WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,351–9,400 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 188 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Site Notify Plugin site-notify Broken Access Control No login needed ≤ 1.0 CVE-2025-32240 Patchstack
4.3 Medium Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic Plugin vagonic-sortable Broken Access Control ≤ 1.9 CVE-2025-32236 Patchstack
4.3 Medium Tutor LMS Plugin tutor Content Injection HTML Injection ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-32230 Patchstack
4.3 Medium Ai Image Alt Text Generator for WP Plugin ai-image-alt-text-generator-for-wp Information Disclosure Sensitive Data Exposure ≤ 1.1.9 CVE-2025-32228 Patchstack
4.3 Medium Asgaros Forum Plugin asgaros-forum Arbitrary File Upload File Upload Numbers Bypass ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-32227 Patchstack
5.4 Medium EazyDocs Plugin eazydocs Broken Access Control ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-32221 Patchstack
6.4 Medium Spider Elements Plugin spider-elements Broken Access Control Addons for Elementor plugin <= 1.6.6 - Broken Access Control ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-32216 Patchstack
6.5 Medium Accessibility Suite Plugin online-accessibility Arbitrary File Upload ≤ 4.18 Fixed in 4.19 CVE-2025-32215 Patchstack
6.5 Medium Hive Support Plugin hive-support Cross-Site Scripting ≤ 1.2.11 CVE-2025-32214 Patchstack
6.5 Medium Flo Forms Plugin flo-forms Broken Access Control ≤ 1.0.43 CVE-2025-32213 Patchstack
6.5 Medium Specia Companion Plugin specia-companion Broken Access Control ≤ 6.3 CVE-2025-32212 Patchstack
6.5 Medium CM Registration and Invitation Codes Plugin cm-invitation-codes Broken Access Control ≤ 2.5.6 Fixed in 3.3.8 CVE-2025-32210 Patchstack
6.5 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.5 Fixed in 7.1.6 CVE-2025-32209 Patchstack
6.5 Medium Hive Support Plugin hive-support Broken Access Control ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-32208 Patchstack
9.1 Critical Processing Projects Plugin processing-projects Arbitrary File Upload ≤ 1.0.2 CVE-2025-32206 Patchstack
2.7 Low Piotnet Forms Plugin piotnetforms Path Traversal ≤ 1.0.30 CVE-2025-32205 Patchstack
9.1 Critical Insert or Embed Articulate Content into Plugin insert-or-embed-articulate-content-into-wordpress Arbitrary File Upload ≤ 4.3000000025 Fixed in 4.3000000026 CVE-2025-32202 Patchstack
6.5 Medium Contact Form Builder by vcita Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.10.2 Fixed in 4.10.5 CVE-2025-32199 Patchstack
6.5 Medium Brizy Plugin brizy Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-32198 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-32160 Patchstack
7.5 High aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32158 Patchstack
8.8 High WpEvently Plugin mage-eventpress PHP Object Injection ≤ 4.3.6 Fixed in 4.3.7 CVE-2025-32145 Patchstack
9.9 Critical WP Remote Thumbnail Plugin wp-remote-thumbnail Arbitrary File Upload ≤ 1.3.2 CVE-2025-32140 Patchstack
5.9 Medium FooBox Image Lightbox Plugin foobox-image-lightbox Cross-Site Scripting FooBox plugin <= 2.7.33 - Cross Site Scripting (XSS) ≤ 2.7.33 Fixed in 2.7.34 CVE-2025-32139 Patchstack
7.6 High Nearby Locations Plugin nearby-locations SQL Injection ≤ 1.1.1 CVE-2025-32128 Patchstack
8.2 High CardGate Payments for WooCommerce Plugin cardgate SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-32119 Patchstack
7.1 High QR Master Plugin qr-master Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2025-32116 Patchstack
7.1 High Popping Content Light Plugin popping-content-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 CVE-2025-32115 Patchstack
7.1 High 5sterrenspecialist Plugin 5-sterrenspecialist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-32114 Patchstack
8.8 High WP User Profiles Plugin wp-users-profiles Privilege Escalation ≤ 2.6.2 CVE-2025-31524 Patchstack
8.5 High Review Stars Count For WooCommerce Plugin review-stars-count-for-woocommerce SQL Injection ≤ 2.0 CVE-2025-32687 Patchstack
8.1 High Real Estate Manager Plugin real-estate-manager Local File Inclusion No login needed ≤ 7.3 CVE-2025-32668 Patchstack
8.1 High DyaPress ERP/CRM Plugin dyapress Local File Inclusion No login needed ≤ 18.0.2.0 CVE-2025-30582 Patchstack
5.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2025-26888 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Cross-Site Request Forgery No login needed ≤ 2.6.1 CVE-2025-26902 Patchstack
4.3 Medium Brizy Pro Plugin brizy-pro Broken Access Control ≤ 2.6.1 CVE-2025-26901 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation No login needed ≤ 8.7.5 CVE-2025-32695 Patchstack
7.1 High Site Table of Contents Plugin site-table-of-contents Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-31385 Patchstack
7.1 High FrescoChat Live Chat Plugin flexytalk-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.2.6 CVE-2025-31383 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.6 Fixed in 1.6.1 CVE-2025-31002 Patchstack
4.3 Medium Rich Table of Contents Plugin rich-table-of-content Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-31004 Patchstack
2.7 Low Squeeze Plugin squeeze Information Disclosure Full Path Disclosure (FPD) ≤ 1.6 Fixed in 1.6.1 CVE-2025-31003 Patchstack
4.3 Medium Easyfonts Plugin easyfonts Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-31005 Patchstack
5.4 Medium IndieBlocks Plugin indieblocks Server-Side Request Forgery No login needed ≤ 0.13.1 Fixed in 0.13.2 CVE-2025-31009 Patchstack
5.9 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4 CVE-2025-31008 Patchstack
5.3 Medium Age Gate Plugin age-gate Broken Access Control No login needed ≤ 3.5.4 Fixed in 3.6.0 CVE-2025-31012 Patchstack
6.5 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2025-31020 Patchstack
6.5 Medium Nav Menu Manager Plugin noakes-menu-manager Cross-Site Scripting ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-31017 Patchstack
7.1 High Comment Validation Reloaded Plugin comment-validation-reloaded Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5 CVE-2025-31026 Patchstack
8.8 High Seo Meta Tags Plugin seo-meta-tags Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.4 CVE-2025-31023 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only