WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,301–1,350 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical OttoKit Plugin suretriggers Privilege Escalation No login needed ≤ 1.0.82 Fixed in 1.0.83 CVE-2025-27007 Patchstack
9.8 Critical Order Delivery Date Pro for WooCommerce Plugin Cross-Site Request Forgery Unauthenticated Arbitrary Option Update No login needed 2.0 – < 12.3.1 Fixed in 12.3.1 CVE-2025-2907 WPScan
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' No login needed ≤ 5.1 CVE-2025-2470 Wordfence
9.9 Critical PowerPress Podcasting Plugin powerpress Arbitrary File Upload ≤ 11.12.5 Fixed in 11.12.6 CVE-2025-46264 Patchstack
9.3 Critical Frontend Dashboard Plugin frontend-dashboard SQL Injection No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-46248 Patchstack
9.8 Critical Flynax Bridge Plugin flynax-bridge Privilege Escalation Unauthenticated Privilege Escalation via Password Update No login needed ≤ 2.2.0 CVE-2025-3603 Wordfence
9.8 Critical Flynax Bridge Plugin flynax-bridge Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 2.2.0 CVE-2025-3604 Wordfence
9.1 Critical Database Toolset Plugin database-toolset Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.8.4 CVE-2025-3065 Wordfence
9.8 Critical Wordpress Plugin Smart Product Review Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2021-4455 Wordfence
9.8 Critical AIHub Theme Arbitrary File Upload Unauthenticated Arbitrary File Upload in generate_image No login needed ≤ 1.3.7 CVE-2025-1093 Wordfence
9.8 Critical UrbanGo Membership Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.4 CVE-2025-3278 Wordfence
9.3 Critical Modal Survey Plugin modal-survey SQL Injection No login needed ≤ 2.0.2.0.1 CVE-2025-39471 Patchstack
9.9 Critical Theme File Duplicator Plugin theme-file-duplicator Arbitrary File Upload ≤ 1.3 CVE-2025-27282 Patchstack
9.8 Critical Saoshyant Slider Plugin saoshyant-slider PHP Object Injection No login needed ≤ 3.0 CVE-2025-27286 Patchstack
9.8 Critical SS Quiz Plugin ssquiz PHP Object Injection No login needed ≤ 2.0.5 CVE-2025-27287 Patchstack
9.3 Critical CHATLIVE Plugin chatlive SQL Injection No login needed ≤ 2.0.1 CVE-2025-27302 Patchstack
9.8 Critical Paid Videochat Turnkey Site Plugin ppv-live-webcams Authentication Bypass Broken Authentication No login needed ≤ 7.3.11 Fixed in 7.3.12 CVE-2025-31380 Patchstack
9.8 Critical Kata Plus Plugin kata-plus PHP Object Injection No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-32572 Patchstack
9.9 Critical PDF 2 Post Plugin pdf2post Remote Code Execution ≤ 2.4.0 CVE-2025-32583 Patchstack
9.3 Critical JS Job Manager Plugin js-jobs SQL Injection No login needed ≤ 2.0.2 CVE-2025-32626 Patchstack
9.3 Critical Local Magic Plugin local-magic SQL Injection No login needed ≤ 2.9.0 CVE-2025-32636 Patchstack
9.8 Critical Projectopia Plugin projectopia-core Privilege Escalation No login needed ≤ 5.1.24 CVE-2025-32648 Patchstack
9.9 Critical Solace Extra Plugin solace-extra Arbitrary File Upload ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-32652 Patchstack
10.0 Critical JS Job Manager Plugin js-jobs Arbitrary File Upload No login needed ≤ 2.0.2 CVE-2025-32660 Patchstack
9.8 Critical HelpGent Plugin helpgent PHP Object Injection No login needed ≤ 2.2.5 CVE-2025-32658 Patchstack
9.3 Critical Office Locator Plugin office-locator SQL Injection No login needed ≤ 1.3.0 CVE-2025-32665 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.6.4 Fixed in 8.6.5 CVE-2025-32682 Patchstack
9.8 Critical FluentCommunity Plugin fluent-community PHP Object Injection No login needed ≤ 1.2.15 Fixed in 1.3.1 CVE-2025-39550 Patchstack
9.8 Critical FluentBoards Plugin fluent-boards PHP Object Injection No login needed ≤ 1.47 Fixed in 1.48 CVE-2025-39551 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.65 Fixed in 3.2.68 CVE-2025-39587 Patchstack
9.8 Critical Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-39588 Patchstack
9.3 Critical Quentn WP Plugin quentn-wp SQL Injection No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-39595 Patchstack
9.8 Critical Quentn WP Plugin quentn-wp Privilege Escalation No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-39596 Patchstack
9.3 Critical CWD – Stealth Links Plugin cwd-stealth-links SQL Injection Stealth Links plugin <= 1.3 - SQL Injection No login needed ≤ 1.3 CVE-2025-22655 Patchstack
9.1 Critical I Draw Plugin idraw Arbitrary File Upload ≤ 1.0 CVE-2025-39436 Patchstack
9.1 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Arbitrary File Upload ≤ 1.5.14 Fixed in 1.5.15 CVE-2025-39557 Patchstack
9.6 Critical Custom CSS, JS & PHP Plugin custom-css Cross-Site Request Forgery CSRF to RCE No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-39601 Patchstack
9.6 Critical WPJobBoard Plugin wpjobboard Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30967 Patchstack
10.0 Critical AI Hub Plugin aihub Arbitrary File Upload No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-26927 Patchstack
9.8 Critical GNUCommerce Plugin gnucommerce PHP Object Injection No login needed ≤ 1.5.4 CVE-2025-30985 Patchstack
9.8 Critical Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder Plugin everest-forms PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.1.1 CVE-2025-3439 Wordfence
9.8 Critical WpBookingly Plugin service-booking-manager PHP Object Injection No login needed ≤ 1.3.0 CVE-2025-32607 Patchstack
9.3 Critical WP Online Users Stats Plugin wp-online-users-stats SQL Injection No login needed ≤ 1.0.0 CVE-2025-32603 Patchstack
9.9 Critical Sync Posts Plugin sync-posts Arbitrary File Upload ≤ 1.0 CVE-2025-32579 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2025-32577 Patchstack
9.8 Critical TableOn Plugin posts-table-filterable PHP Object Injection No login needed ≤ 1.0.4.3 Fixed in 1.0.4.4 CVE-2025-32569 Patchstack
9.8 Critical EmpikPlace for Woocommerce Plugin empik-for-woocommerce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32568 Patchstack
9.3 Critical Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.0 CVE-2025-32565 Patchstack
9.8 Critical Rankology SEO – On-site SEO Plugin rankology-seo-all-in-one-seo-analytics Privilege Escalation On-site SEO plugin <= 2.2.4 - Privilege Escalation No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-32491 Patchstack
9.3 Critical Bulk Product Sync Plugin sync-wc-google SQL Injection No login needed ≤ 8.6 Fixed in 9.0 CVE-2025-31599 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only