WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical I Draw Plugin idraw Arbitrary File Upload ≤ 1.0 CVE-2025-39436 Patchstack
9.1 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Arbitrary File Upload ≤ 1.5.14 Fixed in 1.5.15 CVE-2025-39557 Patchstack
9.6 Critical Custom CSS, JS & PHP Plugin custom-css Cross-Site Request Forgery CSRF to RCE No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-39601 Patchstack
9.6 Critical WPJobBoard Plugin wpjobboard Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30967 Patchstack
10.0 Critical AI Hub Plugin aihub Arbitrary File Upload No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-26927 Patchstack
9.8 Critical GNUCommerce Plugin gnucommerce PHP Object Injection No login needed ≤ 1.5.4 CVE-2025-30985 Patchstack
9.8 Critical Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder Plugin everest-forms PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.1.1 CVE-2025-3439 Wordfence
9.8 Critical WpBookingly Plugin service-booking-manager PHP Object Injection No login needed ≤ 1.3.0 CVE-2025-32607 Patchstack
9.3 Critical WP Online Users Stats Plugin wp-online-users-stats SQL Injection No login needed ≤ 1.0.0 CVE-2025-32603 Patchstack
9.9 Critical Sync Posts Plugin sync-posts Arbitrary File Upload ≤ 1.0 CVE-2025-32579 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2025-32577 Patchstack
9.8 Critical TableOn Plugin posts-table-filterable PHP Object Injection No login needed ≤ 1.0.4.3 Fixed in 1.0.4.4 CVE-2025-32569 Patchstack
9.8 Critical EmpikPlace for Woocommerce Plugin empik-for-woocommerce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32568 Patchstack
9.3 Critical Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.0 CVE-2025-32565 Patchstack
9.8 Critical Rankology SEO – On-site SEO Plugin rankology-seo-all-in-one-seo-analytics Privilege Escalation On-site SEO plugin <= 2.2.4 - Privilege Escalation No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-32491 Patchstack
9.3 Critical Bulk Product Sync Plugin sync-wc-google SQL Injection No login needed ≤ 8.6 Fixed in 9.0 CVE-2025-31599 Patchstack
9.3 Critical WPSmartContracts Plugin wp-smart-contracts SQL Injection No login needed ≤ 2.0.12 CVE-2025-31565 Patchstack
9.1 Critical Processing Projects Plugin processing-projects Arbitrary File Upload ≤ 1.0.2 CVE-2025-32206 Patchstack
9.1 Critical Insert or Embed Articulate Content into Plugin insert-or-embed-articulate-content-into-wordpress Arbitrary File Upload ≤ 4.3000000025 Fixed in 4.3000000026 CVE-2025-32202 Patchstack
9.9 Critical WP Remote Thumbnail Plugin wp-remote-thumbnail Arbitrary File Upload ≤ 1.3.2 CVE-2025-32140 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation No login needed ≤ 8.7.5 CVE-2025-32695 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.6 Fixed in 1.6.1 CVE-2025-31002 Patchstack
9.8 Critical Buddypress Humanity Plugin buddypress-humanity Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.2 CVE-2025-31033 Patchstack
9.6 Critical Ultra Demo Importer Plugin ut-demo-importer Cross-Site Request Forgery CSRF to RCE No login needed ≤ 1.0.5 CVE-2025-32496 Patchstack
9.6 Critical WP shop Plugin wpshop Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.6.1 CVE-2025-32576 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
9.6 Critical Vite Coupon Plugin vite-coupon Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-32642 Patchstack
9.1 Critical CMP – Coming Soon & Maintenance Plugin cmp-coming-soon-maintenance Remote Code Execution Coming Soon & Maintenance plugin <= 4.1.14 - Remote Code Execution (RCE) ≤ 4.1.14 Fixed in 4.1.15 CVE-2025-32118 Patchstack
9.8 Critical Homey Theme homey Privilege Escalation No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-51800 Patchstack
9.3 Critical Booking Calendar and Notification Plugin booking-calendar-and-notification SQL Injection No login needed ≤ 4.0.3 CVE-2025-31403 Patchstack
9.3 Critical Social Share And Social Locker Plugin social-share-and-social-locker-arsocial SQL Injection No login needed ≤ 1.4.2 CVE-2025-31911 Patchstack
9.8 Critical CBX Poll Plugin cbxpoll PHP Object Injection No login needed ≤ 2.0.4 CVE-2025-31612 Patchstack
9.3 Critical WP AutoKeyword Plugin wp-autokeyword SQL Injection No login needed ≤ 1.0 CVE-2025-31579 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-31553 Patchstack
9.3 Critical RSVPMarker Plugin rsvpmaker SQL Injection No login needed ≤ 11.6.7 Fixed in 11.6.8 CVE-2025-31552 Patchstack
9.3 Critical Salesmate Add-On for Gravity Forms Plugin gf-salesmate-add-on SQL Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-31551 Patchstack
9.3 Critical Shopper Plugin shopper SQL Injection No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-31534 Patchstack
9.3 Critical History Log by click5 Plugin history-log-by-click5 SQL Injection No login needed ≤ 1.0.13 CVE-2025-31531 Patchstack
9.9 Critical Countdown & Clock Plugin countdown-builder Remote Code Execution ≤ 2.8.8 Fixed in 2.8.9 CVE-2025-30841 Patchstack
9.3 Critical Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-30807 Patchstack
10.0 Critical DigiWidgets Image Editor Plugin digiwidgets-image-editor Remote Code Execution No login needed ≤ 1.10 CVE-2025-30580 Patchstack
9.3 Critical XV Random Quotes Plugin xv-random-quotes SQL Injection No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-30971 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31095 Patchstack
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
9.8 Critical Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection No login needed ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-31084 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
9.3 Critical JS Help Desk Plugin js-support-ticket SQL Injection No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30886 Patchstack
9.3 Critical Ads by WPQuads Plugin quick-adsense-reloaded SQL Injection No login needed ≤ 2.0.87.1 Fixed in 2.0.88 CVE-2025-30876 Patchstack
9.3 Critical PostMash Plugin postmash-custom SQL Injection No login needed ≤ 1.0.3 CVE-2025-30622 Patchstack
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only