WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 851–900 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Entrada Theme entrada SQL Injection No login needed ≤ 5.7.7 CVE-2025-39484 Patchstack
9.1 Critical Media File Renamer Plugin media-file-renamer Remote Code Execution Arbitrary File Rename lead to RCE ≤ 5.7.7 Fixed in 5.7.8 CVE-2023-50897 Patchstack
9.3 Critical Infility Global Plugin infility-global SQL Injection No login needed ≤ 2.15.06 CVE-2025-68865 Patchstack
9.9 Critical Shopo Theme shopo Arbitrary File Upload ≤ 1.1.4 CVE-2025-31048 Patchstack
9.3 Critical Amazon Native Shopping Recommendations Plugin woozone-contextual SQL Injection No login needed ≤ 1.3 CVE-2025-30633 Patchstack
9.8 Critical Branda – White Label & Branding, Free Login Page Customizer Plugin branda-white-labeling Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.4.24 CVE-2025-14998 Wordfence
9.6 Critical WING WordPress Migrator Plugin wing-migrator Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 2.0.0 CVE-2025-52835 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.7.3 Fixed in 8.7.4 CVE-2025-68562 Patchstack
9.8 Critical Mobile builder Plugin mobile-builder Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 CVE-2025-68860 Patchstack
9.9 Critical IF AS Shortcode Plugin if-as-shortcode Remote Code Execution ≤ 1.2 CVE-2025-68897 Patchstack
9.8 Critical Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 5.8.0 CVE-2025-13773 Wordfence
9.8 Critical PhastPress Plugin phastpress Path Traversal Unauthenticated Arbitrary File Read via Null Byte Injection No login needed ≤ 3.7 CVE-2025-14388 Wordfence
9.8 Critical Flex Store Users Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.1.0 CVE-2025-13619 Wordfence
9.8 Critical File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via add-image-data No login needed ≤ 1.0.3 CVE-2025-13329 Wordfence
9.8 Critical Tuturn Plugin tuturn Authentication Bypass Broken Authentication No login needed < 3.6 Fixed in 3.6 CVE-2025-64236 Patchstack
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
9.0 Critical WP Webhooks Plugin wp-webhooks Arbitrary File Upload No login needed ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66074 Patchstack
9.9 Critical Motors Theme motors Arbitrary File Upload ≤ 5.6.81 Fixed in 5.6.82 CVE-2025-64374 Patchstack
9.8 Critical Codiqa Theme codiqa PHP Object Injection No login needed ≤ 1.2.8 Fixed in 1.2.8 CVE-2025-64233 Patchstack
9.9 Critical WordPress Contact Form 7 PDF, Google Sheet & Database Plugin rtwwcfp-wordpress-contact-form-7-pdf Arbitrary File Upload ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64231 Patchstack
9.8 Critical Client Invoicing by Sprout Invoices Plugin sprout-invoices PHP Object Injection No login needed ≤ 20.8.7 Fixed in 20.8.8 CVE-2025-64227 Patchstack
9.8 Critical Jannah Plugin jannah PHP Object Injection No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64206 Patchstack
9.8 Critical Soledad Theme soledad Privilege Escalation No login needed ≤ 8.6.9 Fixed in 8.6.9.1 CVE-2025-64188 Patchstack
9.8 Critical WP Gravity Forms Salesforce Plugin gf-salesforce-crmperks PHP Object Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-60180 Patchstack
9.8 Critical WP Gravity Forms HubSpot Plugin gf-hubspot PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60178 Patchstack
9.8 Critical WP Gravity Forms Constant Contact Plugin gf-constant-contact PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-60174 Patchstack
9.8 Critical WP Gravity Forms Zoho CRM and Bigin Plugin gf-zoho PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-60091 Patchstack
9.8 Critical WP Gravity Forms Insightly Plugin gf-insightly PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-60090 Patchstack
9.8 Critical WP Gravity Forms FreshDesk Plugin gf-freshdesk PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-60089 Patchstack
9.3 Critical tPlayer Plugin tplayer-html5-audio-player-with-playlist SQL Injection No login needed ≤ 1.2.1.6 CVE-2025-60062 Patchstack
9.3 Critical Advance Seat Reservation Management for WooCommerce Plugin scw-seat-reservation SQL Injection No login needed ≤ 3.1 CVE-2025-58951 Patchstack
9.8 Critical DentiCare Plugin denticare PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.3 CVE-2025-54723 Patchstack
9.8 Critical EasyEat Theme easyeat Local File Inclusion No login needed ≤ 1.9.0 CVE-2025-53433 Patchstack
9.8 Critical Fox LMS – WordPress LMS Plugin fox-lms Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed 1.0.4.7 – 1.0.5.1 CVE-2025-14156 Wordfence
9.8 Critical URL Shortener Plugin exact-links SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.0.7 CVE-2025-10738 Wordfence
9.8 Critical Export WP Page to Static HTML & PDF Plugin Information Disclosure Unauthenticated Cookie Exposure via Log File No login needed ≤ 4.3.4 CVE-2025-11693 Wordfence
9.8 Critical JAY Login & Register Plugin jay-login-register Authentication Bypass Authentication Bypass via Cookie No login needed ≤ 2.4.01 CVE-2025-14440 Wordfence
9.8 Critical LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Plugin lazytasks-project-task-management Broken Access Control Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation No login needed ≤ 1.2.29 CVE-2025-12963 Wordfence
9.8 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.1.7 CVE-2025-14344 Wordfence
9.8 Critical WP CarDealer Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.2.16 CVE-2025-13764 Wordfence
9.8 Critical Elated Membership Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 1.2 CVE-2025-13613 Wordfence
9.6 Critical 10Web Booster Plugin tenweb-speed-optimizer Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache ≤ 2.32.7 CVE-2025-13377 Wordfence
9.8 Critical Flex QR Code Generator Plugin flex-qr-code-generator Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2.7 CVE-2025-12673 Wordfence
9.8 Critical Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification Plugin user-verification Authentication Bypass User Verification <= 2.0.44 - Authentication Bypass to Account Takeover No login needed ≤ 2.0.44 CVE-2025-12374 Wordfence
9.8 Critical CRM Memberships Plugin crm-memberships Broken Access Control Missing Authorization to Privilege Escalation via Unauthenticated Password Reset in 'ntzcrm_changepassword' AJAX Endpoint No login needed ≤ 2.6 CVE-2025-13313 Wordfence
10.0 Critical WP Directory Kit Plugin wpdirectorykit Authentication Bypass Authentication Bypass to Privilege Escalation via Account Takeover No login needed 1.4.0 – 1.4.4 CVE-2025-13390 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Unauthenticated Arbitrary Options Update No login needed ≤ 3.28.20 CVE-2025-13342 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Remote Code Execution Unauthenticated Remote Code Execution in prepare_form No login needed 0.9.0.5 – 0.9.1.1 CVE-2025-13486 Wordfence
9.8 Critical DesignThemes LMS Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.4 CVE-2025-13542 Wordfence
9.8 Critical StreamTube Core Plugin Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 4.78 CVE-2025-13615 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only