WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,401–8,450 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 169 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Section Widget Plugin section-widget Path Traversal No login needed ≤ 3.3.1 CVE-2025-46441 Patchstack
7.1 High wProject Theme wproject Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.8.0 Fixed in 5.8.0 CVE-2025-39365 Patchstack
8.8 High wProject Theme wproject Privilege Escalation Subscriber+ Privilege Escalation < 5.8.0 Fixed in 5.8.0 CVE-2025-39366 Patchstack
7.1 High WordPress Events Calendar Registration & Tickets Plugin wpeventplus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-39372 Patchstack
10.0 Critical Hospital Management System Plugin hospital-management Arbitrary File Upload No login needed ≤ 47.0(20-11-2023) CVE-2025-39380 Patchstack
9.3 Critical Hospital Management System Plugin hospital-management SQL Injection No login needed ≤ 47.0(20-11-2023) CVE-2025-39386 Patchstack
9.3 Critical AnalyticsWP Plugin analyticswp SQL Injection No login needed ≤ 2.1.2 Fixed in 2.1.5 CVE-2025-39389 Patchstack
7.1 High WPAMS Plugin apartment-management Cross-Site Scripting No login needed ≤ 44.0 (17-08-2023) CVE-2025-39392 Patchstack
7.1 High Hospital Management System Plugin hospital-management Cross-Site Scripting No login needed ≤ 47.0(20-11-2023) CVE-2025-39393 Patchstack
9.3 Critical WPAMS Plugin apartment-management SQL Injection No login needed ≤ 44.0 (17-08-2023) CVE-2025-39395 Patchstack
10.0 Critical WPAMS Plugin apartment-management Arbitrary File Upload No login needed ≤ 44.0 (17-08-2023) CVE-2025-39401 Patchstack
9.9 Critical WPAMS Plugin apartment-management Arbitrary File Upload ≤ 44.0 (17-08-2023) CVE-2025-39402 Patchstack
8.5 High WPAMS Plugin apartment-management SQL Injection ≤ 44.0 (17-08-2023) CVE-2025-39403 Patchstack
8.8 High WPAMS Plugin apartment-management Privilege Escalation ≤ 44.0 (17-08-2023) CVE-2025-39405 Patchstack
9.8 Critical WPAMS Plugin apartment-management Local File Inclusion Local File Inclusion to Privilege Escalation No login needed ≤ 44.0 CVE-2025-39406 Patchstack
7.1 High Memberpress Plugin memberpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 1.12.0 Fixed in 1.12.0 CVE-2025-39407 Patchstack
7.1 High WordPress Video Robot - The Ultimate Video Importer Plugin wp-video-robot Cross-Site Scripting The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.0 CVE-2025-39409 Patchstack
9.8 Critical Smart Sections Theme Builder - WPBakery Page Builder Addon Plugin visucom-smart-sections PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed ≤ 1.7.8 CVE-2025-39410 Patchstack
7.5 High WhatsApp Click to Chat Plugin wpt-whatsapp Local File Inclusion No login needed ≤ 2.2.12 CVE-2025-39411 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.2 Fixed in 7.5 CVE-2025-39445 Patchstack
7.1 High Booster Plus for WooCommerce Plugin booster-plus-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.4 Fixed in 7.2.5 CVE-2025-39446 Patchstack
7.5 High JetElements For Elementor Plugin jet-elements Broken Access Control No login needed ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39447 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-39449 Patchstack
7.5 High JetBlocks For Elementor Plugin jet-blocks Broken Access Control No login needed ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-39451 Patchstack
8.1 High Foton Plugin foton Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.6.1 CVE-2025-39458 Patchstack
7.3 High Real Estate 7 Plugin realestate-7 Privilege Escalation No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2025-39459 Patchstack
7.1 High Remote Images Grabber Plugin remote-images-grabber Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6 CVE-2025-43832 Patchstack
7.1 High Syndicate Out Plugin syndicate-out Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-43836 Patchstack
7.1 High Total Donations Plugin total-donations Cross-Site Scripting No login needed ≤ 3.0.8 CVE-2025-43837 Patchstack
6.5 Medium Custom PC Builder Lite for WooCommerce Plugin custom-pc-builder-lite-for-woocommerce Broken Access Control Settings Change No login needed ≤ 1.0.1 CVE-2025-43838 Patchstack
7.1 High BP Messages Tool Plugin bp-messages-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 Fixed in 2.5 CVE-2025-43839 Patchstack
10.0 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Arbitrary File Upload No login needed ≤ 2.9.2 Fixed in 2.10.0 CVE-2025-47577 Patchstack
9.8 Critical WordPress Events Calendar Registration & Tickets Plugin wpeventplus PHP Object Injection No login needed ≤ 2.6.0 CVE-2025-47581 Patchstack
9.8 Critical WPBot Pro Wordpress Chatbot Plugin wpbot-pro PHP Object Injection No login needed ≤ 12.7.0 CVE-2025-47582 Patchstack
8.1 High Tastyc Theme tastyc Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.5.2 CVE-2025-27010 Patchstack
7.1 High Wireless Butler Plugin wireless-butler Cross-Site Scripting No login needed ≤ 1.0.11 CVE-2025-26997 Patchstack
9.9 Critical Celestial Aura Theme celestial-aura Arbitrary File Upload ≤ 2.2 CVE-2025-26892 Patchstack
9.9 Critical Eximius Theme eximius Arbitrary File Upload ≤ 2.2 CVE-2025-26872 Patchstack
7.5 High Grip Theme grip Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-26735 Patchstack
5.4 Medium LTL Freight Quotes – FreightQuote Edition Plugin ltl-freight-quotes-freightquote-edition Broken Access Control FreightQuote Edition plugin <= 2.3.11 - Broken Access Control ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-22287 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39448 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-39450 Patchstack
4.3 Medium Name Directory Plugin name-directory Broken Access Control ≤ 1.30.0 Fixed in 1.30.1 CVE-2025-39454 Patchstack
5.3 Medium Eduma Plugin eduma Broken Access Control No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2025-39460 Patchstack
7.6 High Absolute Links Plugin absolute-links SQL Injection ≤ 1.1.1 CVE-2025-43833 Patchstack
5.9 Medium cookieBAR Plugin cookiebar Cross-Site Scripting ≤ 1.7.0 Fixed in 1.10.1 CVE-2025-43834 Patchstack
4.3 Medium wp-cyr-cho Plugin wp-cyr-cho Cross-Site Request Forgery No login needed ≤ 0.1 CVE-2025-43835 Patchstack
4.3 Medium Master Slider Plugin master-slider Broken Access Control ≤ 3.11.0 CVE-2025-39412 Patchstack
4.3 Medium Bellevue Theme bellevuex Broken Access Control ≤ 4.2.2 CVE-2025-39398 Patchstack
7.5 High JetReviews Plugin jet-reviews Local File Inclusion ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39396 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only