WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Sweet Dessert Theme sweet-dessert PHP Object Injection No login needed ≤ 1.1.13 Fixed in 1.1.13 CVE-2025-49073 Patchstack
9.0 Critical Motors - Events Plugin stm-motors-events Local File Inclusion Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.7 CVE-2025-47586 Patchstack
9.8 Critical Course Builder Plugin course-builder PHP Object Injection No login needed ≤ 3.6.6 Fixed in 3.6.6 CVE-2025-48336 Patchstack
9.8 Critical Dash Theme dash PHP Object Injection No login needed ≤ 1.3 CVE-2025-31049 Patchstack
9.3 Critical WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce Plugin whatscart-for-woocommerce SQL Injection No login needed ≤ 1.1.0 CVE-2025-31056 Patchstack
9.3 Critical Bus Ticket Booking with Seat Reservation for WooCommerce Plugin scw-bus-seat-reservation SQL Injection No login needed ≤ 1.7 CVE-2025-31397 Patchstack
9.8 Critical HotStar – Multi-Purpose Business Theme hotstar PHP Object Injection Multi-Purpose Business Theme <= 1.4 - PHP Object Injection No login needed ≤ 1.4 CVE-2025-31069 Patchstack
9.8 Critical The Business Theme nrgbusiness PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-31430 Patchstack
9.8 Critical Umberto Theme umberto PHP Object Injection No login needed ≤ 1.2.8 CVE-2025-31423 Patchstack
9.8 Critical Fish House Theme fish-house PHP Object Injection No login needed ≤ 1.2.7 CVE-2025-31631 Patchstack
9.3 Critical Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder SQL Injection No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-31914 Patchstack
9.0 Critical JP Students Result Management System Premium Plugin jp-students-result-system-premium Arbitrary File Upload No login needed 1.1.7 CVE-2025-31916 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-31918 Patchstack
9.8 Critical Acerola Theme acerola PHP Object Injection No login needed ≤ 1.6.5 CVE-2025-31927 Patchstack
9.8 Critical Jarvis – Night Club, Concert, Festival Theme jarvis PHP Object Injection Night Club, Concert, Festival WordPress theme <= 1.8.11 - PHP Object Injection No login needed ≤ 1.8.11 CVE-2025-32292 Patchstack
9.8 Critical Grand Tour Plugin grandtour PHP Object Injection No login needed ≤ 5.6 CVE-2025-39485 Patchstack
9.8 Critical Car Dealer Theme cardealer PHP Object Injection No login needed ≤ 1.6.8 Fixed in 1.6.8 CVE-2025-39480 Patchstack
9.8 Critical CouponXL Theme couponxl Privilege Escalation No login needed ≤ 4.5.0 Fixed in 4.5.1 CVE-2025-39489 Patchstack
9.8 Critical Medicare Plugin medicare PHP Object Injection No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-39499 Patchstack
9.8 Critical Avantage Plugin avantage PHP Object Injection No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-39495 Patchstack
9.3 Critical Goodlayers Hostel Plugin gdlr-hostel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39501 Patchstack
9.8 Critical Goodlayers Hostel Plugin gdlr-hostel PHP Object Injection No login needed ≤ 3.1.2 CVE-2025-39500 Patchstack
9.8 Critical Goodlayers Hotel Plugin gdlr-hotel PHP Object Injection No login needed ≤ 3.1.4 CVE-2025-39503 Patchstack
9.3 Critical Goodlayers Hotel Plugin gdlr-hotel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39504 Patchstack
9.3 Critical WP HRM LITE Plugin wp-hrm-lite-human-resource-management-system SQL Injection No login needed ≤ 1.1 CVE-2025-46455 Patchstack
9.3 Critical Easy Guide Plugin wp-easy-guide SQL Injection No login needed ≤ 1.0.0 CVE-2025-46460 Patchstack
9.8 Critical Fable Extra Plugin fable-extra Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46468 Patchstack
9.9 Critical Crossword Compiler Puzzles Plugin crossword-compiler-puzzles Arbitrary File Upload ≤ 5.2 Fixed in 5.3 CVE-2025-46490 Patchstack
9.3 Critical Fable Extra Plugin fable-extra SQL Injection No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46539 Patchstack
9.8 Critical CoinPayments.net Payment Gateway for WooCommerce Plugin coinpayments-payment-gateway-for-woocommerce PHP Object Injection No login needed ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47532 Patchstack
9.8 Critical WPFunnels Plugin wpfunnels PHP Object Injection No login needed ≤ 3.5.18 Fixed in 3.5.19 CVE-2025-47530 Patchstack
9.8 Critical Eventin Plugin wp-event-solution Privilege Escalation No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2025-47539 Patchstack
9.3 Critical Facturante Plugin facturante SQL Injection No login needed ≤ 1.11 Fixed in 1.13 CVE-2025-47599 Patchstack
9.8 Critical ZoomSounds Plugin dzs-zoomsounds PHP Object Injection No login needed ≤ 6.91 CVE-2025-47568 Patchstack
10.0 Critical STAGGS Plugin staggs Arbitrary File Upload No login needed ≤ 2.11.0 Fixed in 2.12.0 CVE-2025-47637 Patchstack
10.0 Critical Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Arbitrary File Upload No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-47641 Patchstack
9.3 Critical Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-47640 Patchstack
9.9 Critical ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Arbitrary File Upload ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-47658 Patchstack
9.8 Critical PSW Front-end Login & Registration Plugin psw-login-and-registration Authentication Bypass Broken Authentication No login needed ≤ 1.13 CVE-2025-47646 Patchstack
10.0 Critical Ajar in5 Embed Plugin ajar-productions-in5-embed Arbitrary File Upload No login needed ≤ 3.1.5 CVE-2025-47642 Patchstack
9.9 Critical Hospital Management System Plugin hospital-management Arbitrary File Upload 47.0(20 – 11 CVE-2025-47663 Patchstack
10.0 Critical StoreKeeper for WooCommerce Plugin storekeeper-for-woocommerce Arbitrary File Upload No login needed ≤ 14.4.4 Fixed in 14.4.5 CVE-2025-47687 Patchstack
9.3 Critical Majestic Support Plugin majestic-support SQL Injection No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-48283 Patchstack
9.8 Critical Kids Planet Theme kidsplanet PHP Object Injection No login needed ≤ 2.2.14 Fixed in 2.2.14.1 CVE-2025-48289 Patchstack
9.8 Critical Pix 4x sem juros - Pagaleve Plugin wc-pagaleve PHP Object Injection Pagaleve plugin <= 1.6.9 - PHP Object Injection No login needed ≤ 1.6.9 Fixed in 1.6.10 CVE-2025-48287 Patchstack
9.8 Critical Madara – Responsive and modern WordPress theme for manga sites Theme Local File Inclusion Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion No login needed ≤ 2.2.2 CVE-2025-4524 Wordfence
9.8 Critical User Profile Meta Manager Plugin user-profile-meta Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.02 CVE-2025-48340 Patchstack
9.8 Critical Grand Restaurant Plugin grandrestaurant Path Traversal Path Traversal to PHP Object Injection No login needed ≤ 7.0 CVE-2025-32926 Patchstack
9.8 Critical FoodBakery Plugin wp-foodbakery PHP Object Injection No login needed ≤ 3.3 CVE-2025-32927 Patchstack
9.8 Critical Altair Theme altair PHP Object Injection No login needed ≤ 5.2.2 CVE-2025-32928 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only