WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,251–1,300 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Pix 4x sem juros - Pagaleve Plugin wc-pagaleve PHP Object Injection Pagaleve plugin <= 1.6.9 - PHP Object Injection No login needed ≤ 1.6.9 Fixed in 1.6.10 CVE-2025-48287 Patchstack
9.8 Critical Madara – Responsive and modern WordPress theme for manga sites Theme Local File Inclusion Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion No login needed ≤ 2.2.2 CVE-2025-4524 Wordfence
9.8 Critical Digits Plugin Authentication Bypass Auth Bypass via OTP Bruteforcing No login needed < 8.4.6.1 Fixed in 8.4.6.1 CVE-2025-4094 WPScan
9.8 Critical Motors Theme Privilege Escalation Unauthenticated Privilege Escalation via Password Update/Account Takeover No login needed ≤ 5.6.67 CVE-2025-4322 Wordfence
9.8 Critical User Profile Meta Manager Plugin user-profile-meta Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.02 CVE-2025-48340 Patchstack
9.8 Critical Grand Restaurant Plugin grandrestaurant Path Traversal Path Traversal to PHP Object Injection No login needed ≤ 7.0 CVE-2025-32926 Patchstack
9.8 Critical FoodBakery Plugin wp-foodbakery PHP Object Injection No login needed ≤ 3.3 CVE-2025-32927 Patchstack
9.8 Critical Altair Theme altair PHP Object Injection No login needed ≤ 5.2.2 CVE-2025-32928 Patchstack
9.8 Critical Grand Restaurant Plugin grandrestaurant PHP Object Injection No login needed ≤ 7.0 CVE-2025-39348 Patchstack
9.8 Critical CiyaShop Theme ciyashop PHP Object Injection No login needed ≤ 4.18.0 CVE-2025-39349 Patchstack
9.8 Critical Grand Conference Plugin grandconference PHP Object Injection No login needed ≤ 5.3 CVE-2025-39354 Patchstack
9.8 Critical Foodbakery Sticky Cart Plugin foodbakery-sticky-cart PHP Object Injection No login needed ≤ 3.2 CVE-2025-39356 Patchstack
10.0 Critical Hospital Management System Plugin hospital-management Arbitrary File Upload No login needed ≤ 47.0(20-11-2023) CVE-2025-39380 Patchstack
9.3 Critical Hospital Management System Plugin hospital-management SQL Injection No login needed ≤ 47.0(20-11-2023) CVE-2025-39386 Patchstack
9.3 Critical AnalyticsWP Plugin analyticswp SQL Injection No login needed ≤ 2.1.2 Fixed in 2.1.5 CVE-2025-39389 Patchstack
9.3 Critical WPAMS Plugin apartment-management SQL Injection No login needed ≤ 44.0 (17-08-2023) CVE-2025-39395 Patchstack
10.0 Critical WPAMS Plugin apartment-management Arbitrary File Upload No login needed ≤ 44.0 (17-08-2023) CVE-2025-39401 Patchstack
9.9 Critical WPAMS Plugin apartment-management Arbitrary File Upload ≤ 44.0 (17-08-2023) CVE-2025-39402 Patchstack
9.8 Critical WPAMS Plugin apartment-management Local File Inclusion Local File Inclusion to Privilege Escalation No login needed ≤ 44.0 CVE-2025-39406 Patchstack
9.8 Critical Smart Sections Theme Builder - WPBakery Page Builder Addon Plugin visucom-smart-sections PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed ≤ 1.7.8 CVE-2025-39410 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 7.2 Fixed in 7.5 CVE-2025-39445 Patchstack
10.0 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Arbitrary File Upload No login needed ≤ 2.9.2 Fixed in 2.10.0 CVE-2025-47577 Patchstack
9.8 Critical WordPress Events Calendar Registration & Tickets Plugin wpeventplus PHP Object Injection No login needed ≤ 2.6.0 CVE-2025-47581 Patchstack
9.8 Critical WPBot Pro Wordpress Chatbot Plugin wpbot-pro PHP Object Injection No login needed ≤ 12.7.0 CVE-2025-47582 Patchstack
9.9 Critical Celestial Aura Theme celestial-aura Arbitrary File Upload ≤ 2.2 CVE-2025-26892 Patchstack
9.9 Critical Eximius Theme eximius Arbitrary File Upload ≤ 2.2 CVE-2025-26872 Patchstack
9.8 Critical Echo RSS Feed Post Generator Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.4.8.1 CVE-2025-4391 Wordfence
9.8 Critical Crawlomatic Multipage Scraper Post Generator Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.6.8.1 CVE-2025-4389 Wordfence
9.3 Critical Eventer Plugin eventer SQL Injection No login needed ≤ 3.11.4 Fixed in 3.11.4 CVE-2025-39481 Patchstack
9.3 Critical WPGYM Plugin gym-management SQL Injection No login needed ≤ 65.0 CVE-2025-32643 Patchstack
9.1 Critical Z-Downloads Plugin z-downloads Cross-Site Scripting Admin+ Stored XSS via SVG Upload No login needed < 1.11.7 Fixed in 1.11.7 CVE-2024-8673 WPScan
9.8 Critical Simple Video Directory Plugin SQL Injection Unauthenticated SQLi No login needed < 1.4.3 Fixed in 1.4.3 CVE-2024-6809 WPScan
9.8 Critical Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress SQL Injection Multiple Unauthenticated SQLi No login needed < 1.9.4 Fixed in 1.9.4 CVE-2024-6159 WPScan
9.8 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.18 CVE-2025-4564 Wordfence
9.8 Critical 百度站长SEO合集(支持百度/神马/Bing/头条推送) Plugin baiduseo Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.0.6 CVE-2025-3917 Wordfence
9.1 Critical Uncanny Automator Plugin uncanny-automator PHP Object Injection Unauthenticated PHP Object Injection in automator_api_decode_message Function No login needed ≤ 6.4.0.1 CVE-2025-3623 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.8.1 - SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-47682 Patchstack
9.8 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via upload Function No login needed ≤ 1.1.6 CVE-2025-4403 Wordfence
9.8 Critical Envolve Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via language_file and fonts_file No login needed ≤ 1.0 CVE-2024-11617 Wordfence
9.8 Critical Frontend Login and Registration Blocks Plugin frontend-login-and-registration-blocks Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.1.1 CVE-2025-3605 Wordfence
9.8 Critical WPBookit Plugin wpbookit Broken Access Control Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update No login needed ≤ 1.0.2 CVE-2025-3811 Wordfence
9.8 Critical WPBookit Plugin wpbookit Broken Access Control Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.0.2 CVE-2025-3810 Wordfence
9.3 Critical Productive Commerce Plugin productive-commerce SQL Injection No login needed ≤ 1.1.40 CVE-2025-47657 Patchstack
9.1 Critical BEAF Plugin beaf-before-and-after-gallery Arbitrary File Upload ≤ 4.6.10 Fixed in 4.6.11 CVE-2025-47549 Patchstack
9.8 Critical Frontend Dashboard Plugin frontend-dashboard Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function No login needed 1.0 – 2.2.6 CVE-2025-4104 Wordfence
9.8 Critical PeproDev Ultimate Profile Solutions Plugin peprodev-ups Authentication Bypass Authentication Bypass to Account Takeover No login needed 1.9.1 – 7.5.2 CVE-2025-3844 Wordfence
9.8 Critical PGS Core Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 5.8.0 CVE-2025-0855 Wordfence
9.8 Critical BuddyBoss Platform Pro Plugin Authentication Bypass Authentication Bypass via Apple OAuth provider No login needed ≤ 2.7.01 CVE-2025-1909 Wordfence
9.8 Critical Job Listings Plugin job-listings Privilege Escalation Unauthenticated Privilege Escalation via register_action Function No login needed 0.1 – 0.1.1 CVE-2025-3918 Wordfence
9.8 Critical OTP-less one tap Sign in Plugin otpless Privilege Escalation Unauthenticated Arbitrary Email Update to Account Takeover/Privilege Escalation No login needed 2.0.14 – 2.0.59 CVE-2025-3746 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only