WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,001–8,050 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 161 of 345
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High SNS Anton Plugin snsanton Local File Inclusion No login needed ≤ 4.1 CVE-2025-28992 Patchstack
9.8 Critical PayU India Plugin payu-india Privilege Escalation Account Takeover No login needed ≤ 3.8.8 Fixed in 3.8.8 CVE-2025-31022 Patchstack
7.5 High elfsight Contact Form widget Plugin elfsight-contact-form Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.1 CVE-2025-31045 Patchstack
9.1 Critical Category Icon Plugin category-icon XML External Entity ≤ 1.0.3 CVE-2025-31039 Patchstack
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
9.8 Critical The Fashion - Model Agency One Page Beauty Plugin nrgfashion PHP Object Injection Model Agency One Page Beauty Theme plugin <= 1.4.4 - Deserialization of untrusted data No login needed ≤ 1.4.4 CVE-2025-31052 Patchstack
7.1 High Universal Video Player Plugin elementor_widget_universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-31057 Patchstack
7.1 High Revolution Video Player Plugin revolution_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.2 CVE-2025-31058 Patchstack
9.3 Critical WBW Product Table PRO Plugin woo-producttables-pro SQL Injection No login needed ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-31059 Patchstack
7.1 High Wishlist Plugin wishlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-31061 Patchstack
9.8 Critical PIMP - Creative MultiPurpose Theme pimp PHP Object Injection Creative MultiPurpose <= 1.7 - Deserialization of untrusted data No login needed ≤ 1.7 CVE-2025-31398 Patchstack
9.8 Critical FLAP - Business Theme flap PHP Object Injection Business WordPress Theme <= 1.5 - PHP Object Injection No login needed ≤ 1.5 CVE-2025-31396 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin leadcapture SQL Injection No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31424 Patchstack
7.1 High Sticky Radio Player Plugin lbg-audio5-html5-shoutcast_sticky Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4 CVE-2025-31426 Patchstack
7.5 High CLEVER Plugin lbg-audio11-html5-shoutcast_history Path Traversal Arbitrary File Download No login needed ≤ 2.6 CVE-2025-31635 Patchstack
9.8 Critical PressGrid - Frontend Publish Reaction & Multimedia Theme press-grid PHP Object Injection Frontend Publish Reaction & Multimedia Theme <= 1.3.1 - Deserialization of untrusted data No login needed ≤ 1.3.1 CVE-2025-31429 Patchstack
7.1 High Spare Theme spare Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-31638 Patchstack
7.1 High Universal Video Player Plugin universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.3 CVE-2025-31917 Patchstack
8.5 High WP Guppy Plugin wp-guppy SQL Injection ≤ 4.3.3 CVE-2025-31920 Patchstack
7.1 High SHOUT Plugin lbg-audio8-html5-radio_ads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.3 CVE-2025-31925 Patchstack
7.1 High FlatNews Theme flatnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 6.2 CVE-2025-32305 Patchstack
10.0 Critical SUMO Affiliates Pro Plugin affs Arbitrary File Upload No login needed ≤ 11.1.0 Fixed in 11.1.0 CVE-2025-32291 Patchstack
7.6 High Team Builder Plugin a-team-showcase Broken Access Control ≤ 1.5.7 CVE-2025-32308 Patchstack
8.1 High Seofy Core Plugin seofy-core Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.11 CVE-2025-39473 Patchstack
8.1 High Krowd Theme krowd Local File Inclusion No login needed ≤ 1.5.0 Fixed in 1.5.0 CVE-2025-32595 Patchstack
8.1 High Arlo Plugin arlo Local File Inclusion No login needed ≤ 6.0.3 CVE-2025-39475 Patchstack
7.5 High Revo Plugin revo Local File Inclusion No login needed ≤ 4.0.26 CVE-2025-39476 Patchstack
7.1 High WP Email Delivery Plugin wp-email-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.11.23 CVE-2025-39539 Patchstack
7.1 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.23 Fixed in 1.22.24 CVE-2025-47477 Patchstack
7.1 High Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-47463 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47487 Patchstack
6.8 Medium Welcart e-Commerce Plugin usc-e-shop Arbitrary File Deletion ≤ 2.11.13 Fixed in 2.11.14 CVE-2025-47511 Patchstack
8.8 High MapSVG Plugin mapsvg Privilege Escalation ≤ 8.6.13 Fixed in 8.6.13 CVE-2025-47561 Patchstack
7.1 High Icegram Collect Plugin icegram-rainmaker Broken Access Control Easy Form, Lead Collection and Subscription plugin <= 1.3.18 - Broken Access Control ≤ 1.3.18 Fixed in 1.3.19 CVE-2025-47527 Patchstack
6.5 Medium History Log by click5 Plugin history-log-by-click5 Cross-Site Scripting ≤ 1.0.13 CVE-2025-47598 Patchstack
8.5 High Infility Global Plugin infility-global SQL Injection ≤ 2.15.06 CVE-2025-47651 Patchstack
9.3 Critical Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart SQL Injection No login needed ≤ 2.5 CVE-2025-47608 Patchstack
9.3 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light SQL Injection Light plugin <= 2.4.37 - SQL Injection No login needed ≤ 2.4.37 CVE-2025-48122 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Path Traversal Light plugin <= 2.4.37 - Arbitrary File Download No login needed ≤ 2.4.37 CVE-2025-48124 Patchstack
10.0 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Remote Code Execution Light plugin <= 2.4.37 - Remote Code Execution (RCE) No login needed ≤ 2.4.37 CVE-2025-48123 Patchstack
8.1 High WP Event Manager Plugin wp-event-manager Local File Inclusion No login needed ≤ 3.1.51 Fixed in 3.2.0 CVE-2025-48125 Patchstack
8.1 High Essential Real Estate Plugin essential-real-estate Local File Inclusion No login needed ≤ 5.2.9 CVE-2025-48126 Patchstack
9.8 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Privilege Escalation Light plugin <= 2.4.37 - Privilege Escalation No login needed ≤ 2.4.37 CVE-2025-48129 Patchstack
7.5 High Spice Blocks Plugin spice-blocks Path Traversal Arbitrary File Download No login needed ≤ 2.0.7.4 Fixed in 2.0.7.5 CVE-2025-48130 Patchstack
6.5 Medium StyleAI Plugin relentlosoftware Broken Access Control No login needed ≤ 1.0.4 CVE-2025-48139 Patchstack
9.9 Critical MetalpriceAPI Plugin metalpriceapi Remote Code Execution ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-48140 Patchstack
9.3 Critical Multi CryptoCurrency Payments Plugin multi-crypto-currency-payment SQL Injection No login needed ≤ 2.0.7 CVE-2025-48141 Patchstack
6.5 Medium CryptoCloud - Crypto Payment Gateway Plugin cryptocloud-crypto-payment-gateway Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.3.2 CVE-2025-48147 Patchstack
7.1 High Formulario de contacto SalesUp! Plugin formularios-de-contacto-salesup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.14 CVE-2025-48143 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only