WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,051–1,100 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.6 Critical ads.txt Guru Connect Plugin adstxt-guru-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-49381 Patchstack
9.8 Critical WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting No login needed ≤ 8.2 Fixed in 8.3 CVE-2025-49400 Patchstack
10.0 Critical Templately Plugin templately Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2025-49408 Patchstack
9.8 Critical SensorPress Plugin sensorpress-uptime-monitoring Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49409 Patchstack
10.0 Critical TC Testimonials Plugin tc-testimonial Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2025-49410 Patchstack
9.8 Critical Support Ticket Plugin support-ticket Privilege Escalation No login needed ≤ 1.9 CVE-2025-49422 Patchstack
9.8 Critical Cars4Rent Theme cars4rent PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-49434 Patchstack
9.8 Critical Organic Beauty Theme organic-beauty PHP Object Injection No login needed ≤ 1.4.6 CVE-2025-49890 Patchstack
10.0 Critical StoreKeeper for WooCommerce Plugin storekeeper-for-woocommerce Arbitrary File Upload No login needed ≤ 14.4.4 Fixed in 14.4.5 CVE-2025-48148 Patchstack
9.9 Critical Code Engine Plugin code-engine Remote Code Execution ≤ 0.3.3 Fixed in 0.3.4 CVE-2025-48169 Patchstack
9.9 Critical ReachShip WooCommerce Multi-Carrier & Conditional Shipping Plugin elex-reachship-multi-carrier-conditional-shipping Arbitrary File Upload ≤ 4.3.1 Fixed in 4.3.2 CVE-2025-53213 Patchstack
9.8 Critical ThemeMakers Visual Content Composer Plugin tmm_content_composer PHP Object Injection No login needed ≤ 1.5.8 CVE-2025-53299 Patchstack
10.0 Critical Global DNS Plugin global-dns Remote Code Execution No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-53577 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-53580 Patchstack
9.8 Critical MediCenter - Health Medical Clinic Plugin medicenter PHP Object Injection Health Medical Clinic <= 15.1 - PHP Object Injection No login needed ≤ 15.1 Fixed in 15.2 CVE-2025-54014 Patchstack
9.3 Critical Custom API for WP Plugin custom-api-for-wp SQL Injection No login needed ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54048 Patchstack
9.9 Critical Custom API for WP Plugin custom-api-for-wp Privilege Escalation ≤ 4.2.2 Fixed in 4.2.3 CVE-2025-54049 Patchstack
9.1 Critical Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Arbitrary File Upload ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54677 Patchstack
9.3 Critical JS Archive List Plugin jquery-archive-list-widget SQL Injection No login needed ≤ 6.1.6 Fixed in 6.1.6 CVE-2025-54726 Patchstack
9.8 Critical Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-54713 Patchstack
9.8 Critical Cloudflare Image Resizing Plugin cf-image-resizing Remote Code Execution Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook No login needed ≤ 1.5.6 CVE-2025-8723 Wordfence
9.8 Critical Real Spaces - WordPress Properties Directory Theme Privilege Escalation WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register' No login needed ≤ 3.6 CVE-2025-6758 Wordfence
9.8 Critical Taxi Booking Manager for Woocommerce | E-cab Plugin ecab-taxi-booking-manager Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.3.0 CVE-2025-8898 Wordfence
9.8 Critical StoryChief Plugin story-chief Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.42 CVE-2025-7441 Wordfence
9.8 Critical Icons Factory Plugin icons-factory Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Deletion via delete_files() Function No login needed ≤ 1.6.12 CVE-2025-7778 Wordfence
9.8 Critical Contact Form by Bit Form - Bit Form Plugin bit-form Arbitrary File Upload Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload No login needed ≤ 2.20.3 CVE-2025-6679 Wordfence
9.3 Critical MDTF Plugin wp-meta-data-filter-and-taxonomy-filter SQL Injection No login needed ≤ 1.3.3.7 Fixed in 1.3.3.8 CVE-2025-54707 Patchstack
9.0 Critical Form Block Plugin form-block Arbitrary File Upload No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-54693 Patchstack
9.8 Critical Exertio Plugin exertio PHP Object Injection No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-54686 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 3.8.15 Fixed in 3.8.16 CVE-2025-54678 Patchstack
9.3 Critical MapSVG Plugin mapsvg SQL Injection No login needed ≤ 8.7.4 Fixed in 8.7.4 CVE-2025-54669 Patchstack
9.9 Critical Forms Plugin forms-by-made-it Arbitrary File Upload ≤ 2.9.0 CVE-2025-24775 Patchstack
10.0 Critical BeeTeam368 Extensions Plugin beeteam368-extensions Local File Inclusion No login needed ≤ 1.9.4 CVE-2025-25174 Patchstack
9.8 Critical Geo Mashup Plugin geo-mashup Local File Inclusion No login needed ≤ 1.13.16 Fixed in 1.13.17 CVE-2025-48293 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.20 Fixed in 1.5.21 CVE-2025-49059 Patchstack
9.9 Critical Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Remote Code Execution ≤ 2.9.3 Fixed in 2.9.4 CVE-2025-49887 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.5 Fixed in 7.6 CVE-2025-52720 Patchstack
9.8 Critical Multiple Plugins from itayamar Plugin Other Supply Chain Compromise No login needed ≤ 1.2, ≤ 1.0 CVE-2025-8047 WPScan
9.8 Critical Latepoint Plugin Local File Inclusion Unauthenticated LFI No login needed < 5.1.94 Fixed in 5.1.94 CVE-2025-6715 WPScan
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-7384 Wordfence
9.8 Critical B Blocks Plugin b-blocks Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via rgfr_registration Function No login needed ≤ 2.0.6 CVE-2025-8059 Wordfence
9.8 Critical Reveal Listing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.3 CVE-2025-6994 Wordfence
9.3 Critical WordPress Plugin wp-property Arbitrary File Upload WordPress Plugin WP-Property <= 1.35.0 PHP File Upload No login needed ≤ 1.35.0 CVE-2012-10027 VulnCheck
10.0 Critical asset-manager Plugin asset-manager Arbitrary File Upload WordPress Plugin Asset-Manager <= 2.0 PHP File Upload No login needed ≤ 2.0 CVE-2012-10026 VulnCheck
10.0 Critical WordPress Plugin advanced-custom-fields Local File Inclusion WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion No login needed ≤ 3.5.1 CVE-2012-10025 VulnCheck
9.8 Critical Brave Conversion Engine (PRO) Plugin Authentication Bypass Authentication Bypass to Administrator No login needed ≤ 0.7.7 CVE-2025-7710 Wordfence
9.8 Critical Service Finder Bookings Plugin Authentication Bypass Authentication Bypass via User Switch Cookie No login needed ≤ 6.0 CVE-2025-5947 Wordfence
9.8 Critical Service Finder SMS System Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0.0 CVE-2025-5954 Wordfence
9.8 Critical MelaPress Login Security Plugin melapress-login-security Authentication Bypass Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function No login needed 2.1.0 – 2.1.1 CVE-2025-6895 Wordfence
9.8 Critical WP Database Backup Plugin wp-database-backup Remote Code Execution Unauthenticated OS Command Injection No login needed < 5.2 Fixed in 5.2 CVE-2019-25224 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only