System for WordPress, WordPress LMS Theme Privilege Escalation ≤ 1.8.4.1 CVE-2015-10139 Wordfence
9.8 Critical LoginPress Pro Plugin Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 5.0.1 CVE-2025-7444 Wordfence
6.5 Medium Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read ≤ 16.8 CVE-2025-7772 Wordfence
5.3 Medium Listly: Listicles Plugin listly Broken Access Control Unauthenticated Arbitrary Transient Deletion No login needed ≤ 2.7 CVE-2025-5811 Wordfence
8.8 High School Management System Plugin wpschoolpress Local File Inclusion Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 93.1.0 CVE-2025-3740 Wordfence
9.3 Critical WP-BusinessDirectory Plugin wp-businessdirectory SQL Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-24759 Patchstack
7.5 High Easy Video Player Wordpress & WooCommerce Plugin fwdevp Path Traversal Arbitrary File Download No login needed ≤ 10.0 CVE-2025-28955 Patchstack
8.8 High Yogi Plugin yogi PHP Object Injection ≤ 2.9.3 Fixed in 2.9.3 CVE-2025-24779 Patchstack
8.8 High Hillter Theme hillter PHP Object Injection ≤ 3.0.7 CVE-2025-24777 Patchstack
9.8 Critical URL Shortener Plugin exact-links PHP Object Injection No login needed ≤ 3.0.7 CVE-2025-28961 Patchstack
9.3 Critical URL Shortener Plugin exact-links SQL Injection No login needed ≤ 3.0.7 CVE-2025-28959 Patchstack
9.3 Critical WP Pipes Plugin wp-pipes SQL Injection No login needed ≤ 1.4.3 CVE-2025-28982 Patchstack
8.6 High URL Shortener Plugin exact-links Broken Access Control No login needed ≤ 3.0.7 CVE-2025-28965 Patchstack
10.0 Critical Medical Prescription Attachment Plugin for WooCommerce Plugin medical-prescription-attachment-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 1.2.3 CVE-2025-29009 Patchstack
7.5 High Multi-language Responsive Contact Form Plugin responsive-contact-form Broken Access Control No login needed ≤ 2.8 CVE-2025-29000 Patchstack
9.8 Critical Site Chat on Telegram Plugin site-chat-on-telegram PHP Object Injection No login needed ≤ 1.0.4 Fixed in 1.0.6 CVE-2025-30949 Patchstack
9.3 Critical Torod Plugin torod SQL Injection No login needed ≤ 2.1 CVE-2025-30936 Patchstack
6.5 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30959 Patchstack
7.1 High ListingEasy Plugin listingeasy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2025-30955 Patchstack
7.1 High Electrician - Electrical Service Plugin electrician Cross-Site Scripting Electrical Service WordPress theme <= 1.0 - Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-31055 Patchstack
9.8 Critical CoSchool LMS Plugin coschool PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-30973 Patchstack
7.1 High Ofiz - WordPress Business Consulting Plugin ofiz Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31072 Patchstack
7.5 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg-cleverbakery Path Traversal WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download No login needed ≤ 2.5 Fixed in 2.5.3 CVE-2025-31070 Patchstack
7.1 High Invico - WordPress Consulting Business Plugin invico Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-31427 Patchstack
8.8 High Visual Art | Gallery Plugin visual-arts PHP Object Injection ≤ 2.4 CVE-2025-31422 Patchstack
7.1 High Wordpress Auto Spinner Plugin wp-auto-spinner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.26.0 CVE-2025-46500 Patchstack
8.5 High WPGYM Plugin gym-management SQL Injection ≤ 65.0 CVE-2025-32574 Patchstack
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
7.1 High CSS3 Compare Pricing Tables Plugin css3_web_pricing_tables_grids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.6 Fixed in 11.7 CVE-2025-47554 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 26.0.6 Fixed in 26.0.7 CVE-2025-48291 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13.4 Fixed in 2.13.5 CVE-2025-47652 Patchstack
6.5 Medium Profiler - What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed ≤ 1.0.0 CVE-2025-48339 Patchstack
9.1 Critical Groundhogg Plugin groundhogg Arbitrary File Upload ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-48300 Patchstack
7.1 High SMu Manual DoFollow Plugin manuall-dofollow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 CVE-2025-49031 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only