WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,051–9,100 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 182 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Simple WP Events Plugin simple-wp-events Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32594 Patchstack
7.1 High WooMS Plugin wooms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.12 CVE-2025-32602 Patchstack
7.3 High Real Estate Manager Plugin real-estate-manager Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.3 CVE-2025-32596 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-32605 Patchstack
7.1 High AWSA Shipping Plugin awsa-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2025-32604 Patchstack
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
7.1 High Verowa Connect Plugin verowa-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-32609 Patchstack
7.1 High Movylo Marketing Automation Plugin movylo-widget Cross-Site Scripting No login needed ≤ 2.0.7 CVE-2025-32608 Patchstack
7.1 High Debug Log Manager Plugin debug-log-manager Cross-Site Scripting No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-32613 Patchstack
7.1 High WooCommerce TBC Credit Card Payment Gateway (Free) Plugin woo-tbc-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-32611 Patchstack
7.1 High Clinked Client Portal Plugin clinked-client-portal Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.10 CVE-2025-32615 Patchstack
7.1 High OTP-less one tap Sign in Plugin otpless Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.58 Fixed in 2.0.59 CVE-2025-32622 Patchstack
7.1 High Doppler Forms Plugin doppler-form Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-32620 Patchstack
9.3 Critical JS Job Manager Plugin js-jobs SQL Injection No login needed ≤ 2.0.2 CVE-2025-32626 Patchstack
7.1 High Mobile Pages Plugin mobile-pages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-32625 Patchstack
7.1 High Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.12 Fixed in 3.1.13 CVE-2025-32628 Patchstack
7.1 High Run Contests, Raffles, and Giveaways with ContestsWP Plugin contest-code-checker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-32634 Patchstack
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32630 Patchstack
9.3 Critical Local Magic Plugin local-magic SQL Injection No login needed ≤ 2.9.0 CVE-2025-32636 Patchstack
7.5 High Hive Support Plugin hive-support Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-32635 Patchstack
7.1 High WP Donate Plugin wp-donate Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-32637 Patchstack
7.1 High Affiliate Links Lite Plugin affiliate-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.0 Fixed in 3.2.0 CVE-2025-32639 Patchstack
7.1 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Cross-Site Scripting No login needed ≤ 0.4.61 CVE-2025-32638 Patchstack
8.8 High Question Answer Plugin question-answer PHP Object Injection ≤ 1.2.73 CVE-2025-32647 Patchstack
7.1 High Question Answer Plugin question-answer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.70 Fixed in 1.2.71 CVE-2025-32646 Patchstack
9.8 Critical Projectopia Plugin projectopia-core Privilege Escalation No login needed ≤ 5.1.24 CVE-2025-32648 Patchstack
7.1 High SERPed.net Plugin serped-net Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.6 Fixed in 4.7 CVE-2025-32651 Patchstack
7.1 High GB Gallery Slideshow Plugin gb-gallery-slideshow Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-32649 Patchstack
7.1 High Cart66 Cloud Plugin cart66-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.7 CVE-2025-32653 Patchstack
9.9 Critical Solace Extra Plugin solace-extra Arbitrary File Upload ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-32652 Patchstack
7.1 High Restrict User Registration Plugin restrict-user-registration Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-32655 Patchstack
10.0 Critical JS Job Manager Plugin js-jobs Arbitrary File Upload No login needed ≤ 2.0.2 CVE-2025-32660 Patchstack
9.8 Critical HelpGent Plugin helpgent PHP Object Injection No login needed ≤ 2.2.5 CVE-2025-32658 Patchstack
8.8 High uListing Plugin ulisting PHP Object Injection Deserialization of untrusted data ≤ 2.2.0 CVE-2025-32662 Patchstack
7.1 High Hive Support Plugin hive-support Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-32666 Patchstack
9.3 Critical Office Locator Plugin office-locator SQL Injection No login needed ≤ 1.3.0 CVE-2025-32665 Patchstack
7.1 High Spark GF Failed Submissions Plugin spark-gf-failed-submissions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-32670 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32682 Patchstack
7.1 High Product Excel Import Export & Bulk Edit for WooCommerce Plugin webd-woocommerce-product-excel-importer-bulk-edit Cross-Site Scripting No login needed ≤ 4.7 CVE-2025-32674 Patchstack
7.1 High Bulk Page Stub Creator Plugin bulk-page-stub-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-39519 Patchstack
8.8 High Team Members Plugin wps-team PHP Object Injection ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-32686 Patchstack
7.1 High Contact Form vCard Generator Plugin contact-form-vcard-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 CVE-2025-39521 Patchstack
8.8 High Rating by BestWebSoft Plugin rating-bws PHP Object Injection ≤ 1.7 CVE-2025-39527 Patchstack
8.1 High Hotel Booking Plugin nd-booking Local File Inclusion No login needed ≤ 3.6 Fixed in 3.7 CVE-2025-39526 Patchstack
7.5 High Spice Blocks Plugin spice-blocks Broken Access Control No login needed ≤ 2.0.7.7 CVE-2025-39532 Patchstack
7.2 High Vitepos Plugin vitepos-lite Authentication Bypass Broken Authentication ≤ 3.1.7 Fixed in 3.1.8 CVE-2025-39535 Patchstack
8.8 High Starfish Review Generation & Marketing Plugin starfish-reviews Privilege Escalation ≤ 3.1.19 Fixed in 3.1.20 CVE-2025-39533 Patchstack
9.8 Critical FluentCommunity Plugin fluent-community PHP Object Injection No login needed ≤ 1.2.15 Fixed in 1.3.1 CVE-2025-39550 Patchstack
8.8 High Xelion Webchat Plugin xelion-webchat Privilege Escalation ≤ 9.1.0 Fixed in 9.2.0 CVE-2025-39542 Patchstack
9.8 Critical FluentBoards Plugin fluent-boards PHP Object Injection No login needed ≤ 1.47 Fixed in 1.48 CVE-2025-39551 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only