WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 9,301–9,350 of 17,220 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | WP Table Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2025-32598 |
Patchstack | |
| 8.1 High | Flexi – Guest Submit | Local File Inclusion Guest Submit Plugin <= 4.28 - Local File Inclusion No login needed |
≤ 4.28 |
CVE-2025-32589 |
Patchstack | |
| 8.1 High | WooCommerce Pickupp | Local File Inclusion No login needed |
≤ 2.4.3 |
CVE-2025-32587 |
Patchstack | |
| 7.1 High | ABA PayWay Payment Gateway for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.4 Fixed in 2.1.5 |
CVE-2025-32586 |
Patchstack | |
| 7.5 High | Shop Products Filter | Local File Inclusion |
≤ 1.2 |
CVE-2025-32585 |
Patchstack | |
| 9.9 Critical | Sync Posts | Arbitrary File Upload |
≤ 1.0 |
CVE-2025-32579 |
Patchstack | |
| 9.8 Critical | Build App Online | Local File Inclusion No login needed |
≤ 1.0.23 |
CVE-2025-32577 |
Patchstack | |
| 9.8 Critical | TableOn | PHP Object Injection No login needed |
≤ 1.0.4.3 Fixed in 1.0.4.4 |
CVE-2025-32569 |
Patchstack | |
| 9.8 Critical | EmpikPlace for Woocommerce | PHP Object Injection No login needed |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2025-32568 |
Patchstack | |
| 8.5 High | Easy Post Duplicator | SQL Injection |
≤ 1.0.1 |
CVE-2025-32567 |
Patchstack | |
| 9.3 Critical | Neon Product Designer | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.2.0 |
CVE-2025-32565 |
Patchstack | |
| 8.5 High | Duplicate Title Checker | SQL Injection |
≤ 1.2 |
CVE-2025-32558 |
Patchstack | |
| 7.1 High | RestroPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.8.4 |
CVE-2025-32553 |
Patchstack | |
| 7.1 High | Connector to CiviCRM with CiviMcRestFace | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.8 Fixed in 1.0.9 |
CVE-2025-32551 |
Patchstack | |
| 8.8 High | Eazy Plugin Manager | Broken Access Control |
≤ 4.3.0 Fixed in 4.4.0 |
CVE-2025-32542 |
Patchstack | |
| 7.1 High | WooCommerce Sales MIS Report | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.3 |
CVE-2025-32541 |
Patchstack | |
| 7.1 High | Store Exporter | Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed |
≤ 2.7.4 Fixed in 2.7.5 |
CVE-2025-32539 |
Patchstack | |
| 7.1 High | Easy Post Duplicator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-32538 |
Patchstack | |
| 7.1 High | Lock Your Updates | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2025-32537 |
Patchstack | |
| 7.1 High | HTML5 Video Player with Playlist | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.50 |
CVE-2025-32536 |
Patchstack | |
| 7.1 High | Workbox Video from Vimeo & Youtube | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.2 |
CVE-2025-32534 |
Patchstack | |
| 7.1 High | Interactive Geo Maps | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.24 Fixed in 1.6.25 |
CVE-2025-32525 |
Patchstack | |
| 7.1 High | MyWorks WooCommerce Sync for QuickBooks Online | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2025-32524 |
Patchstack | |
| 7.1 High | WooCommerce – Payphone Gateway | Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.0 Fixed in 3.2.1 |
CVE-2025-32523 |
Patchstack | |
| 8.1 High | IDonate | Local File Inclusion No login needed |
≤ 2.1.18 |
CVE-2025-32519 |
Patchstack | |
| 7.1 High | MultiMailer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.3 |
CVE-2025-32517 |
Patchstack | |
| 7.5 High | Simple WP Events | Arbitrary File Deletion No login needed |
≤ 1.8.17 Fixed in 1.9.0 |
CVE-2025-32509 |
Patchstack | |
| 9.8 Critical | Rankology SEO – On-site SEO | Privilege Escalation On-site SEO plugin <= 2.2.4 - Privilege Escalation No login needed |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2025-32491 |
Patchstack | |
| 8.8 High | Job Board Manager | PHP Object Injection |
≤ 2.1.61 |
CVE-2025-32144 |
Patchstack | |
| 8.8 High | Accordion | PHP Object Injection |
≤ 2.3.11 Fixed in 2.3.12 |
CVE-2025-32143 |
Patchstack | |
| 9.3 Critical | Bulk Product Sync | SQL Injection No login needed |
≤ 8.6 Fixed in 9.0 |
CVE-2025-31599 |
Patchstack | |
| 9.3 Critical | WPSmartContracts | SQL Injection No login needed |
≤ 2.0.12 |
CVE-2025-31565 |
Patchstack | |
| 7.1 High | Insert HTML Here | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-31379 |
Patchstack | |
| 7.1 High | Oppso Unit Converter | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.1 |
CVE-2025-31378 |
Patchstack | |
| 7.5 High | AnyTrack Affiliate Link Manager | Broken Access Control No login needed |
≤ 1.0.4 Fixed in 1.5.5 |
CVE-2025-31041 |
Patchstack | |
| 8.1 High | WP Food ordering and Restaurant Menu | Local File Inclusion No login needed |
≤ 2.7 |
CVE-2025-31040 |
Patchstack | |
| 7.1 High | WP Hide Categories | Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-31028 |
Patchstack | |
| 7.1 High | Mobile Smart | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ v1.3.16 |
CVE-2025-31021 |
Patchstack | |
| 7.5 High | WordPress SMTP Service, Email Delivery Solved! — MailHawk | Local File Inclusion No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-31015 |
Patchstack | |
| 7.5 High | Material Dashboard | Local File Inclusion |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2025-31014 |
Patchstack | |
| 7.1 High | Vice Versa | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.3 |
CVE-2025-27350 |
Patchstack | |
| 5.9 Medium | Linet ERP-Woocommerce Integration | Path Traversal Arbitrary File Read/Deletion |
≤ 3.5.12 Fixed in 3.6.0 |
CVE-2025-31411 |
Patchstack | |
| 7.5 High | JetCompareWishlist | Local File Inclusion |
≤ 1.5.9 Fixed in 1.5.10 |
CVE-2025-22279 |
Patchstack | |
| 4.3 Medium | ShareThis Dashboard for Google Analytics | Cross-Site Request Forgery No login needed |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2025-32282 |
Patchstack | |
| 4.3 Medium | Survey Maker | Authentication Bypass No login needed |
≤ 5.1.6.3 Fixed in 5.1.6.4 |
CVE-2025-32275 |
Patchstack | |
| 5.3 Medium | DethemeKit For Elementor | Broken Access Control No login needed |
≤ 2.1.10 |
CVE-2025-32260 |
Patchstack | |
| 5.3 Medium | WP ULike | Content Injection Content Spoofing No login needed |
≤ 4.7.9.1 Fixed in 4.7.10 |
CVE-2025-32259 |
Patchstack | |
| 6.5 Medium | SEO Help | Broken Access Control No login needed |
≤ 6.7.9 |
CVE-2025-32244 |
Patchstack | |
| 6.5 Medium | Internal Link Optimiser | Broken Access Control Settings Change No login needed |
≤ 5.1.2 Fixed in 5.1.3 |
CVE-2025-32243 |
Patchstack | |
| 6.5 Medium | Hive Support | Broken Access Control No login needed |
≤ 1.2.5 Fixed in 1.2.6 |
CVE-2025-32242 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.