WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Nestbyte Core Plugin nestbyte-core SQL Injection No login needed ≤ 1.2 CVE-2025-69308 Patchstack
9.3 Critical Medinik Core Plugin medinik-core SQL Injection No login needed ≤ 1.3.6 CVE-2025-69307 Patchstack
9.3 Critical Electio Core Plugin electio-core SQL Injection No login needed ≤ 1.4 CVE-2025-69306 Patchstack
9.3 Critical Crete Core Plugin crete-core SQL Injection No login needed ≤ 1.4.3 CVE-2025-69305 Patchstack
9.3 Critical Allmart Plugin allmart-core SQL Injection No login needed ≤ 1.1 CVE-2025-69304 Patchstack
9.8 Critical PhotoMe Theme photome PHP Object Injection No login needed ≤ 5.6.11 CVE-2025-69301 Patchstack
9.3 Critical Coven Core Plugin coven-core SQL Injection No login needed ≤ 1.3 CVE-2025-69295 Patchstack
9.9 Critical Wiguard Theme wiguard Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68549 Patchstack
9.8 Critical Ippsum Theme ippsum PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-68541 Patchstack
9.8 Critical Travelicious Theme travelicious PHP Object Injection No login needed ≤ 1.6.7 Fixed in 1.6.7 CVE-2025-67997 Patchstack
9.8 Critical Nestin Theme nestin PHP Object Injection No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-67996 Patchstack
9.8 Critical PatioTime Theme patiotime PHP Object Injection No login needed ≤ 2.1 Fixed in 2.1 CVE-2025-67995 Patchstack
9.9 Critical WPForms Google Sheet Connector Plugin gsheetconnector-wpforms Remote Code Execution ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-67979 Patchstack
9.8 Critical WpEvently Plugin mage-eventpress PHP Object Injection No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-23549 Patchstack
9.8 Critical Grand Restaurant Plugin grandrestaurant PHP Object Injection No login needed ≤ 7.0.10 Fixed in 7.0.11 CVE-2026-23542 Patchstack
9.8 Critical s2Member Plugin s2member Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 260127 CVE-2026-1994 Wordfence
9.8 Critical Buyent Theme (with Buyent Classified Plugin) Plugin Privilege Escalation Unauthenticated Privilege Escalation via User Registration No login needed ≤ 1.0.7 CVE-2025-13851 Wordfence
9.8 Critical Prodigy Commerce Plugin prodigy-commerce Local File Inclusion Unauthenticated Local File Inclusion via parameters[template_name] No login needed ≤ 3.3.0 CVE-2026-0926 Wordfence
9.8 Critical Lizza LMS Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2025-13563 Wordfence
9.8 Critical Slider Future Plugin slider-future Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2026-1405 Wordfence
9.8 Critical Clasifico Listing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0 CVE-2025-12882 Wordfence
9.8 Critical Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin cleantalk-spam-protect Broken Access Control Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 6.71 CVE-2026-1490 Wordfence
9.8 Critical Truelysell Core Plugin Privilege Escalation Unauthenticated Privilege Escalation via Registration No login needed ≤ 1.8.7 CVE-2025-8572 Wordfence
9.8 Critical midi-Synth Plugin midi-synth Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'export' AJAX Action No login needed ≤ 1.1.0 CVE-2026-1306 Wordfence
9.8 Critical Prime Listing Manager Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.1 CVE-2025-14892 WPScan
9.8 Critical AdForest Theme Authentication Bypass No login needed ≤ 6.0.12 CVE-2026-1729 Wordfence
9.8 Critical Migration, Backup, Staging Plugin wpvivid-backuprestore Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 0.9.123 CVE-2026-1357 Wordfence
9.8 Critical JAY Login & Register Plugin jay-login-register Privilege Escalation Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user No login needed ≤ 2.6.03 CVE-2025-15027 Wordfence
9.8 Critical User Profile Builder Plugin profile-builder Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed 1.1.27 – < 3.15.2 Fixed in 3.15.2 CVE-2025-15030 WPScan
9.8 Critical Snow Monkey Forms Plugin snow-monkey-forms Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed ≤ 12.0.3 CVE-2026-1056 Wordfence
9.8 Critical Kalrav AI Agent Plugin kalrav-ai-agent Arbitrary File Upload Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action No login needed ≤ 2.3.3 CVE-2025-13374 Wordfence
9.1 Critical Xpro Elementor Addons Plugin xpro-elementor-addons Arbitrary File Upload ≤ 1.4.19.1 Fixed in 1.4.20 CVE-2025-69312 Patchstack
9.8 Critical Workreap Core Plugin workreap_core Authentication Bypass Broken Authentication No login needed ≤ 3.4.1 CVE-2025-69101 Patchstack
9.8 Critical Sound | Musical Instruments Online Store Theme musicplace PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.6.9 CVE-2025-69079 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin registration-login-with-mobile-phone-number Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-69052 Patchstack
9.9 Critical Miion Plugin miion Arbitrary File Upload ≤ 1.2.7 CVE-2025-68986 Patchstack
9.9 Critical Blogzee Plugin blogzee Arbitrary File Upload ≤ 1.0.5 CVE-2025-68910 Patchstack
9.9 Critical Blogistic Plugin blogistic Arbitrary File Upload ≤ 1.0.5 CVE-2025-68909 Patchstack
9.8 Critical LazyTasks Plugin lazytasks-project-task-management Privilege Escalation No login needed ≤ 1.2.37 Fixed in 1.3.01 CVE-2025-68869 Patchstack
9.3 Critical Paid Downloads Plugin paid-downloads SQL Injection No login needed ≤ 3.15 CVE-2025-68857 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.21 Fixed in 1.5.22 CVE-2025-68034 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack
9.0 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2025-68015 Patchstack
10.0 Critical g-FFL Checkout Plugin g-ffl-checkout Arbitrary File Upload No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-68001 Patchstack
9.9 Critical Real Homes CRM Plugin realhomes-crm Arbitrary File Upload ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-67968 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution Arbitrary Code Execution ≤ 8.1.8 Fixed in 8.2.0 CVE-2025-67944 Patchstack
9.8 Critical Consult Aid Plugin consultaid PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-67617 Patchstack
9.9 Critical News Event Plugin news-event Arbitrary File Upload ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-62056 Patchstack
9.9 Critical Blogmatic Plugin blogmatic Arbitrary File Upload ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-62050 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only