WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 751–800 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.3 Critical | Nestbyte Core | SQL Injection No login needed |
≤ 1.2 |
CVE-2025-69308 |
Patchstack | |
| 9.3 Critical | Medinik Core | SQL Injection No login needed |
≤ 1.3.6 |
CVE-2025-69307 |
Patchstack | |
| 9.3 Critical | Electio Core | SQL Injection No login needed |
≤ 1.4 |
CVE-2025-69306 |
Patchstack | |
| 9.3 Critical | Crete Core | SQL Injection No login needed |
≤ 1.4.3 |
CVE-2025-69305 |
Patchstack | |
| 9.3 Critical | Allmart | SQL Injection No login needed |
≤ 1.1 |
CVE-2025-69304 |
Patchstack | |
| 9.8 Critical | PhotoMe | PHP Object Injection No login needed |
≤ 5.6.11 |
CVE-2025-69301 |
Patchstack | |
| 9.3 Critical | Coven Core | SQL Injection No login needed |
≤ 1.3 |
CVE-2025-69295 |
Patchstack | |
| 9.9 Critical | Wiguard | Arbitrary File Upload |
≤ 2.0.1 Fixed in 2.0.1 |
CVE-2025-68549 |
Patchstack | |
| 9.8 Critical | Ippsum | PHP Object Injection No login needed |
≤ 1.2.0 Fixed in 1.2.1 |
CVE-2025-68541 |
Patchstack | |
| 9.8 Critical | Travelicious | PHP Object Injection No login needed |
≤ 1.6.7 Fixed in 1.6.7 |
CVE-2025-67997 |
Patchstack | |
| 9.8 Critical | Nestin | PHP Object Injection No login needed |
≤ 1.2.6 Fixed in 1.2.6 |
CVE-2025-67996 |
Patchstack | |
| 9.8 Critical | PatioTime | PHP Object Injection No login needed |
≤ 2.1 Fixed in 2.1 |
CVE-2025-67995 |
Patchstack | |
| 9.9 Critical | WPForms Google Sheet Connector | Remote Code Execution |
≤ 4.0.1 Fixed in 4.0.2 |
CVE-2025-67979 |
Patchstack | |
| 9.8 Critical | WpEvently | PHP Object Injection No login needed |
≤ 5.1.1 Fixed in 5.1.2 |
CVE-2026-23549 |
Patchstack | |
| 9.8 Critical | Grand Restaurant | PHP Object Injection No login needed |
≤ 7.0.10 Fixed in 7.0.11 |
CVE-2026-23542 |
Patchstack | |
| 9.8 Critical | s2Member | Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed |
≤ 260127 |
CVE-2026-1994 |
Wordfence | |
| 9.8 Critical | Buyent Theme (with Buyent Classified Plugin) | Privilege Escalation Unauthenticated Privilege Escalation via User Registration No login needed |
≤ 1.0.7 |
CVE-2025-13851 |
Wordfence | |
| 9.8 Critical | Prodigy Commerce | Local File Inclusion Unauthenticated Local File Inclusion via parameters[template_name] No login needed |
≤ 3.3.0 |
CVE-2026-0926 |
Wordfence | |
| 9.8 Critical | Lizza LMS Pro | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.3 |
CVE-2025-13563 |
Wordfence | |
| 9.8 Critical | Slider Future | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.0.5 |
CVE-2026-1405 |
Wordfence | |
| 9.8 Critical | Clasifico Listing | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 2.0 |
CVE-2025-12882 |
Wordfence | |
| 9.8 Critical | Spam protection, Honeypot, Anti-Spam by CleanTalk | Broken Access Control Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation No login needed |
≤ 6.71 |
CVE-2026-1490 |
Wordfence | |
| 9.8 Critical | Truelysell Core | Privilege Escalation Unauthenticated Privilege Escalation via Registration No login needed |
≤ 1.8.7 |
CVE-2025-8572 |
Wordfence | |
| 9.8 Critical | midi-Synth | Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'export' AJAX Action No login needed |
≤ 1.1.0 |
CVE-2026-1306 |
Wordfence | |
| 9.8 Critical | Prime Listing Manager | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.1 |
CVE-2025-14892 |
WPScan | |
| 9.8 Critical | AdForest | Authentication Bypass No login needed |
≤ 6.0.12 |
CVE-2026-1729 |
Wordfence | |
| 9.8 Critical | Migration, Backup, Staging | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 0.9.123 |
CVE-2026-1357 |
Wordfence | |
| 9.8 Critical | JAY Login & Register | Privilege Escalation Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user No login needed |
≤ 2.6.03 |
CVE-2025-15027 |
Wordfence | |
| 9.8 Critical | User Profile Builder | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
1.1.27 – < 3.15.2 Fixed in 3.15.2 |
CVE-2025-15030 |
WPScan | |
| 9.8 Critical | Snow Monkey Forms | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed |
≤ 12.0.3 |
CVE-2026-1056 |
Wordfence | |
| 9.8 Critical | Kalrav AI Agent | Arbitrary File Upload Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action No login needed |
≤ 2.3.3 |
CVE-2025-13374 |
Wordfence | |
| 9.1 Critical | Xpro Elementor Addons | Arbitrary File Upload |
≤ 1.4.19.1 Fixed in 1.4.20 |
CVE-2025-69312 |
Patchstack | |
| 9.8 Critical | Workreap Core | Authentication Bypass Broken Authentication No login needed |
≤ 3.4.1 |
CVE-2025-69101 |
Patchstack | |
| 9.8 Critical | Sound | Musical Instruments Online Store | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 1.6.9 |
CVE-2025-69079 |
Patchstack | |
| 9.8 Critical | Registration & Login with Mobile Phone Number for WooCommerce | Broken Access Control No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-69052 |
Patchstack | |
| 9.9 Critical | Miion | Arbitrary File Upload |
≤ 1.2.7 |
CVE-2025-68986 |
Patchstack | |
| 9.9 Critical | Blogzee | Arbitrary File Upload |
≤ 1.0.5 |
CVE-2025-68910 |
Patchstack | |
| 9.9 Critical | Blogistic | Arbitrary File Upload |
≤ 1.0.5 |
CVE-2025-68909 |
Patchstack | |
| 9.8 Critical | LazyTasks | Privilege Escalation No login needed |
≤ 1.2.37 Fixed in 1.3.01 |
CVE-2025-68869 |
Patchstack | |
| 9.3 Critical | Paid Downloads | SQL Injection No login needed |
≤ 3.15 |
CVE-2025-68857 |
Patchstack | |
| 9.3 Critical | CleverReach® WP | SQL Injection No login needed |
≤ 1.5.21 Fixed in 1.5.22 |
CVE-2025-68034 |
Patchstack | |
| 9.4 Critical | Order Listener for WooCommerce | Broken Access Control No login needed |
≤ 3.6.1 Fixed in 3.6.2 |
CVE-2025-68018 |
Patchstack | |
| 9.0 Critical | Event Tickets with Ticket Scanner | Remote Code Execution No login needed |
≤ 2.8.5 Fixed in 2.8.6 |
CVE-2025-68015 |
Patchstack | |
| 10.0 Critical | g-FFL Checkout | Arbitrary File Upload No login needed |
≤ 2.1.0 Fixed in 2.1.1 |
CVE-2025-68001 |
Patchstack | |
| 9.9 Critical | Real Homes CRM | Arbitrary File Upload |
≤ 1.0.0 Fixed in 1.0.1 |
CVE-2025-67968 |
Patchstack | |
| 9.3 Critical | MailerLite – WooCommerce integration | SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2025-67945 |
Patchstack | |
| 9.1 Critical | Nelio AB Testing | Remote Code Execution Arbitrary Code Execution |
≤ 8.1.8 Fixed in 8.2.0 |
CVE-2025-67944 |
Patchstack | |
| 9.8 Critical | Consult Aid | PHP Object Injection No login needed |
≤ 1.4.3 |
CVE-2025-67617 |
Patchstack | |
| 9.9 Critical | News Event | Arbitrary File Upload |
≤ 1.0.1 Fixed in 1.0.2 |
CVE-2025-62056 |
Patchstack | |
| 9.9 Critical | Blogmatic | Arbitrary File Upload |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2025-62050 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.