WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,101–1,150 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Platform Theme Broken Access Control Missing Authorization to Unauthenticated Arbitrary Options Update No login needed < 1.4.4 Fixed in 1.4.4 CVE-2015-10143 Wordfence
9.8 Critical ONLYOFFICE Docs Plugin onlyoffice Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via callback Function No login needed 1.1.0 – 2.2.0 CVE-2025-6380 Wordfence
9.8 Critical Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition Plugin webinar-ignition Authentication Bypass Unauthenticated Login Token Generation to Authentication Bypass No login needed ≤ 4.03.32 CVE-2025-6441 Wordfence
9.8 Critical Ebook Store Plugin ebook-store Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.8012 CVE-2025-7437 Wordfence
9.8 Critical WPBookit Plugin wpbookit Arbitrary File Upload Unauthenticated Arbitrary File Upload via image_upload_handle Function No login needed ≤ 1.0.6 CVE-2025-7852 Wordfence
9.8 Critical bSecure Plugin bsecure Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint No login needed 1.3.7 – 1.7.9 CVE-2025-6187 Wordfence
9.8 Critical FoxyPress Plugin Arbitrary File Upload No login needed < 0.4.2.2 Fixed in 0.4.2.2 CVE-2012-10020 Wordfence
9.8 Critical Website Contact Form With File Upload Plugin website-contact-form-with-file-upload Arbitrary File Upload No login needed ≤ 1.3.4 CVE-2015-10137 Wordfence
9.8 Critical Work The Flow File Upload Plugin Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2015-10138 Wordfence
9.8 Critical WP Mobile Detector Plugin wp-mobile-detector Arbitrary File Upload No login needed ≤ 3.5 CVE-2016-15043 Wordfence
9.8 Critical WPshop 2 – E-Commerce Plugin wpshop Arbitrary File Upload E-Commerce < 1.3.9.6 - Arbitrary File Upload No login needed < 1.3.9.6 Fixed in 1.3.9.6 CVE-2015-10135 Wordfence
9.8 Critical Front-end Editor Plugin Arbitrary File Upload No login needed < 2.3 Fixed in 2.3 CVE-2012-10019 Wordfence
9.8 Critical Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.1.1 CVE-2025-7697 Wordfence
9.8 Critical Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.2.3 CVE-2025-7696 Wordfence
9.8 Critical LoginPress Pro Plugin Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 5.0.1 CVE-2025-7444 Wordfence
9.1 Critical Attachment Manager Plugin attachment-manager Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.1.2 CVE-2025-7643 Wordfence
9.8 Critical WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet Theme Arbitrary File Upload Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.2.6 CVE-2025-6222 Wordfence
9.1 Critical Madara - Core Plugin Arbitrary File Deletion Core <= 2.2.3 - Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.3 CVE-2025-7712 Wordfence
9.8 Critical Bears Backup Plugin Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 2.0.0 CVE-2025-5396 Wordfence
9.3 Critical WP-BusinessDirectory Plugin wp-businessdirectory SQL Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2025-24759 Patchstack
9.8 Critical URL Shortener Plugin exact-links PHP Object Injection No login needed ≤ 3.0.7 CVE-2025-28961 Patchstack
9.3 Critical URL Shortener Plugin exact-links SQL Injection No login needed ≤ 3.0.7 CVE-2025-28959 Patchstack
9.3 Critical WP Pipes Plugin wp-pipes SQL Injection No login needed ≤ 1.4.3 CVE-2025-28982 Patchstack
10.0 Critical Medical Prescription Attachment Plugin for WooCommerce Plugin medical-prescription-attachment-plugin-for-woocommerce Arbitrary File Upload No login needed ≤ 1.2.3 CVE-2025-29009 Patchstack
9.8 Critical Site Chat on Telegram Plugin site-chat-on-telegram PHP Object Injection No login needed ≤ 1.0.4 Fixed in 1.0.6 CVE-2025-30949 Patchstack
9.3 Critical Torod Plugin torod SQL Injection No login needed ≤ 2.1 CVE-2025-30936 Patchstack
9.8 Critical CoSchool LMS Plugin coschool PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-30973 Patchstack
9.1 Critical Groundhogg Plugin groundhogg Arbitrary File Upload ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-48300 Patchstack
9.3 Critical Traveler Plugin traveler SQL Injection No login needed ≤ 3.2.2 Fixed in 3.2.2 CVE-2025-52714 Patchstack
9.8 Critical The E-Commerce ERP Plugin profitori Privilege Escalation No login needed ≤ 2.1.1.3 CVE-2025-52836 Patchstack
9.6 Critical FluentSnippets Plugin easy-code-manager Cross-Site Request Forgery No login needed ≤ 10.50 Fixed in 10.51 CVE-2025-54010 Patchstack
9.8 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.1 CVE-2025-7340 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Path Traversal Directory Traversal to Arbitrary File Move No login needed ≤ 2.2.1 CVE-2025-7360 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.1 CVE-2025-7341 Wordfence
9.8 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation No login needed ≤ 7.8.3 CVE-2025-5394 Wordfence
9.1 Critical Alone – Charity Multipurpose Non-profit Theme Broken Access Control Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion No login needed ≤ 7.8.5 CVE-2025-5393 Wordfence
9.8 Critical AIT CSV import/export Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.0.3 CVE-2020-36849 Wordfence
9.8 Critical Simple File List Plugin simple-file-list Remote Code Execution No login needed < 4.2.3 Fixed in 4.2.3 CVE-2020-36847 Wordfence
9.8 Critical WPBookit Plugin wpbookit Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2025-6058 Wordfence
9.8 Critical GB Forms DB Plugin gb-forms-db Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 1.0.2 CVE-2025-5392 Wordfence
9.8 Critical Premium Age Verification / Restriction Plugin Path Traversal Unauthenticated Arbitrary File Read and Write via remote_tunnel.php No login needed ≤ 3.0.2 CVE-2025-7401 Wordfence
9.8 Critical Sala - Startup & SaaS Theme Privilege Escalation Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 1.1.4 CVE-2025-4606 Wordfence
10.0 Critical Pie Register Plugin pie-register Authentication Bypass WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE No login needed ≤ 3.7.1.4 CVE-2025-34077 VulnCheck
9.8 Critical Support Board Plugin Broken Access Control Unauthenticated Authorization Bypass due to Use of Default Secret Key No login needed ≤ 3.8.0 CVE-2025-4855 Wordfence
9.8 Critical Support Board Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.8.0 CVE-2025-4828 Wordfence
9.8 Critical Service Finder Booking Plugin sf-booking Privilege Escalation No login needed ≤ 6.1 CVE-2025-23970 Patchstack
9.8 Critical Click & Pledge Connect Plugin click-pledge-connect Privilege Escalation Privilege Escalation via SQL Injection No login needed 25.04010101 – WP6.8 CVE-2025-28983 Patchstack
10.0 Critical LogisticsHub Plugin logistics-hub Arbitrary File Upload No login needed ≤ 1.1.6 CVE-2025-30933 Patchstack
10.0 Critical Easy Stripe Plugin easy-stripe Remote Code Execution No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-49302 Patchstack
9.8 Critical RealHomes Plugin realhomes Privilege Escalation No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-49867 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only