WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical WPSmartContracts Plugin wp-smart-contracts SQL Injection No login needed ≤ 2.0.12 CVE-2025-31565 Patchstack
9.1 Critical Processing Projects Plugin processing-projects Arbitrary File Upload ≤ 1.0.2 CVE-2025-32206 Patchstack
9.1 Critical Insert or Embed Articulate Content into Plugin insert-or-embed-articulate-content-into-wordpress Arbitrary File Upload ≤ 4.3000000025 Fixed in 4.3000000026 CVE-2025-32202 Patchstack
9.9 Critical WP Remote Thumbnail Plugin wp-remote-thumbnail Arbitrary File Upload ≤ 1.3.2 CVE-2025-32140 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation No login needed ≤ 8.7.5 CVE-2025-32695 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.6 Fixed in 1.6.1 CVE-2025-31002 Patchstack
9.8 Critical Buddypress Humanity Plugin buddypress-humanity Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.2 CVE-2025-31033 Patchstack
9.6 Critical Ultra Demo Importer Plugin ut-demo-importer Cross-Site Request Forgery CSRF to RCE No login needed ≤ 1.0.5 CVE-2025-32496 Patchstack
9.6 Critical WP shop Plugin wpshop Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.6.1 CVE-2025-32576 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
9.6 Critical Vite Coupon Plugin vite-coupon Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-32642 Patchstack
9.1 Critical Simple WP Events Plugin simple-wp-events Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.8.17 CVE-2025-2004 Wordfence
9.8 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Move No login needed ≤ 1.1.4 CVE-2025-2941 Wordfence
9.1 Critical CMP – Coming Soon & Maintenance Plugin cmp-coming-soon-maintenance Remote Code Execution Coming Soon & Maintenance plugin <= 4.1.14 - Remote Code Execution (RCE) ≤ 4.1.14 Fixed in 4.1.15 CVE-2025-32118 Patchstack
9.8 Critical Homey Theme homey Privilege Escalation No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-51800 Patchstack
9.8 Critical Woffice Theme Authentication Bypass Authentication Bypass via Registration Role No login needed ≤ 5.4.21 CVE-2025-2798 Wordfence
9.3 Critical Booking Calendar and Notification Plugin booking-calendar-and-notification SQL Injection No login needed ≤ 4.0.3 CVE-2025-31403 Patchstack
9.8 Critical TagDiv Composer Plugin Information Disclosure Unauthenticated Arbitrary PHP Object Instantiation No login needed ≤ 5.3 CVE-2024-13645 Wordfence
9.3 Critical Social Share And Social Locker Plugin social-share-and-social-locker-arsocial SQL Injection No login needed ≤ 1.4.2 CVE-2025-31911 Patchstack
9.8 Critical Front-End-Only-Users Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.2.32 CVE-2025-2005 Wordfence
9.8 Critical CBX Poll Plugin cbxpoll PHP Object Injection No login needed ≤ 2.0.4 CVE-2025-31612 Patchstack
9.3 Critical WP AutoKeyword Plugin wp-autokeyword SQL Injection No login needed ≤ 1.0 CVE-2025-31579 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-31553 Patchstack
9.3 Critical RSVPMarker Plugin rsvpmaker SQL Injection No login needed ≤ 11.6.7 Fixed in 11.6.8 CVE-2025-31552 Patchstack
9.3 Critical Salesmate Add-On for Gravity Forms Plugin gf-salesmate-add-on SQL Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-31551 Patchstack
9.3 Critical Shopper Plugin shopper SQL Injection No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-31534 Patchstack
9.3 Critical History Log by click5 Plugin history-log-by-click5 SQL Injection No login needed ≤ 1.0.13 CVE-2025-31531 Patchstack
9.9 Critical Countdown & Clock Plugin countdown-builder Remote Code Execution ≤ 2.8.8 Fixed in 2.8.9 CVE-2025-30841 Patchstack
9.3 Critical Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-30807 Patchstack
10.0 Critical DigiWidgets Image Editor Plugin digiwidgets-image-editor Remote Code Execution No login needed ≤ 1.10 CVE-2025-30580 Patchstack
9.8 Critical WP RealEstate Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'process_register' No login needed ≤ 1.6.26 CVE-2025-2237 Wordfence
9.8 Critical SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation No login needed ≤ 3.7.9 CVE-2024-13553 Wordfence
9.3 Critical XV Random Quotes Plugin xv-random-quotes SQL Injection No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-30971 Patchstack
9.8 Critical Material Dashboard Plugin material-dashboard Privilege Escalation No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31095 Patchstack
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
9.8 Critical Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection No login needed ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-31084 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
9.3 Critical JS Help Desk Plugin js-support-ticket SQL Injection No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30886 Patchstack
9.3 Critical Ads by WPQuads Plugin quick-adsense-reloaded SQL Injection No login needed ≤ 2.0.87.1 Fixed in 2.0.88 CVE-2025-30876 Patchstack
9.3 Critical PostMash Plugin postmash-custom SQL Injection No login needed ≤ 1.0.3 CVE-2025-30622 Patchstack
9.8 Critical Checkout Mestres do WP for WooCommerce Plugin checkout-mestres-wp Broken Access Control Unauthenticated Arbitrary Options Update No login needed 8.6.5 – 8.7.5 CVE-2025-2266 Wordfence
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack
9.3 Critical Schedule Plugin schedule SQL Injection No login needed ≤ 1.0.0 CVE-2025-22523 Patchstack
9.8 Critical Kubio AI Page Builder Plugin kubio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.5.1 CVE-2025-2294 Wordfence
9.0 Critical Traveler Plugin traveler PHP Object Injection No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26873 Patchstack
9.3 Critical Traveler Plugin traveler SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-26898 Patchstack
9.6 Critical Hide My WP Ghost Plugin hide-my-wp Local File Inclusion Local File Inclusion to RCE No login needed ≤ 5.4.01 Fixed in 5.4.02 CVE-2025-26909 Patchstack
9.8 Critical Export All Posts, Products, Orders, Refunds & Users Plugin wp-ultimate-exporter PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.13 CVE-2025-2332 Wordfence
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.0.18 Fixed in 5.0.19 CVE-2025-26941 Patchstack
9.3 Critical Product Catalog Plugin displayproduct SQL Injection No login needed ≤ 1.0.4 CVE-2025-30524 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only