WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,201–9,250 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 185 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SEO Booster Plugin seo-booster Broken Access Control No login needed ≤ 6.1.8 CVE-2025-68019 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack
7.5 High Antideo Email Validator Plugin antideo-email-validator SQL Injection No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2025-68017 Patchstack
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack
9.0 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2025-68015 Patchstack
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
7.1 High CodeColorer Plugin codecolorer Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 0.10.1 Fixed in 0.10.2 CVE-2025-68012 Patchstack
7.1 High GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-68011 Patchstack
7.1 High Netgsm Plugin netgsm Cross-Site Scripting No login needed ≤ 2.9.63 Fixed in 2.9.64 CVE-2025-68010 Patchstack
6.5 Medium Slider Templates Plugin slider-templates Broken Access Control No login needed ≤ 1.0.3 CVE-2025-68009 Patchstack
7.1 High WP Mail Plugin wp-mail Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-68008 Patchstack
6.5 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Settings Change No login needed ≤ 5.0.37.decaf Fixed in 5.0.53.decaf CVE-2025-68007 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
7.1 High My Post Order Plugin my-posts-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1.1 CVE-2025-68004 Patchstack
6.5 Medium Shown Connector Plugin shown-connector Broken Access Control Settings Change No login needed ≤ 1.2.10 CVE-2025-68003 Patchstack
10.0 Critical g-FFL Checkout Plugin g-ffl-checkout Arbitrary File Upload No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-68001 Patchstack
9.9 Critical Real Homes CRM Plugin realhomes-crm Arbitrary File Upload ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-67968 Patchstack
7.6 High Lawyer Directory Plugin lawyer-directory Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67967 Patchstack
8.8 High Lawyer Directory Plugin lawyer-directory Privilege Escalation ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67966 Patchstack
7.1 High Homey Core Plugin homey-core Cross-Site Scripting No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67964 Patchstack
8.6 High Movie Booking Plugin movie-booking Arbitrary File Deletion No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-67963 Patchstack
6.4 Medium WPO365 Plugin wpo365-login Server-Side Request Forgery ≤ 40.0 Fixed in 40.1 CVE-2025-67961 Patchstack
7.1 High WorkScout-Core Plugin workscout-core Cross-Site Scripting No login needed ≤ 1.7.06 Fixed in 1.7.07 CVE-2025-67960 Patchstack
7.1 High WorkScout Plugin workscout Cross-Site Scripting No login needed ≤ 4.1.07 Fixed in 4.1.08 CVE-2025-67959 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
8.1 High Listivo Core Plugin listivo-core Local File Inclusion No login needed ≤ 2.3.77 Fixed in 2.3.78 CVE-2025-67957 Patchstack
8.2 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 4.4.6 Fixed in 4.4.7 CVE-2025-67956 Patchstack
7.5 High MyHome Core Plugin myhome-core Local File Inclusion ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-67955 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
8.1 High Booking Activities Plugin booking-activities Privilege Escalation No login needed ≤ 1.16.44 Fixed in 1.16.45 CVE-2025-67953 Patchstack
7.1 High Grand Tour Plugin grandtour Cross-Site Scripting No login needed ≤ 5.6.2 Fixed in 5.6.2 CVE-2025-67952 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 94.3.6 Fixed in 94.3.6 CVE-2025-67949 Patchstack
7.1 High AdForest Elementor Plugin adforest-elementor Cross-Site Scripting No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2025-67947 Patchstack
8.1 High AdForest Theme adforest Local File Inclusion No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2025-67946 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution Arbitrary Code Execution ≤ 8.1.8 Fixed in 8.2.0 CVE-2025-67944 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.32 Fixed in 3.6.33 CVE-2025-67943 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2025-67942 Patchstack
8.1 High The Aisle Theme theaisle Local File Inclusion No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2025-67941 Patchstack
8.1 High Powerlift Theme powerlift Local File Inclusion No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-67940 Patchstack
6.5 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.2 Fixed in 3.5.6.3 CVE-2025-67939 Patchstack
8.1 High Biagiotti Theme biagiotti Local File Inclusion No login needed ≤ 3.5.2 Fixed in 3.5.2 CVE-2025-67938 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2025-67923 Patchstack
4.3 Medium WP SEO Search Plugin wp-seo-search Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-67626 Patchstack
7.1 High Anon Plugin anon2x Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.10 CVE-2025-67620 Patchstack
8.8 High Kids Heaven Plugin kids-world PHP Object Injection ≤ 3.2 CVE-2025-67619 Patchstack
9.8 Critical Consult Aid Plugin consultaid PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-67617 Patchstack
8.1 High Mella Plugin mella Local File Inclusion No login needed ≤ 1.2.29 CVE-2025-67616 Patchstack
8.1 High Myour Plugin myour Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-67615 Patchstack
7.1 High TheNa Plugin thena Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.5 CVE-2025-67614 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only