WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,901–7,950 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 159 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
5.9 Medium File Manager Pro Plugin filester Cross-Site Scripting ≤ 1.8.8 Fixed in 1.8.9 CVE-2025-52710 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.7 Fixed in 1.3.7.1 CVE-2025-52708 Patchstack
6.5 Medium Firelight Lightbox Plugin easy-fancybox Cross-Site Scripting ≤ 2.3.16 Fixed in 2.3.17 CVE-2025-52707 Patchstack
4.3 Medium Breeze Plugin breeze Broken Access Control ≤ 2.2.13 Fixed in 2.2.14 CVE-2025-23999 Patchstack
7.1 High eForm - WordPress Form Builder Plugin wp-fsqm-pro Cross-Site Scripting WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) No login needed ≤ 4.19.1 Fixed in 4.19.1 CVE-2025-48333 Patchstack
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
7.5 High Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Plugin aeroscroll-gallery Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed ≤ 1.0.13 CVE-2025-49451 Patchstack
10.0 Critical Flozen Plugin flozen-theme Arbitrary File Upload No login needed ≤ 1.5.1 Fixed in 1.5.1 CVE-2025-49071 Patchstack
8.1 High CozyStay Theme cozystay Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2025-49508 Patchstack
9.3 Critical PostaPanduri Plugin postapanduri SQL Injection No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-49452 Patchstack
7.6 High WP Employee Attendance System Plugin wp-employee-attendance-system SQL Injection ≤ 3.5 CVE-2025-28972 Patchstack
9.3 Critical WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm SQL Injection CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection No login needed ≤ 3.2.0 CVE-2025-24773 Patchstack
8.1 High DSK Plugin dsk Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-24761 Patchstack
8.1 High Simen Plugin snssimen Local File Inclusion No login needed ≤ 4.6 CVE-2025-29002 Patchstack
8.1 High Evon Plugin snsevon Local File Inclusion No login needed ≤ 3.4 CVE-2025-28991 Patchstack
9.8 Critical Rapyd Payment Extension for WooCommerce Plugin rapyd-payments PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-30618 Patchstack
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
9.8 Critical Spare Theme spare PHP Object Injection No login needed ≤ 1.7 CVE-2025-31919 Patchstack
7.1 High Elite Video Player Plugin elite-video-player Cross-Site Scripting No login needed ≤ 10.0.5 CVE-2025-30988 Patchstack
7.5 High WPGYM Plugin gym-management Local File Inclusion ≤ 65.0 CVE-2025-32549 Patchstack
10.0 Critical Ovatheme Events Manager Plugin ova-events-manager Arbitrary File Upload No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-32510 Patchstack
8.5 High Rankie Plugin valvepress-rankie SQL Injection ≤ 1.8.2 Fixed in 1.8.2 CVE-2025-39486 Patchstack
9.3 Critical Smart Notification Plugin smio-push-notification SQL Injection No login needed ≤ 10.3 CVE-2025-39479 Patchstack
9.9 Critical WP VR Plugin wpvr Arbitrary File Upload ≤ 8.5.26 Fixed in 8.5.27 CVE-2025-47452 Patchstack
7.1 High Nasa Core Plugin nasa-core Cross-Site Scripting No login needed ≤ 6.4.4 Fixed in 6.4.4 CVE-2025-39508 Patchstack
7.5 High School Management Plugin school-management Local File Inclusion ≤ 93.0.0 CVE-2025-47572 Patchstack
9.9 Critical MapSVG Plugin mapsvg Arbitrary File Upload ≤ 8.7.4 Fixed in 8.7.4 CVE-2025-47559 Patchstack
8.5 High Woocommerce Partial Shipment Plugin wc-partial-shipment SQL Injection ≤ 3.2 Fixed in 3.3 CVE-2025-48118 Patchstack
9.3 Critical School Management Plugin school-management SQL Injection No login needed ≤ 92.0.0 CVE-2025-47573 Patchstack
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48274 Patchstack
7.1 High Track, Analyze & Optimize by WP Tao Plugin wp-tao Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-48145 Patchstack
8.1 High Fana Plugin fana Local File Inclusion No login needed ≤ 1.1.28 Fixed in 1.1.29 CVE-2025-49251 Patchstack
6.5 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control Arbitrary User Deletion ≤ 3.4.6 Fixed in 4.0.0 CVE-2025-49234 Patchstack
8.1 High Lasa Plugin lasa Local File Inclusion No login needed ≤ 1.1 Fixed in 1.1.1 CVE-2025-49253 Patchstack
8.1 High Besa Plugin besa Local File Inclusion No login needed ≤ 2.3.8 Fixed in 2.3.10 CVE-2025-49252 Patchstack
8.1 High Ruza Plugin ruza Local File Inclusion No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49255 Patchstack
8.1 High Nika Plugin nika Local File Inclusion No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-49254 Patchstack
8.1 High Zota Plugin zota Local File Inclusion No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-49257 Patchstack
8.1 High Sapa Plugin sapa Local File Inclusion No login needed ≤ 1.1.14 Fixed in 1.1.15 CVE-2025-49256 Patchstack
8.1 High Hara Plugin hara Local File Inclusion No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-49259 Patchstack
8.1 High Maia Plugin maia Local File Inclusion No login needed ≤ 1.1.15 Fixed in 1.1.16 CVE-2025-49258 Patchstack
8.1 High Diza Theme diza Local File Inclusion No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-49261 Patchstack
8.1 High Aora Theme aora Local File Inclusion No login needed ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-49260 Patchstack
7.1 High Echo RSS Feed Post Generator Plugin rss-feed-post-generator-echo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8.1 Fixed in 5.4.9 CVE-2025-49312 Patchstack
7.1 High Ultimate Reviews Plugin ultimate-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.14 Fixed in 3.2.15 CVE-2025-49266 Patchstack
9.8 Critical Integration for Contact Form 7 and Zoho CRM, Bigin Plugin cf7-zoho PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-49330 Patchstack
7.1 High WP2LEADS Plugin wp2leads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-49316 Patchstack
7.6 High Slim SEO Plugin slim-seo SQL Injection ≤ 4.5.4 Fixed in 4.5.5 CVE-2025-49854 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only