WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,551–7,600 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 152 of 345
Severity Component Vulnerability Affected versions Published CVE Source
9.6 Critical FluentSnippets Plugin easy-code-manager Cross-Site Request Forgery No login needed ≤ 10.50 Fixed in 10.51 CVE-2025-54010 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Cross-Site Scripting ≤ 3.6.8 Fixed in 3.6.8.1 CVE-2025-54009 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-54006 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 4.0.4 Fixed in 4.1.1 CVE-2025-53997 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.5.10.1 Fixed in 3.5.11 CVE-2025-53996 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15.1 Fixed in 2.0.16 CVE-2025-53995 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53994 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53991 Patchstack
7.2 High JetFormBuilder Plugin jetformbuilder PHP Object Injection ≤ 3.5.1.2 Fixed in 3.5.2 CVE-2025-53990 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.19 Fixed in 1.3.19.1 CVE-2025-53989 Patchstack
5.3 Medium Hestia Plugin hestia Broken Access Control No login needed ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-53986 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53984 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53982 Patchstack
8.1 High Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin wp-malware-removal Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.0 CVE-2025-6043 Wordfence
9.8 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed ≤ 7.8.3 CVE-2025-5394 Wordfence
9.1 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed ≤ 7.8.5 CVE-2025-5393 Wordfence
8.8 High Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.3 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 1.6.3 CVE-2025-1313 Wordfence
7.5 High WPGYM - Wordpress Gym Management System Plugin SQL Injection Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection No login needed < 67.8.0 Fixed in 67.8.0 CVE-2025-7442 Wordfence
9.8 Critical Premium Age Verification / Restriction Plugin Path Traversal Unauthenticated Arbitrary File Read and Write via remote_tunnel.php No login needed ≤ 3.0.2 CVE-2025-7401 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms PHP Object Injection Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6742 Wordfence
8.1 High SureForms – Drag and Drop Form Builder Plugin sureforms Arbitrary File Deletion Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6691 Wordfence
9.8 Critical Sala - Startup & SaaS Theme Privilege Escalation Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 1.1.4 CVE-2025-4606 Wordfence
10.0 Critical Pie Register Plugin pie-register Authentication Bypass WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE No login needed ≤ 3.7.1.4 CVE-2025-34077 VulnCheck
5.3 Medium Guest Support – Complete customer support ticket system Plugin guest-support Broken Access Control Complete customer support ticket system for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Ticket Deletion No login needed ≤ 1.2.2 CVE-2025-5957 Wordfence
6.4 Medium Lightbox & Modal Popup WordPress Plugin – FooBox Plugin foobox-image-lightbox Cross-Site Scripting FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.7.34 CVE-2025-5537 Wordfence
7.1 High Zilom Plugin zilom Cross-Site Scripting No login needed ≤ 1.4.5 Fixed in 1.4.5 CVE-2024-43334 Patchstack
7.1 High Content Manager Light Plugin content-manager-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2 CVE-2025-24771 Patchstack
9.8 Critical Service Finder Booking Plugin sf-booking Privilege Escalation No login needed ≤ 6.1 CVE-2025-23970 Patchstack
7.1 High WP Wall Plugin wp-wall Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-28968 Patchstack
8.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24780 Patchstack
7.1 High SB Breadcrumbs Plugin sb-breadcrumbs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-28978 Patchstack
6.5 Medium Email Address Security by WebEmailProtector Plugin webemailprotector Cross-Site Scripting ≤ 3.3.6 CVE-2025-28976 Patchstack
9.8 Critical Click & Pledge Connect Plugin click-pledge-connect Privilege Escalation Privilege Escalation via SQL Injection No login needed 25.04010101 – WP6.8 CVE-2025-28983 Patchstack
7.7 High Aviation Weather from NOAA Plugin aviation-weather-from-noaa Arbitrary File Deletion ≤ 0.7.2 CVE-2025-28980 Patchstack
7.1 High Homey Plugin homey Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2025-31037 Patchstack
10.0 Critical LogisticsHub Plugin logistics-hub Arbitrary File Upload No login needed ≤ 1.1.6 CVE-2025-30933 Patchstack
7.1 High Pressroom Theme pressroom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0 Fixed in 7.1 CVE-2025-32311 Patchstack
8.5 High Simple Link Directory Plugin qc-simple-link-directory SQL Injection ≤ 14.8.1 Fixed in 14.8.1 CVE-2025-32297 Patchstack
5.3 Medium WP Compress Plugin wp-compress-image-optimizer Authentication Bypass Broken Authentication No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47479 Patchstack
7.1 High Rankie Plugin valvepress-rankie Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-39487 Patchstack
6.3 Medium EventON Plugin eventon Broken Access Control ≤ 4.9.9 CVE-2025-47565 Patchstack
6.5 Medium WC Pickup Store Plugin wc-pickup-store Broken Access Control Settings Change No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2025-47634 Patchstack
7.5 High PrivateContent - Mail Actions Plugin private-content-mail-actions Local File Inclusion Mail Actions plugin <= 2.3.2 - Local File Inclusion No login needed ≤ 2.3.2 CVE-2025-47627 Patchstack
7.1 High Testimonials Showcase Plugin testimonials-showcase Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49245 Patchstack
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
7.1 High Neom Blog Plugin neom-blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.9 Fixed in 0.1.0 CVE-2025-49274 Patchstack
7.1 High Team Showcase Plugin team-showcase-cm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49247 Patchstack
6.8 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Path Traversal Arbitrary File Download ≤ 3.28.7 Fixed in 3.28.8 CVE-2025-49303 Patchstack
10.0 Critical Easy Stripe Plugin easy-stripe Remote Code Execution No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-49302 Patchstack
9.8 Critical RealHomes Plugin realhomes Privilege Escalation No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-49867 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only