WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 7,901–7,950 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 159 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical SevenHills Theme sevenhills PHP Object Injection No login needed ≤ 1.6.2 CVE-2025-69372 Patchstack
9.8 Critical KindlyCare Theme kindlycare PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-69371 Patchstack
9.8 Critical Capella Theme capella PHP Object Injection No login needed ≤ 2.5.5 CVE-2025-69370 Patchstack
7.1 High SOHO - Photography Theme soho Cross-Site Scripting Photography WordPress Theme theme <= 3.0.3 - Cross Site Scripting (XSS) No login needed ≤ 3.0.3 CVE-2025-69368 Patchstack
7.1 High Oyster - Photography Theme oyster Cross-Site Scripting Photography WordPress Theme theme <= 4.4.3 - Cross Site Scripting (XSS) No login needed ≤ 4.4.3 CVE-2025-69367 Patchstack
9.3 Critical Emerce Core Plugin emerce-core SQL Injection No login needed ≤ 1.8 CVE-2025-69366 Patchstack
9.3 Critical Uroan Core Plugin uroan-core SQL Injection No login needed ≤ 1.4.4 CVE-2025-69365 Patchstack
9.3 Critical Wolmart Core Plugin wolmart-core SQL Injection No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-69337 Patchstack
7.1 High Prestige Theme prestige Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.1 CVE-2025-69330 Patchstack
9.8 Critical Prestige Theme prestige PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.1 CVE-2025-69329 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69326 Patchstack
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69324 Patchstack
7.1 High Slimstat Analytics Plugin wp-slimstat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.2 Fixed in 5.3.3 CVE-2025-69323 Patchstack
8.1 High PeakShops Theme peakshops Local File Inclusion No login needed ≤ 1.5.9 Fixed in 1.5.9 CVE-2025-69322 Patchstack
9.3 Critical Woodly Core Plugin woodly-core SQL Injection No login needed ≤ 1.4 CVE-2025-69310 Patchstack
9.3 Critical Saasplate Core Plugin saasplate-core SQL Injection No login needed ≤ 1.2.8 CVE-2025-69309 Patchstack
9.3 Critical Nestbyte Core Plugin nestbyte-core SQL Injection No login needed ≤ 1.2 CVE-2025-69308 Patchstack
9.3 Critical Medinik Core Plugin medinik-core SQL Injection No login needed ≤ 1.3.6 CVE-2025-69307 Patchstack
9.3 Critical Electio Core Plugin electio-core SQL Injection No login needed ≤ 1.4 CVE-2025-69306 Patchstack
9.3 Critical Crete Core Plugin crete-core SQL Injection No login needed ≤ 1.4.3 CVE-2025-69305 Patchstack
9.3 Critical Allmart Plugin allmart-core SQL Injection No login needed ≤ 1.1 CVE-2025-69304 Patchstack
7.5 High ModelTheme Framework Plugin modeltheme-framework Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.0 CVE-2025-69303 Patchstack
7.1 High DesignThemes Core Features Plugin designthemes-core-features Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-69302 Patchstack
9.8 Critical PhotoMe Theme photome PHP Object Injection No login needed ≤ 5.6.11 CVE-2025-69301 Patchstack
7.2 High Oxygen Theme oxygen Server-Side Request Forgery No login needed ≤ 6.0.8 CVE-2025-69299 Patchstack
7.5 High Gauge Theme gauge Broken Access Control No login needed ≤ 6.56.4 CVE-2025-69298 Patchstack
7.5 High Aardvark Plugin aardvark-plugin Broken Access Control No login needed ≤ 2.19 CVE-2025-69297 Patchstack
7.1 High Aardvark Theme aardvark Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.6.3 CVE-2025-69296 Patchstack
9.3 Critical Coven Core Plugin coven-core SQL Injection No login needed ≤ 1.3 CVE-2025-69295 Patchstack
8.8 High PeakShops Theme peakshops PHP Object Injection ≤ 1.5.9 CVE-2025-69294 Patchstack
8.6 High New User Approve Plugin new-user-approve Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-69063 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
6.5 Medium AhaChat Messenger Marketing Plugin ahachat-messenger-marketing Authentication Bypass Broken Authentication No login needed ≤ 1.1 CVE-2025-68895 Patchstack
7.1 High Simple Archive Generator Plugin simple-archive-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2 CVE-2025-68880 Patchstack
7.1 High iContact for Gravity Forms Plugin gravity-forms-icontact Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-68863 Patchstack
7.7 High Woo File Dropzone Plugin woo-file-dropzone Arbitrary File Deletion ≤ 1.1.7 CVE-2025-68862 Patchstack
7.1 High Mopinion Feedback Form Plugin mopinion-feedback-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-68856 Patchstack
5.9 Medium JobBoard Job listing Plugin job-board-light Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.8 CVE-2025-68855 Patchstack
7.1 High ID Arrays Plugin id-arrays Cross-Site Scripting POST-Based Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-68854 Patchstack
8.8 High Contact Manager Plugin contact-manager PHP Object Injection No login needed ≤ 9.1.1 CVE-2025-68853 Patchstack
7.1 High Court Reservation Plugin court-reservation Cross-Site Scripting No login needed ≤ 1.10.13 CVE-2025-68852 Patchstack
7.1 High amr cron manager Plugin amr-cron-manager Cross-Site Scripting Reflecte dCross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-68848 Patchstack
7.1 High iSape Plugin isape Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.72 CVE-2025-68847 Patchstack
7.1 High Asynchronous Javascript Plugin asynchronous-javascript Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 CVE-2025-68846 Patchstack
7.1 High eDS Responsive Menu Plugin eds-responsive-menu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-68845 Patchstack
7.1 High Membee Login Plugin membees-member-login-widget Cross-Site Scripting No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68844 Patchstack
7.1 High FeedWordPress Advanced Filters Plugin faf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.2 CVE-2025-68843 Patchstack
7.1 High Widget Logic Visual Plugin widget-logic-visual Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.52 CVE-2025-68842 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only