WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 901–950 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Tiare Membership Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.2 CVE-2025-13540 Wordfence
9.8 Critical FindAll Membership Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 1.0.4 CVE-2025-13539 Wordfence
9.8 Critical Tiger Theme Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 101.2.1 CVE-2025-13675 Wordfence
9.8 Critical FindAll Listing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.5 CVE-2025-13538 Wordfence
9.8 Critical AI Feeds Plugin ai-feeds Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.11 CVE-2025-13597 Wordfence
9.8 Critical CIBELES AI Plugin cibeles-ai Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.10.8 CVE-2025-13595 Wordfence
9.8 Critical EduKart Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2025-13559 Wordfence
9.8 Critical Sneeit Framework Plugin Remote Code Execution Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback No login needed ≤ 8.3 CVE-2025-6389 Wordfence
9.8 Critical Mstoreapp Mobile (App Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0.8, ≤ 9.0.1 CVE-2025-11127 WPScan
9.8 Critical ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.1 CVE-2025-11456 Wordfence
9.8 Critical WavePlayer Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 3.8.0 Fixed in 3.8.0 CVE-2025-12057 WPScan
9.0 Critical W3 Total Cache Plugin w3-total-cache Remote Code Execution Unauthenticated Command Injection No login needed < 2.8.13 Fixed in 2.8.13 CVE-2025-9501 WPScan
10.0 Critical TNC Toolbox: Web Performance Plugin tnc-toolbox Information Disclosure Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover No login needed ≤ 1.4.2 CVE-2025-12539 Wordfence
9.8 Critical WP移行専用プラグイン for CPI Plugin cpi-wp-migration Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2025-11170 Wordfence
9.8 Critical Holiday class post calendar Plugin holiday-class-post-calendar Remote Code Execution Unauthenticated Remote Code Execution via 'contents' No login needed ≤ 7.1 CVE-2025-12813 Wordfence
9.8 Critical EasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin easycommerce Privilege Escalation AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 - Unauthenticated Privilege Escalation No login needed ≤ 1.8.2 CVE-2025-11457 Wordfence
9.8 Critical Gravity Forms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'copy_post_image' No login needed ≤ 2.9.20 CVE-2025-12352 Wordfence
10.0 Critical King Addons for Elementor Plugin king-addons Arbitrary File Upload No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6327 Patchstack
9.8 Critical King Addons for Elementor Plugin king-addons Privilege Escalation No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6325 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Arbitrary File Upload ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-62065 Patchstack
9.8 Critical Search & Go Plugin search-and-go Authentication Bypass Broken Authentication No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-62064 Patchstack
9.9 Critical Case Addons Plugin case-addons Arbitrary File Upload ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-62047 Patchstack
9.9 Critical KALLYAS Theme kallyas Arbitrary File Upload ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62016 Patchstack
9.8 Critical WP User Manager Plugin wp-user-manager PHP Object Injection No login needed ≤ 2.9.12 Fixed in 2.9.13 CVE-2025-60245 Patchstack
9.8 Critical Selling Commander for WooCommerce Plugin selling-commander-connector Privilege Escalation No login needed ≤ 1.2.46 CVE-2025-60243 Patchstack
10.0 Critical Support Ticket System for WooCommerce (Premium) Plugin support-ticket-system-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.7 CVE-2025-60235 Patchstack
10.0 Critical Custom User Registration Fields for WooCommerce Plugin user-registration-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 2.1.2 CVE-2025-60207 Patchstack
9.8 Critical Atarim Plugin atarim-visual-collaboration Privilege Escalation No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60195 Patchstack
9.8 Critical s2Member Plugin s2member PHP Object Injection No login needed ≤ 250701 Fixed in 250905 CVE-2025-58998 Patchstack
9.1 Critical Advanced Settings Plugin advanced-settings Arbitrary File Upload ≤ 3.1.1 Fixed in 3.2.0 CVE-2025-58996 Patchstack
9.8 Critical WP Gravity Forms Keap/Infusionsoft Plugin gf-infusionsoft PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-58636 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2025-58627 Patchstack
10.0 Critical Drop Uploader for CF7 - Drag&Drop File Uploader Addon Plugin drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon Arbitrary File Upload Drag&Drop File Uploader Addon Plugin <= 2.4.1 - Arbitrary File Upload No login needed ≤ 2.4.1 CVE-2025-53283 Patchstack
9.8 Critical Seil Theme seil PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.7.1 CVE-2025-53242 Patchstack
9.3 Critical HieCOR Payment Gateway Plugin hcv4-payment-gateway SQL Injection No login needed ≤ 1.5.11 Fixed in 2.0.0 CVE-2025-52773 Patchstack
9.8 Critical Sign-up Sheets Plugin sign-up-sheets PHP Object Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-49393 Patchstack
10.0 Critical HAPPY Plugin happy-helpdesk-support-ticket-system Remote Code Execution No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49372 Patchstack
9.3 Critical Education WordPress Theme | HiStudy Theme histudy SQL Injection No login needed ≤ 3.1.0 Fixed in 3.1.0 CVE-2025-48089 Patchstack
9.1 Critical Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Remote Code Execution Arbitrary Code Execution ≤ 4.5.9 Fixed in 4.5.10 CVE-2025-47588 Patchstack
9.9 Critical Widget Logic Plugin widget-logic Remote Code Execution ≤ 6.0.5 Fixed in 6.0.6 CVE-2025-32222 Patchstack
9.8 Critical KiotViet Sync Plugin kiotvietsync Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.8.5 CVE-2025-12674 Wordfence
9.8 Critical AI Engine Plugin ai-engine Information Disclosure Unauthenticated Sensitive Information Exposure to Privilege Escalation No login needed ≤ 3.1.3 CVE-2025-11749 Wordfence
9.8 Critical Easy Upload Files During Checkout Plugin easy-upload-files-during-checkout Arbitrary File Upload Unauthenticated Arbitrary JavaScript File Upload No login needed ≤ 2.9.8 CVE-2025-12682 Wordfence
9.8 Critical ShopLentor Plugin woolentor-addons Local File Inclusion Unauthenticated Local PHP File Inclusion via 'load_template' No login needed ≤ 3.2.5 CVE-2025-12493 Wordfence
9.8 Critical Simple User Capabilities Plugin simple-user-capabilities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation No login needed ≤ 1.0 CVE-2025-12158 Wordfence
9.8 Critical CE21 Suite Plugin ce21-suite Information Disclosure Unauthenticated Sensitive Information Exposure to Privilege Escalation No login needed ≤ 2.3.1 CVE-2025-11008 Wordfence
9.8 Critical CE21 Suite Plugin ce21-suite Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Plugin Settings Update No login needed 2.2.1 – 2.3.1 CVE-2025-11007 Wordfence
9.8 Critical Doccure Core Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed < 1.5.4 Fixed in 1.5.4 CVE-2025-8900 Wordfence
9.8 Critical Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Plugin tablesome Arbitrary File Upload Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.1.32 CVE-2025-11499 Wordfence
9.8 Critical Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App Plugin post-smtp Broken Access Control Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure No login needed ≤ 3.6.0 CVE-2025-11833 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only