WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 801–850 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Grand Restaurant Plugin grandrestaurant PHP Object Injection No login needed ≤ 7.0 CVE-2025-39348 Patchstack
9.8 Critical CiyaShop Theme ciyashop PHP Object Injection No login needed ≤ 4.18.0 CVE-2025-39349 Patchstack
9.8 Critical Grand Conference Plugin grandconference PHP Object Injection No login needed ≤ 5.3 CVE-2025-39354 Patchstack
9.8 Critical Foodbakery Sticky Cart Plugin foodbakery-sticky-cart PHP Object Injection No login needed ≤ 3.2 CVE-2025-39356 Patchstack
10.0 Critical Hospital Management System Plugin hospital-management Arbitrary File Upload No login needed ≤ 47.0(20-11-2023) CVE-2025-39380 Patchstack
9.3 Critical Hospital Management System Plugin hospital-management SQL Injection No login needed ≤ 47.0(20-11-2023) CVE-2025-39386 Patchstack
9.3 Critical AnalyticsWP Plugin analyticswp SQL Injection No login needed ≤ 2.1.2 Fixed in 2.1.5 CVE-2025-39389 Patchstack
9.3 Critical WPAMS Plugin apartment-management SQL Injection No login needed ≤ 44.0 (17-08-2023) CVE-2025-39395 Patchstack
10.0 Critical WPAMS Plugin apartment-management Arbitrary File Upload No login needed ≤ 44.0 (17-08-2023) CVE-2025-39401 Patchstack
9.9 Critical WPAMS Plugin apartment-management Arbitrary File Upload ≤ 44.0 (17-08-2023) CVE-2025-39402 Patchstack
9.8 Critical WPAMS Plugin apartment-management Local File Inclusion Local File Inclusion to Privilege Escalation No login needed ≤ 44.0 CVE-2025-39406 Patchstack
9.8 Critical Smart Sections Theme Builder - WPBakery Page Builder Addon Plugin visucom-smart-sections PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed ≤ 1.7.8 CVE-2025-39410 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.2 Fixed in 7.5 CVE-2025-39445 Patchstack
10.0 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Arbitrary File Upload No login needed ≤ 2.9.2 Fixed in 2.10.0 CVE-2025-47577 Patchstack
9.8 Critical WordPress Events Calendar Registration & Tickets Plugin wpeventplus PHP Object Injection No login needed ≤ 2.6.0 CVE-2025-47581 Patchstack
9.8 Critical WPBot Pro Wordpress Chatbot Plugin wpbot-pro PHP Object Injection No login needed ≤ 12.7.0 CVE-2025-47582 Patchstack
9.9 Critical Celestial Aura Theme celestial-aura Arbitrary File Upload ≤ 2.2 CVE-2025-26892 Patchstack
9.9 Critical Eximius Theme eximius Arbitrary File Upload ≤ 2.2 CVE-2025-26872 Patchstack
9.3 Critical Eventer Plugin eventer SQL Injection No login needed ≤ 3.11.4 Fixed in 3.11.4 CVE-2025-39481 Patchstack
9.3 Critical WPGYM Plugin gym-management SQL Injection No login needed ≤ 65.0 CVE-2025-32643 Patchstack
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.8.1 - SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-47682 Patchstack
9.3 Critical Productive Commerce Plugin productive-commerce SQL Injection No login needed ≤ 1.1.40 CVE-2025-47657 Patchstack
9.1 Critical BEAF Plugin beaf-before-and-after-gallery Arbitrary File Upload ≤ 4.6.10 Fixed in 4.6.11 CVE-2025-47549 Patchstack
9.8 Critical OttoKit Plugin suretriggers Privilege Escalation No login needed ≤ 1.0.82 Fixed in 1.0.83 CVE-2025-27007 Patchstack
9.9 Critical PowerPress Podcasting Plugin powerpress Arbitrary File Upload ≤ 11.12.5 Fixed in 11.12.6 CVE-2025-46264 Patchstack
9.3 Critical Frontend Dashboard Plugin frontend-dashboard SQL Injection No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-46248 Patchstack
9.8 Critical Wordpress Plugin Smart Product Review Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2021-4455 Wordfence
9.3 Critical Modal Survey Plugin modal-survey SQL Injection No login needed ≤ 2.0.2.0.1 CVE-2025-39471 Patchstack
9.9 Critical Theme File Duplicator Plugin theme-file-duplicator Arbitrary File Upload ≤ 1.3 CVE-2025-27282 Patchstack
9.8 Critical Saoshyant Slider Plugin saoshyant-slider PHP Object Injection No login needed ≤ 3.0 CVE-2025-27286 Patchstack
9.8 Critical SS Quiz Plugin ssquiz PHP Object Injection No login needed ≤ 2.0.5 CVE-2025-27287 Patchstack
9.3 Critical CHATLIVE Plugin chatlive SQL Injection No login needed ≤ 2.0.1 CVE-2025-27302 Patchstack
9.8 Critical Paid Videochat Turnkey Site Plugin ppv-live-webcams Authentication Bypass Broken Authentication No login needed ≤ 7.3.11 Fixed in 7.3.12 CVE-2025-31380 Patchstack
9.8 Critical Kata Plus Plugin kata-plus PHP Object Injection No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-32572 Patchstack
9.9 Critical PDF 2 Post Plugin pdf2post Remote Code Execution ≤ 2.4.0 CVE-2025-32583 Patchstack
9.3 Critical JS Job Manager Plugin js-jobs SQL Injection No login needed ≤ 2.0.2 CVE-2025-32626 Patchstack
9.3 Critical Local Magic Plugin local-magic SQL Injection No login needed ≤ 2.9.0 CVE-2025-32636 Patchstack
9.8 Critical Projectopia Plugin projectopia-core Privilege Escalation No login needed ≤ 5.1.24 CVE-2025-32648 Patchstack
9.9 Critical Solace Extra Plugin solace-extra Arbitrary File Upload ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-32652 Patchstack
10.0 Critical JS Job Manager Plugin js-jobs Arbitrary File Upload No login needed ≤ 2.0.2 CVE-2025-32660 Patchstack
9.8 Critical HelpGent Plugin helpgent PHP Object Injection No login needed ≤ 2.2.5 CVE-2025-32658 Patchstack
9.3 Critical Office Locator Plugin office-locator SQL Injection No login needed ≤ 1.3.0 CVE-2025-32665 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32682 Patchstack
9.8 Critical FluentCommunity Plugin fluent-community PHP Object Injection No login needed ≤ 1.2.15 Fixed in 1.3.1 CVE-2025-39550 Patchstack
9.8 Critical FluentBoards Plugin fluent-boards PHP Object Injection No login needed ≤ 1.47 Fixed in 1.48 CVE-2025-39551 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.65 Fixed in 3.2.68 CVE-2025-39587 Patchstack
9.8 Critical Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-39588 Patchstack
9.3 Critical Quentn WP Plugin quentn-wp SQL Injection No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-39595 Patchstack
9.8 Critical Quentn WP Plugin quentn-wp Privilege Escalation No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-39596 Patchstack
9.3 Critical CWD – Stealth Links Plugin cwd-stealth-links SQL Injection Stealth Links plugin <= 1.3 - SQL Injection No login needed ≤ 1.3 CVE-2025-22655 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only