WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,401–1,450 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 29 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Trust Payments Gateway for WooCommerce Plugin trust-payments-hosted-payment-pages-integration SQL Injection No login needed ≤ 1.1.4 Fixed in 2.0.0 CVE-2025-28942 Patchstack
9.8 Critical Docpro Plugin docpro Local File Inclusion No login needed ≤ 2.0.1 CVE-2025-28916 Patchstack
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.2 CVE-2025-28898 Patchstack
9.9 Critical Visual Text Editor Plugin visual-text-editor Remote Code Execution ≤ 1.2.1 CVE-2025-28893 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-28904 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
9.3 Critical Awesome Logos Plugin awesome-logos Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.2 CVE-2025-30528 Patchstack
9.8 Critical Age Gate Plugin age-gate Local File Inclusion Unauthenticated Local PHP File Inclusion via 'lang' No login needed ≤ 3.5.3 CVE-2025-2505 Wordfence
9.8 Critical File Away Plugin file-away Broken Access Control Missing Authorization to Unauthenticated File Upload via upload Function No login needed ≤ 3.9.9.0.1 CVE-2025-2512 Wordfence
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 5.0 CVE-2024-13442 Wordfence
9.8 Critical MinimogWP – The High Converting eCommerce Theme Local File Inclusion The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion No login needed ≤ 3.7.0 CVE-2024-13790 Wordfence
9.8 Critical CozyStay Plugin PHP Object Injection Unauthenticated PHP Object Injection in ajax_handler No login needed ≤ 1.7.0, ≤ 3.9.0 CVE-2024-13410 Wordfence
9.8 Critical Altair Theme Broken Access Control Unauthenticated Arbitrary Options Update via pp_import_current No login needed ≤ 5.2.4 CVE-2024-12922 Wordfence
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
9.8 Critical Traveler Theme Local File Inclusion Unauthenticated Local File Inclusion via hotel_alone_load_more_post No login needed ≤ 3.1.8 CVE-2025-1771 Wordfence
9.8 Critical Realteo - Real Estate Plugin by Purethemes Plugin Authentication Bypass Real Estate Plugin by Purethemes <= 1.2.8 - Authentication Bypass via 'do_register_user' No login needed ≤ 1.2.8 CVE-2025-2232 Wordfence
9.8 Critical Civi - Job Board & Freelance Marketplace Theme Authentication Bypass Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Password Update No login needed ≤ 2.1.4 CVE-2024-13771 Wordfence
9.8 Critical CiyaShop - Multipurpose WooCommerce Theme PHP Object Injection Multipurpose WooCommerce Theme <= 4.19.0 - Unauthenticated PHP Object Injection No login needed ≤ 4.19.0 CVE-2024-13824 Wordfence
9.8 Critical WP JobHunt Plugin Authentication Bypass No login needed ≤ 7.1 CVE-2024-11286 Wordfence
9.8 Critical WP JobHunt Plugin Privilege Escalation Unauthenticated Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 7.1 CVE-2024-11284 Wordfence
9.8 Critical WP JobHunt Plugin Privilege Escalation Unauthenticated Privilege Escalation via Email Update/Account Takeover No login needed ≤ 7.1 CVE-2024-11285 Wordfence
9.8 Critical Workreap Plugin Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.2.5 CVE-2024-13446 Wordfence
9.1 Critical ThemeEgg ToolKit Plugin themeegg-toolkit Arbitrary File Upload ≤ 1.2.9 CVE-2025-28915 Patchstack
9.8 Critical HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.6.5 CVE-2025-1661 Wordfence
10.0 Critical Fresh Framework Plugin fresh-framework Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.70.0 CVE-2025-26936 Patchstack
9.0 Critical Massive Dynamic Plugin massive-dynamic Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 8.2 CVE-2025-26916 Patchstack
9.8 Critical Javo Core Plugin Privilege Escalation Unauthenticated Privilege Escalation in ajax_signup No login needed ≤ 3.0.0.080 CVE-2025-0177 Wordfence
9.8 Critical Golo - Directory & Listing, Travel Theme Broken Access Control Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change No login needed ≤ 1.6.10 CVE-2024-12876 Wordfence
9.8 Critical InWave Jobs Plugin Privilege Escalation Unauthenticated Privilege Escalation via Password Reset No login needed ≤ 3.5.1 CVE-2025-1315 Wordfence
9.8 Critical WPCOM Member Plugin wpcom-member Authentication Bypass Authentication Bypass via 'user_phone' No login needed ≤ 1.7.5 CVE-2025-1475 Wordfence
9.8 Critical Homey Login Register Plugin Privilege Escalation Unauthenticated Privilege Escalation in homey_register No login needed ≤ 2.4.0 CVE-2024-11951 Wordfence
9.8 Critical Homey Theme Privilege Escalation Unauthenticated Privilege Escalation in homey_save_profile No login needed ≤ 2.4.2 CVE-2024-12281 Wordfence
9.8 Critical VEDA - MultiPurpose Theme PHP Object Injection MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection No login needed ≤ 4.2 CVE-2024-13787 Wordfence
9.8 Critical WP Real Estate Manager Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 2.8 CVE-2025-1515 Wordfence
9.8 Critical Newscrunch Theme newscrunch Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1307 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.4 CVE-2025-0912 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
10.0 Critical Ark Theme Core Plugin ark-core Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.71.0 Fixed in 1.71.0 CVE-2025-26970 Patchstack
9.8 Critical Residential Address Detection Plugin residential-address-detection Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-27270 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection Worldwide Express Edition Plugin <= 5.2.18 - SQL Injection No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-27268 Patchstack
9.3 Critical Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway SQL Injection No login needed ≤ 1.7.6 CVE-2025-26535 Patchstack
9.3 Critical uListing Plugin ulisting SQL Injection No login needed ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-25150 Patchstack
9.8 Critical SetSail Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.0.3 CVE-2025-1564 Wordfence
9.8 Critical Academist Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.1.6 CVE-2025-1671 Wordfence
9.8 Critical Alloggio Membership Plugin Authentication Bypass Authentication Bypass via Social Login Account Takeover No login needed ≤ 1.1 CVE-2025-1638 Wordfence
9.8 Critical Nokri – Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change No login needed ≤ 1.6.2 CVE-2024-12824 Wordfence
9.8 Critical DHVC Form Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.4.7 CVE-2024-8420 Wordfence
9.8 Critical WHMpress Plugin Local File Inclusion Unauthenticated Local File Inclusion to Arbitrary Options Update No login needed ≤ 6.3-revision-0 CVE-2024-9193 Wordfence
9.8 Critical WooCommerce Ultimate Gift Card Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.9.2 CVE-2024-8425 Wordfence
9.3 Critical WP Multistore Locator Plugin wp-multi-store-locator SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2025-26974 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only