WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,951–8,000 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 160 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High eCommerce Product Catalog Plugin ecommerce-product-catalog PHP Object Injection ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-49331 Patchstack
4.3 Medium myCred Plugin mycred Broken Access Control ≤ 2.9.4.2 Fixed in 2.9.4.3 CVE-2025-49857 Patchstack
4.3 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-49856 Patchstack
6.5 Medium Meks Flexible Shortcodes Plugin meks-flexible-shortcodes Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-49855 Patchstack
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.17 Fixed in 2.1.18 CVE-2025-49858 Patchstack
6.5 Medium Kama Click Counter Plugin kama-clic-counter Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-49861 Patchstack
6.5 Medium WP Views Counter Plugin wpecounter Cross-Site Scripting ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-49859 Patchstack
6.5 Medium Advanced Sermons Plugin advanced-sermons Cross-Site Scripting ≤ 3.6 Fixed in 3.7 CVE-2025-49863 Patchstack
5.9 Medium Ebook Store Plugin ebook-store Cross-Site Scripting ≤ 5.8008 Fixed in 5.8009 CVE-2025-49862 Patchstack
4.7 Medium FunnelKit Automations Plugin wp-marketing-automations Open Redirect No login needed ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-49868 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-49865 Patchstack
5.3 Medium AFS Analytics Plugin addfreestats Broken Access Control No login needed ≤ 4.21 Fixed in 4.22 CVE-2025-49864 Patchstack
5.3 Medium myCred Plugin mycred Broken Access Control No login needed ≤ 2.9.4.2 Fixed in 2.9.4.3 CVE-2025-49872 Patchstack
5.9 Medium Noptin Plugin newsletter-optin-box Cross-Site Scripting ≤ 3.8.7 Fixed in 4.0.0 CVE-2025-49871 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting ≤ 1.9.3.1 Fixed in 1.9.3.2 CVE-2025-49875 Patchstack
4.3 Medium Arconix FAQ Plugin arconix-faq Broken Access Control ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-49874 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Cross-Site Scripting ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-49878 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
4.3 Medium CubeWP Forms Plugin cubewp-forms Broken Access Control ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-49880 Patchstack
8.6 High Litho Plugin litho Arbitrary File Deletion No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-49879 Patchstack
6.5 Medium CubeWP Plugin cubewp-framework Cross-Site Scripting ≤ 1.1.23 Fixed in 1.1.24 CVE-2025-49882 Patchstack
6.5 Medium Responsive Blocks Plugin responsive-block-editor-addons Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-49881 Patchstack
10.0 Critical Reformer for Elementor Plugin reformer-elementor Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2025-49444 Patchstack
8.6 High FW Gallery Plugin fw-gallery Arbitrary File Deletion No login needed ≤ 8.0.0 CVE-2025-49415 Patchstack
10.0 Critical FW Food Menu Plugin fw-food-menu Arbitrary File Upload No login needed ≤ 6.0.0 CVE-2025-49447 Patchstack
6.4 Medium WordPress Infinite Scroll – Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting ≤ 7.4.0.1 CVE-2025-4775 Wordfence
8.1 High Zagg - Electronics & Accessories WooCommerce Theme Local File Inclusion Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.1 CVE-2025-4200 Wordfence
5.9 Medium UserPro - Community and User Profile Plugin Path Traversal Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Read No login needed ≤ 5.1.10 CVE-2025-4187 Wordfence
5.3 Medium WordPress Single Sign-On (SSO) Plugin Broken Access Control Multiple Versions - Incorrect Authorization to Sensitive Information Exposure No login needed ≤ 18.5.3, ≤ 28.5.3, ≤ 30.5.3, … CVE-2025-6003 Wordfence
8.8 High Automatic Plugin - AI content generator and auto poster Plugin Arbitrary File Upload AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File Upload ≤ 3.115.0 CVE-2025-5395 Wordfence
8.1 High TinySalt Theme tinysalt Local File Inclusion No login needed ≤ 3.10.0 Fixed in 3.10.0 CVE-2025-49454 Patchstack
9.3 Critical WordPress-WPJobBoard Plugin click-pledge-wpjobboard SQL Injection No login needed ≤ 25.07010000-WP6.8.1-JB5.11.5 Fixed in 25.09000000-WP6.8.2-JB5.12.0 CVE-2025-49455 Patchstack
9.8 Critical CozyStay Theme cozystay PHP Object Injection No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2025-49507 Patchstack
5.3 Medium Audio Editor & Recorder Plugin audio-editor-recorder Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-49509 Patchstack
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.3.3 CVE-2025-2918 Wordfence
8.8 High RH - Real Estate Theme Privilege Escalation Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 4.4.0 CVE-2025-4601 Wordfence
8.1 High Fitrush Theme bw-fitrush Local File Inclusion No login needed ≤ 1.3.4 CVE-2023-26005 Patchstack
8.1 High BodyCenter - Gym, Fitness WooCommerce Theme bodycenter Local File Inclusion Gym, Fitness WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2023-25999 Patchstack
8.1 High One-Login Plugin one-login Privilege Escalation No login needed ≤ 1.4 CVE-2025-23974 Patchstack
9.3 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai SQL Injection No login needed ≤ 3.19 Fixed in 3.21 CVE-2025-24767 Patchstack
8.1 High CraftXtore Plugin bw-craftxtore Local File Inclusion No login needed ≤ 1.7 CVE-2025-24770 Patchstack
8.1 High Nitan Plugin snsnitan Local File Inclusion No login needed ≤ 2.9 CVE-2025-24768 Patchstack
8.1 High Lab Plugin lab Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-26592 Patchstack
8.1 High Petito Plugin bw-petito Local File Inclusion No login needed ≤ 1.6.6 Fixed in 1.6.6 CVE-2025-27362 Patchstack
8.1 High Avaz Plugin snsavaz Local File Inclusion No login needed ≤ 2.8 CVE-2025-28944 Patchstack
8.1 High GiftXtore Plugin bw-giftxtore Local File Inclusion No login needed ≤ 1.7.7 Fixed in 1.7.7 CVE-2025-28888 Patchstack
8.1 High Valen - Sport, Fashion WooCommerce Plugin valen Local File Inclusion Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2025-28945 Patchstack
8.8 High Password Policy Manager Plugin password-policy-manager Privilege Escalation Account Takeover ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-31019 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only