WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,201–1,250 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical PayU India Plugin payu-india Privilege Escalation Account Takeover No login needed ≤ 3.8.8 Fixed in 3.8.8 CVE-2025-31022 Patchstack
9.1 Critical Category Icon Plugin category-icon XML External Entity ≤ 1.0.3 CVE-2025-31039 Patchstack
9.8 Critical The Fashion - Model Agency One Page Beauty Plugin nrgfashion PHP Object Injection Model Agency One Page Beauty Theme plugin <= 1.4.4 - Deserialization of untrusted data No login needed ≤ 1.4.4 CVE-2025-31052 Patchstack
9.3 Critical WBW Product Table PRO Plugin woo-producttables-pro SQL Injection No login needed ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-31059 Patchstack
9.8 Critical PIMP - Creative MultiPurpose Theme pimp PHP Object Injection Creative MultiPurpose <= 1.7 - Deserialization of untrusted data No login needed ≤ 1.7 CVE-2025-31398 Patchstack
9.8 Critical FLAP - Business Theme flap PHP Object Injection Business WordPress Theme <= 1.5 - PHP Object Injection No login needed ≤ 1.5 CVE-2025-31396 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin leadcapture SQL Injection No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31424 Patchstack
9.8 Critical PressGrid - Frontend Publish Reaction & Multimedia Theme press-grid PHP Object Injection Frontend Publish Reaction & Multimedia Theme <= 1.3.1 - Deserialization of untrusted data No login needed ≤ 1.3.1 CVE-2025-31429 Patchstack
10.0 Critical SUMO Affiliates Pro Plugin affs Arbitrary File Upload No login needed ≤ 11.1.0 Fixed in 11.1.0 CVE-2025-32291 Patchstack
9.3 Critical Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart SQL Injection No login needed ≤ 2.5 CVE-2025-47608 Patchstack
9.3 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light SQL Injection Light plugin <= 2.4.37 - SQL Injection No login needed ≤ 2.4.37 CVE-2025-48122 Patchstack
10.0 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Remote Code Execution Light plugin <= 2.4.37 - Remote Code Execution (RCE) No login needed ≤ 2.4.37 CVE-2025-48123 Patchstack
9.8 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Privilege Escalation Light plugin <= 2.4.37 - Privilege Escalation No login needed ≤ 2.4.37 CVE-2025-48129 Patchstack
9.9 Critical MetalpriceAPI Plugin metalpriceapi Remote Code Execution ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-48140 Patchstack
9.3 Critical Multi CryptoCurrency Payments Plugin multi-crypto-currency-payment SQL Injection No login needed ≤ 2.0.7 CVE-2025-48141 Patchstack
9.3 Critical MyStyle Custom Product Designer Plugin mystyle-custom-product-designer SQL Injection No login needed ≤ 3.21.1 Fixed in 3.21.2 CVE-2025-48281 Patchstack
9.8 Critical Mr. Murphy Theme mr-murphy PHP Object Injection No login needed ≤ 1.2.12.1 Fixed in 1.2.12.1 CVE-2025-49072 Patchstack
9.8 Critical Sweet Dessert Theme sweet-dessert PHP Object Injection No login needed ≤ 1.1.13 Fixed in 1.1.13 CVE-2025-49073 Patchstack
9.0 Critical Motors - Events Plugin stm-motors-events Local File Inclusion Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.7 CVE-2025-47586 Patchstack
9.8 Critical WP Email Debug Plugin wp-email-debug Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Password Reset No login needed 1.0 – 1.1.0 CVE-2025-5486 Wordfence
9.8 Critical File Provider Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 1.2.3 CVE-2025-4578 WPScan
9.8 Critical Golo Theme Authentication Bypass Authentication Bypass to Account Takeover No login needed ≤ 1.7.0 CVE-2025-4797 Wordfence
9.8 Critical Profitori Plugin profitori Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via stocktend_object Endpoint No login needed 2.0.6.0 – 2.1.1.3 CVE-2025-4631 Wordfence
9.8 Critical PSW Front-end Login & Registration Plugin psw-login-and-registration Privilege Escalation Insufficiently Random Values to Unauthenticated Account Takeover/Privilege Escalation via customer_registration Function No login needed ≤ 1.12 CVE-2025-4607 Wordfence
9.8 Critical Course Builder Plugin course-builder PHP Object Injection No login needed ≤ 3.6.6 Fixed in 3.6.6 CVE-2025-48336 Patchstack
9.8 Critical eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Upload Unauthenticated Arbitrary File Upload via set_image() No login needed ≤ 1.2.5 CVE-2025-5058 Wordfence
9.1 Critical eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.2.5 CVE-2025-4603 Wordfence
9.8 Critical Dash Theme dash PHP Object Injection No login needed ≤ 1.3 CVE-2025-31049 Patchstack
9.3 Critical WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce Plugin whatscart-for-woocommerce SQL Injection No login needed ≤ 1.1.0 CVE-2025-31056 Patchstack
9.3 Critical Bus Ticket Booking with Seat Reservation for WooCommerce Plugin scw-bus-seat-reservation SQL Injection No login needed ≤ 1.7 CVE-2025-31397 Patchstack
9.8 Critical HotStar – Multi-Purpose Business Theme hotstar PHP Object Injection Multi-Purpose Business Theme <= 1.4 - PHP Object Injection No login needed ≤ 1.4 CVE-2025-31069 Patchstack
9.8 Critical The Business Theme nrgbusiness PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-31430 Patchstack
9.8 Critical Umberto Theme umberto PHP Object Injection No login needed ≤ 1.2.8 CVE-2025-31423 Patchstack
9.8 Critical Fish House Theme fish-house PHP Object Injection No login needed ≤ 1.2.7 CVE-2025-31631 Patchstack
9.3 Critical Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder SQL Injection No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-31914 Patchstack
9.0 Critical JP Students Result Management System Premium Plugin jp-students-result-system-premium Arbitrary File Upload No login needed 1.1.7 CVE-2025-31916 Patchstack
9.8 Critical Simple Business Directory Pro Plugin simple-business-directory-pro Privilege Escalation No login needed ≤ 15.6.9 Fixed in 15.6.9 CVE-2025-31918 Patchstack
9.8 Critical Acerola Theme acerola PHP Object Injection No login needed ≤ 1.6.5 CVE-2025-31927 Patchstack
9.8 Critical Jarvis – Night Club, Concert, Festival Theme jarvis PHP Object Injection Night Club, Concert, Festival WordPress theme <= 1.8.11 - PHP Object Injection No login needed ≤ 1.8.11 CVE-2025-32292 Patchstack
9.8 Critical Grand Tour Plugin grandtour PHP Object Injection No login needed ≤ 5.6 CVE-2025-39485 Patchstack
9.8 Critical Car Dealer Theme cardealer PHP Object Injection No login needed ≤ 1.6.8 Fixed in 1.6.8 CVE-2025-39480 Patchstack
9.8 Critical CouponXL Theme couponxl Privilege Escalation No login needed ≤ 4.5.0 Fixed in 4.5.1 CVE-2025-39489 Patchstack
9.8 Critical Medicare Plugin medicare PHP Object Injection No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-39499 Patchstack
9.8 Critical Avantage Plugin avantage PHP Object Injection No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-39495 Patchstack
9.3 Critical Goodlayers Hostel Plugin gdlr-hostel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39501 Patchstack
9.8 Critical Goodlayers Hostel Plugin gdlr-hostel PHP Object Injection No login needed ≤ 3.1.2 CVE-2025-39500 Patchstack
9.8 Critical Goodlayers Hotel Plugin gdlr-hotel PHP Object Injection No login needed ≤ 3.1.4 CVE-2025-39503 Patchstack
9.3 Critical Goodlayers Hotel Plugin gdlr-hotel SQL Injection No login needed ≤ 3.1.4 CVE-2025-39504 Patchstack
9.3 Critical WP HRM LITE Plugin wp-hrm-lite-human-resource-management-system SQL Injection No login needed ≤ 1.1 CVE-2025-46455 Patchstack
9.3 Critical Easy Guide Plugin wp-easy-guide SQL Injection No login needed ≤ 1.0.0 CVE-2025-46460 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only