WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,251–9,300 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 186 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Crumber Plugin crumber-elementor Broken Access Control ≤ 1.0.10 CVE-2025-66143 Patchstack
5.4 Medium Comparimager for Elementor Plugin comparimager-elementor Broken Access Control ≤ 1.0.1 CVE-2025-66142 Patchstack
5.4 Medium Scroller Plugin scroller Broken Access Control ≤ 2.0.2 CVE-2025-66141 Patchstack
5.4 Medium Uper for Elementor Plugin uper-elementor Broken Access Control ≤ 1.0.5 CVE-2025-66140 Patchstack
5.4 Medium Audier For Elementor Plugin audier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66139 Patchstack
5.4 Medium Motionger for Elementor Plugin motionger-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66138 Patchstack
5.4 Medium Searcher for Elementor Plugin searcher-elementor Broken Access Control ≤ 1.0.3 CVE-2025-66137 Patchstack
5.4 Medium Carter for Elementor Plugin carter-elementor Broken Access Control ≤ 1.0.2 CVE-2025-66136 Patchstack
5.4 Medium Imager for Elementor Plugin imager-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66135 Patchstack
4.9 Medium ANAC XML Viewer Plugin anac-xml-viewer Server-Side Request Forgery ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-64252 Patchstack
4.3 Medium REHub Framework Plugin rehub-framework Information Disclosure Sensitive Data Exposure ≤ 19.9.9.4 Fixed in 19.9.9.4 CVE-2025-63051 Patchstack
6.5 Medium Grand Restaurant Theme Elements for Elementor Plugin grandrestaurant-elementor Cross-Site Scripting ≤ 2.1.1 CVE-2025-63026 Patchstack
5.3 Medium Cookies and Content Security Policy Plugin cookies-and-content-security-policy Information Disclosure Sensitive Data Exposure No login needed ≤ 2.34 Fixed in 2.35 CVE-2025-63019 Patchstack
4.3 Medium Bard Plugin bard Broken Access Control ≤ 2.229 CVE-2025-63018 Patchstack
7.5 High WerkStatt Plugin werkstatt-plugin Local File Inclusion ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-63017 Patchstack
5.3 Medium Payment Gateway bKash for WC Plugin woo-payment-bkash Broken Access Control No login needed ≤ 3.1.0 CVE-2025-62754 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack
5.4 Medium WP-CRM System Plugin wp-crm-system Broken Access Control ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-62106 Patchstack
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
9.9 Critical News Event Plugin news-event Arbitrary File Upload ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-62056 Patchstack
9.9 Critical Blogmatic Plugin blogmatic Arbitrary File Upload ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-62050 Patchstack
6.5 Medium Electron Plugin electron Broken Access Control ≤ 1.8.2 CVE-2025-5805 Patchstack
8.1 High Depot Plugin depot Local File Inclusion No login needed ≤ 1.16 CVE-2025-54003 Patchstack
6.5 Medium xSmart Plugin xsmart Broken Access Control ≤ 1.2.9.4 CVE-2025-54002 Patchstack
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
7.1 High flexo-posts-manager Plugin flexo-posts-manager Cross-Site Scripting No login needed ≤ 1.0001 CVE-2025-52762 Patchstack
7.1 High Restaurante Plugin restaurante Cross-Site Scripting No login needed ≤ 3.0.7 Fixed in 3.1.1 CVE-2025-52746 Patchstack
8.8 High xSmart Plugin xsmart Privilege Escalation ≤ 1.2.9.4 CVE-2025-50007 Patchstack
7.1 High xSmart Plugin xsmart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9.4 CVE-2025-50006 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50005 Patchstack
8.8 High JupiterX Core Plugin jupiterx-core PHP Object Injection ≤ 4.10.1 Fixed in 4.11.0 CVE-2025-50004 Patchstack
8.1 High Amuli Plugin amuli Local File Inclusion No login needed ≤ 2.3.0 CVE-2025-50003 Patchstack
10.0 Critical Energia Plugin energia Arbitrary File Upload No login needed ≤ 1.1.2 CVE-2025-50002 Patchstack
8.1 High Athens Plugin athens Local File Inclusion No login needed ≤ 1.1.6 CVE-2025-49994 Patchstack
5.4 Medium HomeLancer Plugin homelancer Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-49375 Patchstack
5.9 Medium Pondol BBS Plugin pondol-bbs Cross-Site Scripting ≤ 1.1.8.4 CVE-2025-49336 Patchstack
7.1 High Drone Plugin drone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.40 CVE-2025-49249 Patchstack
7.1 High Accordion Slider PRO Plugin accordion_slider_pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-49066 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection No login needed ≤ 2.5 CVE-2025-49055 Patchstack
8.5 High WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection ≤ 2.5 CVE-2025-49050 Patchstack
8.5 High DZS Video Gallery Plugin dzs-videogallery SQL Injection ≤ 12.39 Fixed in 12.40 CVE-2025-49049 Patchstack
7.1 High xPromoter Plugin top_bar_promoter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 CVE-2025-49046 Patchstack
7.1 High Super Interactive Maps Plugin super-interactive-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-49045 Patchstack
7.1 High Magic Responsive Slider and Carousel Plugin magic_carousel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-49043 Patchstack
7.1 High Magic Slider Plugin magic_slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-48094 Patchstack
7.1 High Image&Video FullScreen Background Plugin lbg_fullscreen_fullwidth_slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 CVE-2025-47666 Patchstack
5.3 Medium WoodMart Theme woodmart Arbitrary Shortcode Execution No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2025-47600 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
5.9 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting ≤ 3.19.5 Fixed in 3.19.6 CVE-2025-47500 Patchstack
8.1 High Anarkali Plugin anarkali Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-47474 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only