WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 133 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control Missing Authorization to Unauthenticated Business Information Export No login needed ≤ 3.3.11 CVE-2025-13414 Wordfence
6.5 Medium Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update No login needed ≤ 8.5.2 CVE-2025-12174 Wordfence
5.4 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Arbitrary Shortcode Execution Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description ≤ 5.0.3 CVE-2025-7711 Wordfence
4.3 Medium GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory Broken Access Control WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment ≤ 2.8.139 CVE-2025-12833 Wordfence
4.3 Medium Classified Listing – AI-Powered Classified ads & Business Directory Plugin classified-listing Broken Access Control AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering ≤ 5.2.0 CVE-2025-12953 Wordfence
4.3 Medium Business Directory Plugin business-directory-plugin Broken Access Control ≤ 6.4.18 Fixed in 6.4.19 CVE-2025-64219 Patchstack
7.1 High WP Business Hours Plugin wp-business-hours Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62934 Patchstack
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Remote Code Execution Authenticated (Subscriber+) Arbitrary File Move ≤ 8.4.8 CVE-2025-10488 Wordfence
6.4 Medium Simple Business Data Plugin simple-business-data Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2025-11870 Wordfence
6.4 Medium CM Business Directory Plugin cm-business-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.2 CVE-2025-10178 Wordfence
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via claim_business No login needed ≤ 6.0 CVE-2025-5948 Wordfence
7.1 High Simple Business Directory Pro Plugin simple-business-directory-pro Cross-Site Scripting No login needed ≤ 15.5.1 Fixed in 15.5.2 CVE-2025-48162 Patchstack
7.5 High Maya Business Plugin paymaya-checkout-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-53208 Patchstack
8.1 High Widget for Google Reviews Plugin business-reviews-wp Local File Inclusion No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-53565 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-53580 Patchstack
6.4 Medium BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites Plugin blockspare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets ≤ 3.2.13.1 CVE-2025-4684 Wordfence
7.5 High GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory SQL Injection WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection No login needed ≤ 2.8.97 CVE-2024-13507 Wordfence
6.4 Medium Structured Content Plugin structured-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode ≤ 1.6.4 CVE-2025-4608 Wordfence
9.3 Critical WP-BusinessDirectory Plugin wp-businessdirectory SQL Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-24759 Patchstack
7.1 High Ofiz - WordPress Business Consulting Plugin ofiz Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31072 Patchstack
7.1 High Invico - WordPress Consulting Business Plugin invico Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-31427 Patchstack
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets ≤ 6.1.19 CVE-2025-6244 Wordfence
5.3 Medium CRM ERP Business Solution Plugin crm-erp-business-solution Broken Access Control No login needed ≤ 1.13 CVE-2025-49987 Patchstack
9.8 Critical FLAP - Business Theme flap PHP Object Injection Business WordPress Theme <= 1.5 - PHP Object Injection No login needed ≤ 1.5 CVE-2025-31396 Patchstack
8.1 High Vizeon - Business Consulting Plugin vizeon Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.2.1 CVE-2025-31064 Patchstack
9.8 Critical HotStar – Multi-Purpose Business Theme hotstar PHP Object Injection Multi-Purpose Business Theme <= 1.4 - PHP Object Injection No login needed ≤ 1.4 CVE-2025-31069 Patchstack
9.8 Critical The Business Theme nrgbusiness PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-31430 Patchstack
8.1 High Enzio - Responsive Business Plugin enzio Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-31912 Patchstack
8.1 High Kiamo - Responsive Business Service Theme kiamo Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-31633 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-31918 Patchstack
5.3 Medium The Business Theme nrgbusiness Broken Access Control No login needed ≤ 1.6.1 CVE-2025-31630 Patchstack
5.3 Medium HotStar – Multi-Purpose Business Theme hotstar Broken Access Control Multi-Purpose Business Theme <= 1.4 - Broken Access Control No login needed ≤ 1.4 CVE-2025-31071 Patchstack
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
5.9 Medium Business Contact Widget Plugin business-contact-widget Cross-Site Scripting ≤ 2.7.0 CVE-2025-46529 Patchstack
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32630 Patchstack
8.6 High WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Deletion No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32629 Patchstack
6.5 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Cross-Site Scripting ≤ 3.3.11 CVE-2025-32162 Patchstack
7.5 High Apptivo Business Site CRM Plugin apptivo-business-site Broken Access Control Arbitrary Content Deletion No login needed ≤ 5.3 Fixed in 5.4 CVE-2025-31909 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
5.3 Medium Business Directory Plugin - Easy Listing Directories Plugin business-directory-plugin Broken Access Control Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image Addition No login needed ≤ 6.4.14 CVE-2024-13887 Wordfence
6.5 Medium Listingo - Business Listing and Directory Theme Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.7 CVE-2024-13815 Wordfence
6.4 Medium Structured Content (JSON-LD) #wpsc Plugin structured-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode ≤ 1.6.3 CVE-2025-0512 Wordfence
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Privilege Escalation Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 8.1 CVE-2025-1570 Wordfence
6.5 Medium Business Card Block Plugin business-card-block Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-26952 Patchstack
5.3 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Information Disclosure Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure No login needed ≤ 4.0.4 CVE-2025-1063 Wordfence
4.3 Medium Apptivo Business Site CRM Plugin apptivo-business-site Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed ≤ 5.3 CVE-2024-13405 Wordfence
6.4 Medium GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory Cross-Site Scripting WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display_name Parameter ≤ 2.8.97 CVE-2024-13506 Wordfence
5.3 Medium Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings Plugin directorist Information Disclosure AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure No login needed ≤ 8.0.12 CVE-2024-12041 Wordfence
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-13057 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13056 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only