WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,151–1,200 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Video List Manager Plugin video-list-manager SQL Injection No login needed ≤ 1.7 CVE-2025-52831 Patchstack
9.3 Critical bSecure – Your Universal Checkout Plugin bsecure SQL Injection Your Universal Checkout plugin <= 1.7.9 - SQL Injection No login needed ≤ 1.7.9 CVE-2025-52830 Patchstack
9.3 Critical LMS Plugin lms SQL Injection No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52833 Patchstack
9.3 Critical NGG Smart Image Search Plugin ngg-smart-image-search SQL Injection No login needed ≤ 3.4.1 Fixed in 3.4.3 CVE-2025-52832 Patchstack
9.8 Critical WooCommerce Product Multi-Action Plugin woo-product-multiaction PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3 CVE-2025-49417 Patchstack
10.0 Critical FW Gallery Plugin fw-gallery Arbitrary File Upload No login needed ≤ 8.0.0 CVE-2025-49414 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-28951 Patchstack
9.1 Critical AiBud WP Plugin aibuddy-openai-chatgpt Arbitrary File Upload ≤ 1.9 CVE-2025-23968 Patchstack
9.8 Critical Education Center | LMS & Online Courses Theme PHP Object Injection No login needed ≤ 3.6.10 CVE-2024-13786 Wordfence
9.8 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin Arbitrary File Upload WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.1, 5.0 – 5.0.5 CVE-2025-5746 Wordfence
9.8 Critical Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin Local File Inclusion Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion to Remote Code Execution No login needed ≤ 4.89 CVE-2025-4689 Wordfence
9.1 Critical Custom Login And Signup Widget Plugin custom-login-and-signup-widget Remote Code Execution Arbitrary Code Execution ≤ 1.0 CVE-2025-49029 Patchstack
9.8 Critical Opal Estate Pro Plugin opal-estate-pro Privilege Escalation Unauthenticated Privilege Escalation via 'on_regiser_user' No login needed ≤ 1.7.5 CVE-2025-6934 Wordfence
9.8 Critical PT Project Notebooks Plugin project-notebooks Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via wpnb_pto_new_users_add Function No login needed 1.0.0 – 1.1.3 CVE-2025-5304 Wordfence
9.6 Critical WP Optimizer Plugin wp-optimizer Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2025-53314 Patchstack
9.1 Critical File Manager Plugin file-manager-plugin-for-wordpress Arbitrary File Upload ≤ 7.5 CVE-2025-53260 Patchstack
9.8 Critical WP Optimize By xTraffic Plugin wp-optimize-by-xtraffic PHP Object Injection No login needed ≤ 5.1.6 CVE-2025-28970 Patchstack
9.3 Critical Amely Theme amely SQL Injection No login needed ≤ 3.1.4 Fixed in 3.2.0 CVE-2025-39474 Patchstack
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
9.3 Critical LifterLMS Plugin lifterlms SQL Injection No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-52717 Patchstack
9.3 Critical Classiera Theme classiera SQL Injection No login needed ≤ 4.0.34 Fixed in 4.0.35 CVE-2025-52722 Patchstack
9.8 Critical CouponXxL Plugin couponxxl PHP Object Injection No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-52725 Patchstack
9.8 Critical Amwerk Theme amwerk PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-52724 Patchstack
9.3 Critical Homey Plugin homey SQL Injection No login needed ≤ 2.4.7 CVE-2025-52834 Patchstack
9.3 Critical DirectIQ Email Marketing Plugin directiq-wp SQL Injection No login needed ≤ 2.0 CVE-2025-52829 Patchstack
9.3 Critical GG Bought Together for WooCommerce Plugin gg-bought-together SQL Injection No login needed ≤ 1.0.2 CVE-2025-23967 Patchstack
9.8 Critical DWT - Directory & Listing Theme Privilege Escalation Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password Reset No login needed ≤ 3.3.6 CVE-2024-12827 Wordfence
9.8 Critical Simple Payment Plugin simple-payment Authentication Bypass Authentication Bypass to Admin No login needed 1.3.6 – 2.3.8 CVE-2025-6688 Wordfence
9.8 Critical Simple User Registration Plugin wp-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 6.3 CVE-2025-4334 Wordfence
9.8 Critical Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 3.5.3 CVE-2025-1562 Wordfence
10.0 Critical Flozen Plugin flozen-theme Arbitrary File Upload No login needed ≤ 1.5.1 Fixed in 1.5.1 CVE-2025-49071 Patchstack
9.3 Critical PostaPanduri Plugin postapanduri SQL Injection No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-49452 Patchstack
9.3 Critical WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm SQL Injection CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection No login needed ≤ 3.2.0 CVE-2025-24773 Patchstack
9.8 Critical Rapyd Payment Extension for WooCommerce Plugin rapyd-payments PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-30618 Patchstack
9.8 Critical Spare Theme spare PHP Object Injection No login needed ≤ 1.7 CVE-2025-31919 Patchstack
10.0 Critical Ovatheme Events Manager Plugin ova-events-manager Arbitrary File Upload No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-32510 Patchstack
9.3 Critical Smart Notification Plugin smio-push-notification SQL Injection No login needed ≤ 10.3 CVE-2025-39479 Patchstack
9.9 Critical WP VR Plugin wpvr Arbitrary File Upload ≤ 8.5.26 Fixed in 8.5.27 CVE-2025-47452 Patchstack
9.9 Critical MapSVG Plugin mapsvg Arbitrary File Upload ≤ 8.7.4 Fixed in 8.7.4 CVE-2025-47559 Patchstack
9.3 Critical School Management Plugin school-management SQL Injection No login needed ≤ 92.0.0 CVE-2025-47573 Patchstack
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48274 Patchstack
9.8 Critical Integration for Contact Form 7 and Zoho CRM, Bigin Plugin cf7-zoho PHP Object Injection No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-49330 Patchstack
10.0 Critical Reformer for Elementor Plugin reformer-elementor Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2025-49444 Patchstack
10.0 Critical FW Food Menu Plugin fw-food-menu Arbitrary File Upload No login needed ≤ 6.0.0 CVE-2025-49447 Patchstack
9.1 Critical Image Resizer On The Fly Plugin image-resizer-on-the-fly Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.1 CVE-2025-6065 Wordfence
9.8 Critical REST API | Custom API Generator For Cross Platform And Import Export In WP Plugin import-export-with-custom-rest-api Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via process_handler Function No login needed 1.0.0 – 2.0.3 CVE-2025-5288 Wordfence
9.8 Critical Workreap Plugin Authentication Bypass Authentication Bypass via 'workreap_verify_user_account' No login needed ≤ 3.3.1 CVE-2025-4973 Wordfence
9.3 Critical WordPress-WPJobBoard Plugin click-pledge-wpjobboard SQL Injection No login needed ≤ 25.07010000-WP6.8.1-JB5.11.5 Fixed in 25.09000000-WP6.8.2-JB5.12.0 CVE-2025-49455 Patchstack
9.8 Critical CozyStay Theme cozystay PHP Object Injection No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2025-49507 Patchstack
9.3 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai SQL Injection No login needed ≤ 3.19 Fixed in 3.21 CVE-2025-24767 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only