WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,301–8,350 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 167 of 345
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Avantage Plugin avantage PHP Object Injection No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-39495 Patchstack
9.3 Critical Goodlayers Hostel Plugin gdlr-hostel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39501 Patchstack
9.8 Critical Goodlayers Hostel Plugin gdlr-hostel PHP Object Injection No login needed ≤ 3.1.2 CVE-2025-39500 Patchstack
9.8 Critical Goodlayers Hotel Plugin gdlr-hotel PHP Object Injection No login needed ≤ 3.1.4 CVE-2025-39503 Patchstack
7.1 High Goodlayers Hostel Plugin gdlr-hostel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 CVE-2025-39502 Patchstack
7.1 High Goodlayers Hotel Plugin gdlr-hotel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.4 CVE-2025-39505 Patchstack
9.3 Critical Goodlayers Hotel Plugin gdlr-hotel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39504 Patchstack
8.2 High JobHunt Job Alerts Plugin jobhunt-notifications Broken Access Control Arbitrary Content Deletion No login needed ≤ 3.6 CVE-2025-39536 Patchstack
8.1 High Nasa Core Plugin nasa-core Local File Inclusion No login needed ≤ 6.3.2 CVE-2025-39506 Patchstack
7.1 High kStats Reloaded Plugin kstats-reloaded Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7.4 CVE-2025-46440 Patchstack
7.1 High Tayori Form Plugin tayori Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 CVE-2025-46437 Patchstack
7.1 High Libro de Reclamaciones Plugin libro-de-reclamaciones Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-46446 Patchstack
8.1 High Ads Pro Plugin ap-plugin-scripteo Local File Inclusion No login needed ≤ 4.89 CVE-2025-46444 Patchstack
9.3 Critical WP HRM LITE Plugin wp-hrm-lite-human-resource-management-system SQL Injection No login needed ≤ 1.1 CVE-2025-46455 Patchstack
7.5 High Meta Keywords & Description Plugin wp-meta-keywords-meta-description Local File Inclusion No login needed ≤ 0.8 CVE-2025-46454 Patchstack
7.1 High Document Management System Plugin dms Cross-Site Scripting No login needed ≤ 1.24 CVE-2025-46448 Patchstack
7.1 High Theme Blvd Sliders Plugin theme-blvd-sliders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-46456 Patchstack
9.3 Critical Easy Guide Plugin wp-easy-guide SQL Injection No login needed ≤ 1.0.0 CVE-2025-46460 Patchstack
8.2 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.3.0 CVE-2025-46458 Patchstack
9.8 Critical Fable Extra Plugin fable-extra Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46468 Patchstack
8.5 High Mailing Group Listserv Plugin wp-mailing-group SQL Injection ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-46463 Patchstack
4.9 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.7 Fixed in 7.1.8 CVE-2025-46486 Patchstack
8.1 High SEUR Oficial Plugin seur Local File Inclusion No login needed ≤ 2.2.23 Fixed in 2.2.24 CVE-2025-46474 Patchstack
7.1 High Visual Builder Plugin visual-builder Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-46488 Patchstack
7.1 High EC Authorize.net Plugin ec-authorizenet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2025-46487 Patchstack
6.5 Medium Crossword Compiler Puzzles Plugin crossword-compiler-puzzles Cross-Site Scripting ≤ 14.5 CVE-2025-46493 Patchstack
9.9 Critical Crossword Compiler Puzzles Plugin crossword-compiler-puzzles Arbitrary File Upload ≤ 5.2 Fixed in 5.3 CVE-2025-46490 Patchstack
6.5 Medium IGIT Related Posts With Thumb Image After Posts Plugin igit-related-posts-with-thumb-images-after-posts Cross-Site Scripting ≤ 4.5.3 CVE-2025-46518 Patchstack
7.1 High Category Widget Plugin category-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2025-46515 Patchstack
6.5 Medium Web3Press Plugin likecoin Path Traversal Decentralize Publishing with Writing NFT plugin <= 3.2.0 - Arbitrary File Read ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-46527 Patchstack
7.1 High My Custom Widgets Plugin mycustomwidget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 CVE-2025-46526 Patchstack
8.1 High WP Job Portal Plugin wp-job-portal Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-47438 Patchstack
9.3 Critical Fable Extra Plugin fable-extra SQL Injection No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-46539 Patchstack
7.1 High Section Widget Plugin section-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.1 CVE-2025-46537 Patchstack
7.1 High B2i Investor Tools Plugin b2i-investor-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7.9 Fixed in 1.0.8 CVE-2025-47458 Patchstack
8.1 High WP Smart Import Plugin wp-smart-import Local File Inclusion No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-47453 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.0 Fixed in 5.9.5.1 CVE-2025-47478 Patchstack
8.8 High Subaccounts for WooCommerce Plugin subaccounts-for-woocommerce Privilege Escalation Account Takeover ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-47461 Patchstack
8.6 High Tainacan Plugin tainacan Arbitrary File Deletion No login needed ≤ 0.21.14 Fixed in 0.21.15 CVE-2025-47512 Patchstack
8.6 High Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2025-47492 Patchstack
6.5 Medium Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget Broken Access Control Call To Action, Sticky CTA, Floating Button Plugin <= 1.1.1 - Settings Change No login needed ≤ 1.1.1 Fixed in 1.2.1 CVE-2025-47529 Patchstack
4.9 Medium Infocob CRM Forms Plugin infocob-crm-forms Path Traversal Arbitrary File Download ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-47513 Patchstack
9.8 Critical CoinPayments.net Payment Gateway for WooCommerce Plugin coinpayments-payment-gateway-for-woocommerce PHP Object Injection No login needed ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47532 Patchstack
9.8 Critical WPFunnels Plugin wpfunnels PHP Object Injection No login needed ≤ 3.5.18 Fixed in 3.5.19 CVE-2025-47530 Patchstack
9.8 Critical Eventin Plugin wp-event-solution Privilege Escalation No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2025-47539 Patchstack
8.6 High Opal Woo Custom Product Variation Plugin opal-woo-custom-product-variation Arbitrary File Deletion No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-47535 Patchstack
7.5 High MapSVG Plugin mapsvg Broken Access Control No login needed ≤ 8.6.13 Fixed in 8.6.13 CVE-2025-47558 Patchstack
7.5 High Mail Mint Plugin mail-mint Information Disclosure Sensitive Data Exposure No login needed ≤ 1.17.7 Fixed in 1.17.8 CVE-2025-47541 Patchstack
9.3 Critical Facturante Plugin facturante SQL Injection No login needed ≤ 1.11 Fixed in 1.13 CVE-2025-47599 Patchstack
8.5 High School Management Plugin school-management SQL Injection ≤ 92.0.0 CVE-2025-47575 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only