WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 901–950 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Schedule Plugin schedule SQL Injection No login needed ≤ 1.0.0 CVE-2025-22523 Patchstack
9.0 Critical Traveler Plugin traveler PHP Object Injection No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26873 Patchstack
9.3 Critical Traveler Plugin traveler SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26898 Patchstack
9.6 Critical Hide My WP Ghost Plugin hide-my-wp Local File Inclusion Local File Inclusion to RCE No login needed ≤ 5.4.01 Fixed in 5.4.02 CVE-2025-26909 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.0.18 Fixed in 5.0.19 CVE-2025-26941 Patchstack
9.3 Critical Product Catalog Plugin displayproduct SQL Injection No login needed ≤ 1.0.4 CVE-2025-30524 Patchstack
9.3 Critical Trust Payments Gateway for WooCommerce Plugin trust-payments-hosted-payment-pages-integration SQL Injection No login needed ≤ 1.1.4 Fixed in 2.0.0 CVE-2025-28942 Patchstack
9.8 Critical Docpro Plugin docpro Local File Inclusion No login needed ≤ 2.0.1 CVE-2025-28916 Patchstack
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.2 CVE-2025-28898 Patchstack
9.9 Critical Visual Text Editor Plugin visual-text-editor Remote Code Execution ≤ 1.2.1 CVE-2025-28893 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-28904 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
9.3 Critical Awesome Logos Plugin awesome-logos Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.2 CVE-2025-30528 Patchstack
9.8 Critical MinimogWP – The High Converting eCommerce Theme Local File Inclusion The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion No login needed ≤ 3.7.0 CVE-2024-13790 Wordfence
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
9.8 Critical Civi - Job Board & Freelance Marketplace Theme Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Password Update No login needed ≤ 2.1.4 CVE-2024-13771 Wordfence
9.1 Critical ThemeEgg ToolKit Plugin themeegg-toolkit Arbitrary File Upload ≤ 1.2.9 CVE-2025-28915 Patchstack
10.0 Critical Fresh Framework Plugin fresh-framework Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.70.0 CVE-2025-26936 Patchstack
9.0 Critical Massive Dynamic Plugin massive-dynamic Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 8.2 CVE-2025-26916 Patchstack
9.8 Critical Golo - Directory & Listing, Travel Theme Broken Access Control Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change No login needed ≤ 1.6.10 CVE-2024-12876 Wordfence
9.8 Critical VEDA - MultiPurpose Theme PHP Object Injection MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection No login needed ≤ 4.2 CVE-2024-13787 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
10.0 Critical Ark Theme Core Plugin ark-core Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.71.0 Fixed in 1.71.0 CVE-2025-26970 Patchstack
9.8 Critical Residential Address Detection Plugin residential-address-detection Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-27270 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection Worldwide Express Edition Plugin <= 5.2.18 - SQL Injection No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-27268 Patchstack
9.3 Critical Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway SQL Injection No login needed ≤ 1.7.6 CVE-2025-26535 Patchstack
9.3 Critical uListing Plugin ulisting SQL Injection No login needed ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-25150 Patchstack
9.8 Critical Nokri – Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change No login needed ≤ 1.6.2 CVE-2024-12824 Wordfence
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2025-26974 Patchstack
9.8 Critical PrivateContent Plugin private-content Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 8.11.5 CVE-2025-26966 Patchstack
9.3 Critical Easy Quotes Plugin easy-quotes SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-26943 Patchstack
9.8 Critical Flexmls® IDX Plugin flexmls-idx PHP Object Injection No login needed ≤ 3.14.27 Fixed in 3.14.28 CVE-2025-26900 Patchstack
10.0 Critical Chaty Pro Plugin chaty-pro Arbitrary File Upload No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-26776 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack
10.0 Critical Simplified Plugin simplified Arbitrary File Upload No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-22654 Patchstack
9.8 Critical K Elements Plugin k-elements Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.4.0 Fixed in 5.4.0 CVE-2024-56000 Patchstack
9.8 Critical CarSpot – Dealership Wordpress Classified Theme Privilege Escalation Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover No login needed ≤ 2.4.3 CVE-2024-12860 Wordfence
9.3 Critical LTL Freight Quotes – FreightQuote Edition Plugin ltl-freight-quotes-freightquote-edition SQL Injection FreightQuote Edition Plugin <= 2.3.11 - SQL Injection No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-22290 Patchstack
9.9 Critical Widget Options Plugin widget-options Remote Code Execution Arbitrary Code Execution ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-22630 Patchstack
9.8 Critical Real Estate 7 Theme Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed ≤ 3.5.1 CVE-2024-13421 Wordfence
9.6 Critical Munk Sites Plugin munk-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.0.7 CVE-2025-25101 Patchstack
9.6 Critical OneStore Sites Plugin onestore-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 0.1.1 CVE-2025-25107 Patchstack
9.6 Critical Starter Templates by FancyWP Plugin starter-templates Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.0.0 CVE-2025-25106 Patchstack
9.9 Critical Post/Page Copying Tool Plugin postpage-import-export-with-custom-fields-taxonomies Remote Code Execution ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-24677 Patchstack
9.0 Critical Traveler Code Plugin traveler-code SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.1.2 Fixed in 3.1.2 CVE-2025-22699 Patchstack
9.8 Critical iControlWP – Multiple WordPress Site Manager Plugin worpit-admin-dashboard-plugin PHP Object Injection Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.5 CVE-2024-13742 Wordfence
9.8 Critical Save as PDF Plugin save-as-pdf-by-pdfcrowd PHP Object Injection No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-24671 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection No login needed ≤ 5.2.17 Fixed in 5.2.18 CVE-2025-24667 Patchstack
9.3 Critical Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition SQL Injection No login needed ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-24665 Patchstack
9.3 Critical LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition SQL Injection No login needed ≤ 5.0.20 Fixed in 5.0.21 CVE-2025-24664 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only