WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,751–7,800 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 156 of 345
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical WP Optimize By xTraffic Plugin wp-optimize-by-xtraffic PHP Object Injection No login needed ≤ 5.1.6 CVE-2025-28970 Patchstack
8.1 High SNS Vicky Theme snsvicky Local File Inclusion No login needed ≤ 3.7 CVE-2025-28990 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.3 Fixed in 4.9.4 CVE-2025-28988 Patchstack
8.6 High Content No Cache Plugin content-no-cache Remote Code Execution Arbitrary Function Call No login needed ≤ 0.1.4 Fixed in 0.1.5 CVE-2025-28993 Patchstack
7.1 High Woocommerce Line Notify Plugin woo-line-notify Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-30972 Patchstack
8.1 High SERPed.net Plugin serped-net Local File Inclusion No login needed ≤ 4.6 Fixed in 4.7 CVE-2025-28998 Patchstack
7.1 High Seven Stars Theme sevenstars Cross-Site Scripting No login needed ≤ 1.4.4 CVE-2025-31067 Patchstack
8.1 High Puca Plugin puca Local File Inclusion No login needed ≤ 2.6.33 Fixed in 2.6.34 CVE-2025-30992 Patchstack
7.1 High HYDRO Plugin hydro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 CVE-2025-31428 Patchstack
7.5 High CTUsers Plugin ctuser Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-32298 Patchstack
4.3 Medium DarkMySite Plugin darkmysite Cross-Site Request Forgery No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-32281 Patchstack
7.1 High Smart Notification Plugin smio-push-notification Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 10.3 CVE-2025-39478 Patchstack
9.3 Critical Amely Theme amely SQL Injection No login needed ≤ 3.1.4 Fixed in 3.2.0 CVE-2025-39474 Patchstack
7.1 High MagOne Theme magone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8 Fixed in 8.9 CVE-2025-39488 Patchstack
7.1 High FormLift for Infusionsoft Web Forms Plugin formlift Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.5.20 Fixed in 7.5.21 CVE-2025-47654 Patchstack
7.1 High School Management Plugin school-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 92.0.0 CVE-2025-47574 Patchstack
7.1 High Eventin Plugin wp-event-solution Cross-Site Scripting No login needed ≤ 4.0.28 Fixed in 4.0.29 CVE-2025-49321 Patchstack
7.1 High Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.8.4 Fixed in 0.5.8.5 CVE-2025-49290 Patchstack
8.1 High Greenmart Plugin greenmart Local File Inclusion No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-49883 Patchstack
8.1 High Zikzag Core Plugin zikzag-core Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-49886 Patchstack
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
7.1 High Flexo Counter Plugin flexo-countdown Cross-Site Scripting No login needed ≤ 1.0001 CVE-2025-50052 Patchstack
9.3 Critical LifterLMS Plugin lifterlms SQL Injection No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-52717 Patchstack
8.1 High Networker Theme networker Local File Inclusion No login needed ≤ 1.2.0 Fixed in 1.2.2 CVE-2025-52723 Patchstack
9.3 Critical Classiera Theme classiera SQL Injection No login needed ≤ 4.0.34 Fixed in 4.0.35 CVE-2025-52722 Patchstack
9.8 Critical CouponXxL Plugin couponxxl PHP Object Injection No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-52725 Patchstack
9.8 Critical Amwerk Theme amwerk PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-52724 Patchstack
8.6 High CouponXxL Custom Post Types Plugin couponxxl-cpt Privilege Escalation No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-52726 Patchstack
8.1 High Diza Theme diza Local File Inclusion No login needed ≤ 1.3.9 Fixed in 1.3.11 CVE-2025-52729 Patchstack
7.1 High CSS3 Vertical Web Pricing Tables Plugin css3_vertical_web_pricing_tables Cross-Site Scripting No login needed ≤ 1.9 Fixed in 2.0 CVE-2025-52727 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting No login needed ≤ 2.12.5.2 CVE-2025-52778 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting No login needed ≤ 2.15.06 CVE-2025-52774 Patchstack
8.1 High RealtyElite Plugin realtyelite Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-52808 Patchstack
7.1 High LMS Plugin lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52799 Patchstack
8.1 High National Weather Service Alerts Plugin national-weather-service-alerts Local File Inclusion No login needed ≤ 1.3.5 CVE-2025-52809 Patchstack
8.1 High Davenport - Versatile Blog and Magazine Plugin davenport Local File Inclusion Versatile Blog and Magazine WordPress Theme <= 1.3 - Local File Inclusion No login needed ≤ 1.3 CVE-2025-52811 Patchstack
8.1 High Katerio - Magazine Theme katerio Local File Inclusion Magazine theme <= 1.5.1 - Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-52810 Patchstack
8.1 High Domnoo Plugin domnoo Local File Inclusion No login needed ≤ 1.49 Fixed in 1.52.1 CVE-2025-52812 Patchstack
8.1 High CityGov Theme citygov Local File Inclusion No login needed ≤ 1.9 CVE-2025-52815 Patchstack
8.1 High BRW Plugin ova-brw Local File Inclusion No login needed ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-52814 Patchstack
8.2 High Abandoned Contact Form 7 Plugin abandoned-contact-form-7 Broken Access Control No login needed ≤ 2.2 CVE-2025-52817 Patchstack
8.1 High Zita Plugin zita Local File Inclusion No login needed ≤ 1.6.5 CVE-2025-52816 Patchstack
8.2 High Trusty Whistleblowing Plugin trusty-whistleblowing-solution Broken Access Control No login needed ≤ 2.0.1 CVE-2025-52818 Patchstack
8.8 High Sala Theme sala PHP Object Injection ≤ 1.1.3 CVE-2025-52826 Patchstack
8.8 High Mobile DJ Manager Plugin mobile-dj-manager Privilege Escalation ≤ 1.7.8.3 CVE-2025-52824 Patchstack
8.8 High Nuss Plugin nuss PHP Object Injection ≤ 1.3.3 CVE-2025-52827 Patchstack
9.3 Critical Homey Plugin homey SQL Injection No login needed ≤ 2.4.7 CVE-2025-52834 Patchstack
9.3 Critical DirectIQ Email Marketing Plugin directiq-wp SQL Injection No login needed ≤ 2.0 CVE-2025-52829 Patchstack
8.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed ≤ 2.6 CVE-2023-25998 Patchstack
7.1 High SpecFit-Virtual Try On Woocommerce Plugin try-on-for-woocommerce Cross-Site Scripting No login needed ≤ 8.0.3 CVE-2025-23973 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only