WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,301–9,350 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 187 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP Table Builder Plugin wp-table-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-32598 Patchstack
8.1 High Flexi – Guest Submit Plugin flexi Local File Inclusion Guest Submit Plugin <= 4.28 - Local File Inclusion No login needed ≤ 4.28 CVE-2025-32589 Patchstack
8.1 High WooCommerce Pickupp Plugin wc-pickupp Local File Inclusion No login needed ≤ 2.4.3 CVE-2025-32587 Patchstack
7.1 High ABA PayWay Payment Gateway for WooCommerce Plugin aba-payway-woocommerce-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-32586 Patchstack
7.5 High Shop Products Filter Plugin trusty-woo-products-filter Local File Inclusion ≤ 1.2 CVE-2025-32585 Patchstack
9.9 Critical Sync Posts Plugin sync-posts Arbitrary File Upload ≤ 1.0 CVE-2025-32579 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2025-32577 Patchstack
9.8 Critical TableOn Plugin posts-table-filterable PHP Object Injection No login needed ≤ 1.0.4.3 Fixed in 1.0.4.4 CVE-2025-32569 Patchstack
9.8 Critical EmpikPlace for Woocommerce Plugin empik-for-woocommerce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32568 Patchstack
8.5 High Easy Post Duplicator Plugin easy-post-duplicator SQL Injection ≤ 1.0.1 CVE-2025-32567 Patchstack
9.3 Critical Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.0 CVE-2025-32565 Patchstack
8.5 High Duplicate Title Checker Plugin duplicate-title-checker SQL Injection ≤ 1.2 CVE-2025-32558 Patchstack
7.1 High RestroPress Plugin restropress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.8.4 CVE-2025-32553 Patchstack
7.1 High Connector to CiviCRM with CiviMcRestFace Plugin connector-civicrm-mcrestface Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-32551 Patchstack
8.8 High Eazy Plugin Manager Plugin plugins-on-steroids Broken Access Control ≤ 4.3.0 Fixed in 4.4.0 CVE-2025-32542 Patchstack
7.1 High WooCommerce Sales MIS Report Plugin woocommerce-mis-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 CVE-2025-32541 Patchstack
7.1 High Store Exporter Plugin woocommerce-exporter Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-32539 Patchstack
7.1 High Easy Post Duplicator Plugin easy-post-duplicator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-32538 Patchstack
7.1 High Lock Your Updates Plugin lock-your-updates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-32537 Patchstack
7.1 High HTML5 Video Player with Playlist Plugin html5-video-player-with-playlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.50 CVE-2025-32536 Patchstack
7.1 High Workbox Video from Vimeo & Youtube Plugin workbox-video-from-vimeo-youtube-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.2 CVE-2025-32534 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.24 Fixed in 1.6.25 CVE-2025-32525 Patchstack
7.1 High MyWorks WooCommerce Sync for QuickBooks Online Plugin myworks-woo-sync-for-quickbooks-online Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-32524 Patchstack
7.1 High WooCommerce – Payphone Gateway Plugin wc-payphone-gateway Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32523 Patchstack
8.1 High IDonate Plugin idonate Local File Inclusion No login needed ≤ 2.1.18 CVE-2025-32519 Patchstack
7.1 High MultiMailer Plugin scand-multi-mailer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-32517 Patchstack
7.5 High Simple WP Events Plugin simple-wp-events Arbitrary File Deletion No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32509 Patchstack
9.8 Critical Rankology SEO – On-site SEO Plugin rankology-seo-all-in-one-seo-analytics Privilege Escalation On-site SEO plugin <= 2.2.4 - Privilege Escalation No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-32491 Patchstack
8.8 High Job Board Manager Plugin job-board-manager PHP Object Injection ≤ 2.1.61 CVE-2025-32144 Patchstack
8.8 High Accordion Plugin accordions PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-32143 Patchstack
9.3 Critical Bulk Product Sync Plugin sync-wc-google SQL Injection No login needed ≤ 8.6 Fixed in 9.0 CVE-2025-31599 Patchstack
9.3 Critical WPSmartContracts Plugin wp-smart-contracts SQL Injection No login needed ≤ 2.0.12 CVE-2025-31565 Patchstack
7.1 High Insert HTML Here Plugin insert-html-here Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-31379 Patchstack
7.1 High Oppso Unit Converter Plugin oppso-unit-converter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-31378 Patchstack
7.5 High AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.5.5 CVE-2025-31041 Patchstack
8.1 High WP Food ordering and Restaurant Menu Plugin wp-food Local File Inclusion No login needed ≤ 2.7 CVE-2025-31040 Patchstack
7.1 High WP Hide Categories Plugin wp-hide-categories Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-31028 Patchstack
7.1 High Mobile Smart Plugin mobile-smart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v1.3.16 CVE-2025-31021 Patchstack
7.5 High WordPress SMTP Service, Email Delivery Solved! — MailHawk Plugin mailhawk Local File Inclusion No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-31015 Patchstack
7.5 High Material Dashboard Plugin material-dashboard Local File Inclusion ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31014 Patchstack
7.1 High Vice Versa Plugin vice-versa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2025-27350 Patchstack
5.9 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Path Traversal Arbitrary File Read/Deletion ≤ 3.5.12 Fixed in 3.6.0 CVE-2025-31411 Patchstack
7.5 High JetCompareWishlist Plugin jet-compare-wishlist Local File Inclusion ≤ 1.5.9 Fixed in 1.5.10 CVE-2025-22279 Patchstack
4.3 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Cross-Site Request Forgery No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-32282 Patchstack
4.3 Medium Survey Maker Plugin survey-maker Authentication Bypass No login needed ≤ 5.1.6.3 Fixed in 5.1.6.4 CVE-2025-32275 Patchstack
5.3 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Broken Access Control No login needed ≤ 2.1.10 CVE-2025-32260 Patchstack
5.3 Medium WP ULike Plugin wp-ulike Content Injection Content Spoofing No login needed ≤ 4.7.9.1 Fixed in 4.7.10 CVE-2025-32259 Patchstack
6.5 Medium SEO Help Plugin seo-help Broken Access Control No login needed ≤ 6.7.9 CVE-2025-32244 Patchstack
6.5 Medium Internal Link Optimiser Plugin internal-link-finder Broken Access Control Settings Change No login needed ≤ 5.1.2 Fixed in 5.1.3 CVE-2025-32243 Patchstack
6.5 Medium Hive Support Plugin hive-support Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-32242 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only