WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,001–1,050 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token() No login needed ≤ 6.26.12 CVE-2025-9485 Wordfence
9.8 Critical JoomSport Plugin joomsport-sports-league-results-management Path Traversal Unauthenticated Directory Traversal to Local File Inclusion No login needed ≤ 5.7.3 CVE-2025-7721 Wordfence
9.8 Critical Appy Pie Connect for WooCommerce Plugin appy-pie-connect-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password No login needed ≤ 1.1.2 CVE-2025-9286 Wordfence
9.8 Critical RestroPress – Online Food Ordering System Plugin restropress Information Disclosure Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT No login needed 3.0.0 – 3.1.9.2 CVE-2025-9209 Wordfence
9.1 Critical WPRecovery Plugin wprecovery SQL Injection Unauthenticated SQL Injection to Arbitrary File Deletion No login needed ≤ 2.0 CVE-2025-10726 Wordfence
9.8 Critical Spirit Framework Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 1.2.14 CVE-2025-6388 Wordfence
9.8 Critical Ajax WooSearch Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.0 CVE-2025-9697 WPScan
9.1 Critical Custom Searchable Data Entry System Plugin Broken Access Control Unauthenticated Database Wiping No login needed ≤ 1.7.1 CVE-2020-36852 Wordfence
9.8 Critical Post By Email Plugin post-by-email Arbitrary File Upload Unauthenticated Arbitrary File Upload via Email Attachments No login needed ≤ 1.0.4b CVE-2025-9762 Wordfence
9.8 Critical Copypress Rest API Plugin copypress-rest-api Remote Code Execution Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution No login needed 1.1 – 1.2 CVE-2025-8625 Wordfence
10.0 Critical WooCommerce Designer Pro Plugin wc-designer-pro Arbitrary File Upload No login needed ≤ 1.9.24 CVE-2025-60219 Patchstack
9.6 Critical AR Plugin ar-for-wordpress Cross-Site Request Forgery No login needed ≤ 8.34 CVE-2025-60156 Patchstack
9.8 Critical MultiLoca - WooCommerce Multi Locations Inventory Management Plugin Broken Access Control WooCommerce Multi Locations Inventory Management <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Options Update via 'wcmlim_settings_ajax_handler' No login needed ≤ 4.2.8 CVE-2025-9054 Wordfence
9.8 Critical Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) Plugin Arbitrary File Upload Uni CPO (Premium) <= 4.9.55 - Unauthenticated Arbitrary File Upload via 'uni_cpo_upload_file' No login needed ≤ 4.9.55 CVE-2025-10412 Wordfence
9.8 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.2.6 CVE-2025-10147 Wordfence
9.8 Critical WPCasa Plugin wpcasa Remote Code Execution Unauthenticated Code Injection No login needed ≤ 1.4.1 CVE-2025-9321 Wordfence
9.6 Critical Custom Post Type Images Plugin custom-post-types-image Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-58255 Patchstack
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via claim_business No login needed ≤ 6.0 CVE-2025-5948 Wordfence
9.8 Critical Goza - Nonprofit Charity Theme Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed ≤ 3.2.2 CVE-2025-10690 Wordfence
9.8 Critical Ninja-forms Plugin PHP Object Injection Unauthenticated PHP Objection No login needed < 3.11.1 Fixed in 3.11.1 CVE-2025-9083 WPScan
9.1 Critical WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Subscriber+ Rating Manipulation No login needed < 2.2.3 Fixed in 2.2.3 CVE-2025-8942 WPScan
9.8 Critical Password Reset with Code Plugin bdvs-password-reset Privilege Escalation Insecure Password Reset Code Creation No login needed < 0.0.17 Fixed in 0.0.17 CVE-2025-5305 WPScan
9.8 Critical BeyondCart Connector Plugin beyondcart Privilege Escalation Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter No login needed ≤ 3.0.1 CVE-2025-8570 Wordfence
9.6 Critical Mow Plugin mow Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-58997 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-32486 Patchstack
9.3 Critical WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card SQL Injection No login needed ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-47569 Patchstack
9.0 Critical Photography Plugin photography PHP Object Injection No login needed ≤ 7.7.2 CVE-2025-47579 Patchstack
9.1 Critical Goza - Nonprofit Charity Theme Broken Access Control Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed 3.2.2 CVE-2025-10134 Wordfence
9.8 Critical Doccure Theme Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 1.5.0 CVE-2025-9114 Wordfence
9.8 Critical Doccure Core Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.5.3 CVE-2025-9113 Wordfence
9.8 Critical AdForest Theme Authentication Bypass Authentication Bypass to Admin No login needed ≤ 6.0.9 CVE-2025-8359 Wordfence
9.3 Critical Miraculous Plugin miraculous SQL Injection No login needed ≤ 2.0.9 CVE-2025-58628 Patchstack
9.8 Critical smart SEO Theme smartseo Privilege Escalation No login needed ≤ 4.0 CVE-2025-49401 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-58819 Patchstack
9.8 Critical RealHomes Plugin realhomes Privilege Escalation No login needed ≤ 4.3.6 Fixed in 4.3.7 CVE-2024-32444 Patchstack
9.9 Critical School Management Plugin school-management Arbitrary File Upload ≤ 1.93.1 (02-07-2025) CVE-2025-31100 Patchstack
9.8 Critical Login with phone number Plugin login-with-phone-number Broken Access Control No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-32832 Patchstack
9.8 Critical Jobmonster Theme noo-jobmonster Authentication Bypass Broken Authentication No login needed ≤ 4.7.9 Fixed in 4.8.0 CVE-2025-54738 Patchstack
9.8 Critical Golo Plugin golo Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-54725 Patchstack
9.3 Critical Nest Addons Plugin nest-addons SQL Injection No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-54720 Patchstack
9.8 Critical WP Funnel Manager Plugin wp-funnel-manager PHP Object Injection No login needed ≤ 1.4.0 CVE-2025-52761 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Privilege Escalation No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-49388 Patchstack
10.0 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-49387 Patchstack
9.1 Critical bidorbuy Store Integrator Plugin bidorbuystoreintegrator Remote Code Execution ≤ 2.12.0 CVE-2025-48100 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed < 2.9.6 Fixed in 2.9.6 CVE-2025-39496 Patchstack
9.8 Critical RingCentral Communications Plugin rccp-free Authentication Bypass Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function No login needed 1.5 – 1.6.8 CVE-2025-7955 Wordfence
9.8 Critical Case Theme User Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 1.0.3 CVE-2025-5821 Wordfence
9.8 Critical Simpler Checkout Plugin simpler-checkout Authentication Bypass No login needed 0.7.0 – 1.1.9 CVE-2025-7642 Wordfence
9.9 Critical Pin WP Theme pin-wp Arbitrary File Upload ≤ 7.2 Fixed in 7.2 CVE-2025-53251 Patchstack
9.8 Critical WP Webhooks Plugin wp-webhooks Path Traversal Unauthenticated Arbitrary File Copy No login needed ≤ 3.3.5 CVE-2025-8895 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only