WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 801–850 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical Energia Plugin energia Arbitrary File Upload No login needed ≤ 1.1.2 CVE-2025-50002 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection No login needed ≤ 2.5 CVE-2025-49055 Patchstack
9.8 Critical LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Privilege Escalation Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter No login needed ≤ 1.5.6.3 CVE-2026-0920 Wordfence
9.8 Critical Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy Privilege Escalation WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.5.0 CVE-2025-15521 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Insert User Form Action No login needed ≤ 0.9.2.1 CVE-2025-14533 Wordfence
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin Authentication Bypass No login needed ≤ 1.3.1 CVE-2025-10484 Wordfence
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Unauthenticated Privilege Escalation via admin_order No login needed ≤ 6.0.7.1 CVE-2025-15403 Wordfence
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed 2.5.2 – < 2.6.0 Fixed in 2.6.0 CVE-2026-23800 Patchstack
9.3 Critical Omni Secure Files Plugin omni-secure-files Arbitrary File Upload Omni Secure Files < 0.1.14 Unauthenticated Arbitrary File Upload No login needed < 0.1.14 Fixed in 0.1.14 CVE-2012-10064 VulnCheck
9.3 Critical Uploadify Plugin Arbitrary File Upload Uploadify <= 1.0 Unauthenticated Arbitrary File Upload No login needed ≤ 1.0 CVE-2011-10041 VulnCheck
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-23550 Patchstack
9.8 Critical News and Blog Designer Bundle Plugin news-and-blog-designer-bundle Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.1 CVE-2025-14502 Wordfence
9.8 Critical Integration Opvius AI for WooCommerce Plugin woosa-ai-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion/Read via Path Traversal No login needed ≤ 1.3.0 CVE-2025-14301 Wordfence
9.1 Critical e-xact-hosted-payment Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.0 CVE-2025-14829 WPScan
9.8 Critical Dreamer Blog Theme Broken Access Control Subscriber+ Arbitrary Plugin Installation No login needed ≤ 1.2 CVE-2025-10915 WPScan
9.3 Critical AccessAlly Plugin Remote Code Execution AccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution No login needed < 3.3.2 Fixed in 3.3.2 CVE-2020-36875 VulnCheck
9.1 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element No login needed ≤ 3.28.25 CVE-2025-14741 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Role Form Field No login needed ≤ 3.28.29 CVE-2025-14736 Wordfence
9.3 Critical Automotive Listings Plugin automotive SQL Injection No login needed ≤ 18.6 Fixed in 18.7 CVE-2025-67928 Patchstack
9.9 Critical Corpkit Theme corpkit Arbitrary File Upload ≤ 2.0 Fixed in 2.0.1 CVE-2025-67924 Patchstack
9.8 Critical Newsletters Plugin newsletters-lite PHP Object Injection No login needed ≤ 4.11 Fixed in 4.12 CVE-2025-67911 Patchstack
9.1 Critical Contentstudio Plugin contentstudio Arbitrary File Upload ≤ 1.3.7 Fixed in 1.4.0 CVE-2025-67910 Patchstack
9.3 Critical Felan Framework Plugin felan-framework SQL Injection No login needed ≤ 1.1.3 CVE-2025-23993 Patchstack
9.8 Critical Felan Framework Plugin felan-framework Privilege Escalation Account Takeover No login needed ≤ 1.1.3 CVE-2025-23504 Patchstack
9.8 Critical WP Cost Estimation Plugin Broken Access Control Missing Authorization to Arbitrary File Upload/Delete No login needed < 9.644 Fixed in 9.644 CVE-2019-25296 Wordfence
9.8 Critical DZS Video Gallery Plugin dzs-videogallery PHP Object Injection No login needed ≤ 12.37 CVE-2025-47552 Patchstack
9.3 Critical WPCHURCH Plugin church-management SQL Injection No login needed ≤ 2.7.0 CVE-2025-32303 Patchstack
9.8 Critical Optional Email Plugin optional-email Privilege Escalation Unauthenticated Privilege Escalation to Account Takeover No login needed ≤ 1.3.11 CVE-2025-15018 Wordfence
9.9 Critical Themify Sidepane Theme sidepane Arbitrary File Upload Arbitrary File Upload Vulnerability in WordPress themes by Themify ≤ 1.9.8, ≤ 1.9.9, ≤ 1.9.6, … CVE-2025-30996 Patchstack
9.8 Critical InWave Jobs Plugin iwjob Broken Access Control No login needed ≤ 3.5.8 CVE-2025-39477 Patchstack
9.8 Critical FS Registration Password Plugin registration-password Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.0.1 CVE-2025-15001 Wordfence
9.8 Critical AS Password Field In Default Registration Form Plugin as-password-field-in-default-registration-form Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 2.0.0 CVE-2025-14996 Wordfence
9.3 Critical Entrada Theme entrada SQL Injection No login needed ≤ 5.7.7 CVE-2025-39484 Patchstack
9.1 Critical Media File Renamer Plugin media-file-renamer Remote Code Execution Arbitrary File Rename lead to RCE ≤ 5.7.7 Fixed in 5.7.8 CVE-2023-50897 Patchstack
9.3 Critical Infility Global Plugin infility-global SQL Injection No login needed ≤ 2.15.06 CVE-2025-68865 Patchstack
9.9 Critical Shopo Theme shopo Arbitrary File Upload ≤ 1.1.4 CVE-2025-31048 Patchstack
9.3 Critical Amazon Native Shopping Recommendations Plugin woozone-contextual SQL Injection No login needed ≤ 1.3 CVE-2025-30633 Patchstack
9.8 Critical Branda – White Label & Branding, Free Login Page Customizer Plugin branda-white-labeling Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.4.24 CVE-2025-14998 Wordfence
9.6 Critical WING WordPress Migrator Plugin wing-migrator Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 2.0.0 CVE-2025-52835 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.7.3 Fixed in 8.7.4 CVE-2025-68562 Patchstack
9.8 Critical Mobile builder Plugin mobile-builder Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 CVE-2025-68860 Patchstack
9.9 Critical IF AS Shortcode Plugin if-as-shortcode Remote Code Execution ≤ 1.2 CVE-2025-68897 Patchstack
9.8 Critical Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 5.8.0 CVE-2025-13773 Wordfence
9.8 Critical PhastPress Plugin phastpress Path Traversal Unauthenticated Arbitrary File Read via Null Byte Injection No login needed ≤ 3.7 CVE-2025-14388 Wordfence
9.8 Critical Flex Store Users Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.1.0 CVE-2025-13619 Wordfence
9.8 Critical File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via add-image-data No login needed ≤ 1.0.3 CVE-2025-13329 Wordfence
9.8 Critical Tuturn Plugin tuturn Authentication Bypass Broken Authentication No login needed < 3.6 Fixed in 3.6 CVE-2025-64236 Patchstack
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
9.0 Critical WP Webhooks Plugin wp-webhooks Arbitrary File Upload No login needed ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66074 Patchstack
9.9 Critical Motors Theme motors Arbitrary File Upload ≤ 5.6.81 Fixed in 5.6.82 CVE-2025-64374 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only