WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1,001–1,050 of 2,168 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | OAuth Single Sign On – SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token() No login needed |
≤ 6.26.12 |
CVE-2025-9485 |
Wordfence | |
| 9.8 Critical | JoomSport | Path Traversal Unauthenticated Directory Traversal to Local File Inclusion No login needed |
≤ 5.7.3 |
CVE-2025-7721 |
Wordfence | |
| 9.8 Critical | Appy Pie Connect for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password No login needed |
≤ 1.1.2 |
CVE-2025-9286 |
Wordfence | |
| 9.8 Critical | RestroPress – Online Food Ordering System | Information Disclosure Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT No login needed |
3.0.0 – 3.1.9.2 |
CVE-2025-9209 |
Wordfence | |
| 9.1 Critical | WPRecovery | SQL Injection Unauthenticated SQL Injection to Arbitrary File Deletion No login needed |
≤ 2.0 |
CVE-2025-10726 |
Wordfence | |
| 9.8 Critical | Spirit Framework | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 1.2.14 |
CVE-2025-6388 |
Wordfence | |
| 9.8 Critical | Ajax WooSearch | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.0.0 |
CVE-2025-9697 |
WPScan | |
| 9.1 Critical | Custom Searchable Data Entry System | Broken Access Control Unauthenticated Database Wiping No login needed |
≤ 1.7.1 |
CVE-2020-36852 |
Wordfence | |
| 9.8 Critical | Post By Email | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Email Attachments No login needed |
≤ 1.0.4b |
CVE-2025-9762 |
Wordfence | |
| 9.8 Critical | Copypress Rest API | Remote Code Execution Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution No login needed |
1.1 – 1.2 |
CVE-2025-8625 |
Wordfence | |
| 10.0 Critical | WooCommerce Designer Pro | Arbitrary File Upload No login needed |
≤ 1.9.24 |
CVE-2025-60219 |
Patchstack | |
| 9.6 Critical | AR | Cross-Site Request Forgery No login needed |
≤ 8.34 |
CVE-2025-60156 |
Patchstack | |
| 9.8 Critical | MultiLoca - WooCommerce Multi Locations Inventory Management | Broken Access Control WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' No login needed |
≤ 4.2.8 |
CVE-2025-9054 |
Wordfence | |
| 9.8 Critical | Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) | Arbitrary File Upload Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' No login needed |
≤ 4.9.55 |
CVE-2025-10412 |
Wordfence | |
| 9.8 Critical | Podlove Podcast Publisher | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 4.2.6 |
CVE-2025-10147 |
Wordfence | |
| 9.8 Critical | WPCasa | Remote Code Execution Unauthenticated Code Injection No login needed |
≤ 1.4.1 |
CVE-2025-9321 |
Wordfence | |
| 9.6 Critical | Custom Post Type Images | Cross-Site Request Forgery No login needed |
≤ 0.5 |
CVE-2025-58255 |
Patchstack | |
| 9.8 Critical | Service Finder Bookings | Privilege Escalation Unauthenticated Privilege Escalation via claim_business No login needed |
≤ 6.0 |
CVE-2025-5948 |
Wordfence | |
| 9.8 Critical | Goza - Nonprofit Charity | Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed |
≤ 3.2.2 |
CVE-2025-10690 |
Wordfence | |
| 9.8 Critical | Ninja-forms | PHP Object Injection Unauthenticated PHP Objection No login needed |
< 3.11.1 Fixed in 3.11.1 |
CVE-2025-9083 |
WPScan | |
| 9.1 Critical | WP Hotel Booking | Broken Access Control Subscriber+ Rating Manipulation No login needed |
< 2.2.3 Fixed in 2.2.3 |
CVE-2025-8942 |
WPScan | |
| 9.8 Critical | Password Reset with Code | Privilege Escalation Insecure Password Reset Code Creation No login needed |
< 0.0.17 Fixed in 0.0.17 |
CVE-2025-5305 |
WPScan | |
| 9.8 Critical | BeyondCart Connector | Privilege Escalation Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter No login needed |
≤ 3.0.1 |
CVE-2025-8570 |
Wordfence | |
| 9.6 Critical | Mow | Cross-Site Request Forgery No login needed |
≤ 4.10 Fixed in 4.11 |
CVE-2025-58997 |
Patchstack | |
| 9.8 Critical | Material Dashboard | Privilege Escalation No login needed |
≤ 1.4.6 Fixed in 1.4.7 |
CVE-2025-32486 |
Patchstack | |
| 9.3 Critical | WooCommerce Ultimate Gift Card | SQL Injection No login needed |
≤ 2.9.6 Fixed in 2.9.7 |
CVE-2025-47569 |
Patchstack | |
| 9.0 Critical | Photography | PHP Object Injection No login needed |
≤ 7.7.2 |
CVE-2025-47579 |
Patchstack | |
| 9.1 Critical | Goza - Nonprofit Charity | Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed |
3.2.2 |
CVE-2025-10134 |
Wordfence | |
| 9.8 Critical | Doccure | Broken Access Control Unauthenticated Arbitrary User Password Change No login needed |
≤ 1.5.0 |
CVE-2025-9114 |
Wordfence | |
| 9.8 Critical | Doccure Core | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.5.3 |
CVE-2025-9113 |
Wordfence | |
| 9.8 Critical | AdForest | Authentication Bypass Authentication Bypass to Admin No login needed |
≤ 6.0.9 |
CVE-2025-8359 |
Wordfence | |
| 9.3 Critical | Miraculous | SQL Injection No login needed |
≤ 2.0.9 |
CVE-2025-58628 |
Patchstack | |
| 9.8 Critical | smart SEO | Privilege Escalation No login needed |
≤ 4.0 |
CVE-2025-49401 |
Patchstack | |
| 9.1 Critical | Bulk Featured Image | Arbitrary File Upload |
≤ 1.2.4 |
CVE-2025-58819 |
Patchstack | |
| 9.8 Critical | RealHomes | Privilege Escalation No login needed |
≤ 4.3.6 Fixed in 4.3.7 |
CVE-2024-32444 |
Patchstack | |
| 9.9 Critical | School Management | Arbitrary File Upload |
≤ 1.93.1 (02-07-2025) |
CVE-2025-31100 |
Patchstack | |
| 9.8 Critical | Login with phone number | Broken Access Control No login needed |
≤ 1.6.93 Fixed in 1.6.94 |
CVE-2024-32832 |
Patchstack | |
| 9.8 Critical | Jobmonster | Authentication Bypass Broken Authentication No login needed |
≤ 4.7.9 Fixed in 4.8.0 |
CVE-2025-54738 |
Patchstack | |
| 9.8 Critical | Golo | Authentication Bypass Broken Authentication No login needed |
≤ 1.7.0 Fixed in 1.7.1 |
CVE-2025-54725 |
Patchstack | |
| 9.3 Critical | Nest Addons | SQL Injection No login needed |
≤ 1.6.3 Fixed in 1.6.4 |
CVE-2025-54720 |
Patchstack | |
| 9.8 Critical | WP Funnel Manager | PHP Object Injection No login needed |
≤ 1.4.0 |
CVE-2025-52761 |
Patchstack | |
| 9.8 Critical | Miraculous Core | Privilege Escalation No login needed |
≤ 2.0.7 Fixed in 2.0.8 |
CVE-2025-49388 |
Patchstack | |
| 10.0 Critical | Drag and Drop File Upload for Elementor Forms | Arbitrary File Upload No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2025-49387 |
Patchstack | |
| 9.1 Critical | bidorbuy Store Integrator | Remote Code Execution |
≤ 2.12.0 |
CVE-2025-48100 |
Patchstack | |
| 9.3 Critical | WooBeWoo Product Filter Pro | SQL Injection No login needed |
< 2.9.6 Fixed in 2.9.6 |
CVE-2025-39496 |
Patchstack | |
| 9.8 Critical | RingCentral Communications | Authentication Bypass Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function No login needed |
1.5 – 1.6.8 |
CVE-2025-7955 |
Wordfence | |
| 9.8 Critical | Case Theme User | Authentication Bypass Authentication Bypass via Social Login No login needed |
≤ 1.0.3 |
CVE-2025-5821 |
Wordfence | |
| 9.8 Critical | Simpler Checkout | Authentication Bypass No login needed |
0.7.0 – 1.1.9 |
CVE-2025-7642 |
Wordfence | |
| 9.9 Critical | Pin WP | Arbitrary File Upload |
≤ 7.2 Fixed in 7.2 |
CVE-2025-53251 |
Patchstack | |
| 9.8 Critical | WP Webhooks | Path Traversal Unauthenticated Arbitrary File Copy No login needed |
≤ 3.3.5 |
CVE-2025-8895 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.