WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 951–1,000 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor Plugin king-addons Privilege Escalation Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation No login needed ≤ 51.1.14 CVE-2025-8489 Wordfence
9.8 Critical Jobmonster - Job Board Theme Authentication Bypass Job Board WordPress Theme <= 4.8.1 - Authentication Bypass No login needed ≤ 4.8.1 CVE-2025-5397 Wordfence
9.6 Critical CFDB7 Plugin contact-form-cfdb7 SQL Injection WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization… No login needed 0.0.0 – 1.3.2 Fixed in 1.3.3 CVE-2025-4665 Mandiant
9.1 Critical Paid Videochat Turnkey Site Plugin ppv-live-webcams Remote Code Execution ≤ 7.3.23 Fixed in 7.3.24 CVE-2025-62959 Patchstack
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.26 CVE-2025-6440 Wordfence
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-62025 Patchstack
9.0 Critical s2Member Plugin s2member Remote Code Execution No login needed ≤ 250905 Fixed in 251005 CVE-2025-62023 Patchstack
9.8 Critical UNIVERSAM Plugin universam-demo PHP Object Injection No login needed ≤ 9.04.02 CVE-2025-60238 Patchstack
9.8 Critical KBx Pro Ultimate Plugin knowledgebase-helpdesk-pro PHP Object Injection No login needed ≤ 8.0.5 CVE-2025-60232 Patchstack
9.8 Critical White Rabbit Theme whiterabbit PHP Object Injection No login needed ≤ 1.5.2 CVE-2025-60226 Patchstack
9.8 Critical BugsPatrol Theme bugspatrol PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60225 Patchstack
9.8 Critical Subscribe to Download Plugin subscribe-to-download PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60224 Patchstack
9.8 Critical Captivate Sync Plugin captivatesync-trade PHP Object Injection No login needed ≤ 3.0.3 Fixed in 3.2.2 CVE-2025-60221 Patchstack
9.8 Critical CouponXxL Plugin couponxxl Privilege Escalation No login needed ≤ 3.0.0 CVE-2025-60220 Patchstack
9.8 Critical Addison Plugin addison PHP Object Injection No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2025-60216 Patchstack
9.8 Critical Goldenblatt Plugin goldenblatt PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.0 CVE-2025-60214 Patchstack
9.8 Critical Scape Plugin scape PHP Object Injection No login needed ≤ 1.5.13 CVE-2025-60213 Patchstack
9.8 Critical Everest Forms - Frontend Listing Plugin everest-forms-frontend-listing PHP Object Injection Frontend Listing plugin <= 1.0.5 - PHP Object Injection No login needed ≤ 1.0.5 CVE-2025-60210 Patchstack
9.8 Critical Connector for Gravity Forms and Google Sheets Plugin wp-gravity-forms-spreadsheets PHP Object Injection No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-60209 Patchstack
10.0 Critical Alone Plugin alone Remote Code Execution No login needed ≤ 7.8.3 CVE-2025-60206 Patchstack
9.8 Critical Noisa Plugin noisa PHP Object Injection No login needed ≤ 2.6.0 Fixed in 2.6.3 CVE-2025-60039 Patchstack
9.3 Critical Learts Addons Plugin learts-addons SQL Injection No login needed ≤ 1.7.5 Fixed in 1.7.5 CVE-2025-59557 Patchstack
9.8 Critical TF Woo Product Grid Addon For Elementor Plugin tf-woo-product-grid PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.0.1 CVE-2025-59007 Patchstack
10.0 Critical Medcity Plugin medcity Arbitrary File Upload No login needed ≤ 1.1.9 Fixed in 1.1.9 CVE-2025-58963 Patchstack
9.1 Critical Zippy Plugin zippy Arbitrary File Upload ≤ 1.7.0 CVE-2025-52758 Patchstack
9.3 Critical JetSearch Plugin jet-search SQL Injection No login needed ≤ 3.5.10 Fixed in 3.5.10.1 CVE-2025-49931 Patchstack
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection No login needed ≤ 3.8.5 Fixed in 3.8.6 CVE-2025-49915 Patchstack
9.8 Critical Simple Link Directory Plugin qc-simple-link-directory Authentication Bypass Broken Authentication No login needed ≤ 14.8.1 Fixed in 14.8.1 CVE-2025-49901 Patchstack
9.8 Critical WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder PHP Object Injection No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49380 Patchstack
10.0 Critical Wastia Plugin wastia Arbitrary File Upload No login needed ≤ 1.1.3 Fixed in 1.1.3 CVE-2025-49060 Patchstack
10.0 Critical Clanora Theme clanora Arbitrary File Upload No login needed ≤ 1.3.1 Fixed in 1.3.1 CVE-2025-48106 Patchstack
9.1 Critical FormGent Plugin formgent Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed < 1.0.4 Fixed in 1.0.4 CVE-2025-10916 WPScan
9.8 Critical PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Upload No login needed ≤ 33.0.15 CVE-2025-11391 Wordfence
9.8 Critical RegistrationMagic - Custom Registration Forms Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection Custom Registration Forms <= 3.7.9.2 - PHP Object Injection No login needed < 3.7.9.3 Fixed in 3.7.9.3 CVE-2017-20208 Wordfence
9.8 Critical Flickr Gallery Plugin flickr-gallery PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.5.3 Fixed in 1.5.3 CVE-2017-20207 Wordfence
9.8 Critical Appointments Plugin appointments PHP Object Injection Unauthenticated PHP Object Injection No login needed < 2.2.2 Fixed in 2.2.2 CVE-2017-20206 Wordfence
9.8 Critical Felan Framework Plugin Authentication Bypass Hardcoded Credentials No login needed ≤ 1.1.4 CVE-2025-10850 Wordfence
9.8 Critical Truelysell Core Plugin Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 1.8.6 CVE-2025-10742 Wordfence
9.8 Critical OwnID Passwordless Login Plugin ownid-passwordless-login Authentication Bypass No login needed ≤ 1.3.4 CVE-2025-10294 Wordfence
9.8 Critical Orion SMS OTP Verification Plugin orion-sms-otp-verification Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.1.7 CVE-2025-9967 Wordfence
9.8 Critical Flex QR Code Generator Plugin flex-qr-code-generator Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2.5 CVE-2025-10041 Wordfence
9.3 Critical is-human Plugin is-human Remote Code Execution WordPress Plugin is-human <= v1.4.2 Eval Injection RCE No login needed ≤ 1.4.2 CVE-2011-10033 VulnCheck
9.8 Critical WooCommerce Designer Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.9.26 CVE-2025-6439 Wordfence
9.8 Critical Ovatheme Events Manager Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.8.5 CVE-2025-6553 Wordfence
9.8 Critical WP Freeio Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.2.21 CVE-2025-11533 Wordfence
9.8 Critical Search & Go - Directory Theme Authentication Bypass Directory WordPress Theme <= 2.7 - Authentication Bypass to Privilege Escalation via Account Takeover No login needed ≤ 2.7 CVE-2025-11522 Wordfence
9.8 Critical WP Travel Engine – Tour Booking Plugin – Tour Operator Software Plugin wp-travel-engine Local File Inclusion Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion No login needed ≤ 6.6.7 CVE-2025-7634 Wordfence
9.8 Critical WP Travel Engine – Tour Booking Plugin – Tour Operator Software Plugin wp-travel-engine Arbitrary File Deletion Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming No login needed ≤ 6.6.7 CVE-2025-7526 Wordfence
9.8 Critical Community Events Plugin community-events SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.5.1 CVE-2025-10586 Wordfence
9.8 Critical Community Events Plugin community-events SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.5.1 CVE-2025-10587 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only