WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,451–1,500 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical PrivateContent Plugin private-content Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 8.11.5 CVE-2025-26966 Patchstack
9.3 Critical Easy Quotes Plugin easy-quotes SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-26943 Patchstack
9.8 Critical Flexmls® IDX Plugin flexmls-idx PHP Object Injection No login needed ≤ 3.14.27 Fixed in 3.14.28 CVE-2025-26900 Patchstack
9.8 Critical Everest Forms Plugin everest-forms Arbitrary File Upload Unauthenticated Arbitrary File Upload, Read, and Deletion No login needed ≤ 3.0.9.4 CVE-2025-1128 Wordfence
10.0 Critical Chaty Pro Plugin chaty-pro Arbitrary File Upload No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2025-26776 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack
9.8 Critical Ravpage Plugin ravpage PHP Object Injection No login needed ≤ 2.31 CVE-2024-13789 Wordfence
10.0 Critical Simplified Plugin simplified Arbitrary File Upload No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-22654 Patchstack
9.8 Critical K Elements Plugin k-elements Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.4.0 Fixed in 5.4.0 CVE-2024-56000 Patchstack
9.8 Critical CarSpot – Dealership Wordpress Classified Theme Privilege Escalation Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover No login needed ≤ 2.4.3 CVE-2024-12860 Wordfence
9.8 Critical Keap Official Opt-in Forms Plugin infusionsoft-official-opt-in-forms Local File Inclusion Unauthenticated Limited Local File Inclusion No login needed ≤ 2.0.1 CVE-2024-13725 Wordfence
9.3 Critical LTL Freight Quotes – FreightQuote Edition Plugin ltl-freight-quotes-freightquote-edition SQL Injection FreightQuote Edition Plugin <= 2.3.11 - SQL Injection No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-22290 Patchstack
9.8 Critical s2Member Pro Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 241216 CVE-2024-12562 Wordfence
9.8 Critical Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Information Disclosure A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation No login needed ≤ 2.4.2.3 CVE-2024-13513 Wordfence
9.9 Critical Widget Options Plugin widget-options Remote Code Execution Arbitrary Code Execution ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-22630 Patchstack
9.8 Critical WP Directorybox Manager Plugin Authentication Bypass No login needed ≤ 2.5 CVE-2024-13182 Wordfence
9.8 Critical Campress Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.35 CVE-2024-10763 Wordfence
9.9 Critical Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads ≤ 2.6.4 CVE-2024-10960 Wordfence
9.8 Critical Security & Malware scan by CleanTalk Plugin security-malware-firewall Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.149 CVE-2024-13365 Wordfence
9.8 Critical WP Job Board Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via process_register No login needed < 1.2.85 Fixed in 1.2.85 CVE-2024-12213 Wordfence
9.8 Critical Real Estate 7 Theme Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed ≤ 3.5.1 CVE-2024-13421 Wordfence
9.8 Critical WPGateway Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.5 CVE-2022-3180 Wordfence
9.8 Critical WP Foodbakery Plugin Authentication Bypass Authentication Bypass in foodbakery_parse_request No login needed ≤ 4.8 CVE-2025-0181 Wordfence
9.8 Critical WP Foodbakery Plugin Privilege Escalation Unauthenticated Privilege Escalation in foodbakery_registration_validation No login needed ≤ 4.7 CVE-2025-0180 Wordfence
9.8 Critical WP Foodbakery Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.7 CVE-2024-13011 Wordfence
9.8 Critical WP Directorybox Manager Plugin Authentication Bypass No login needed ≤ 2.5 CVE-2025-0316 Wordfence
9.6 Critical Munk Sites Plugin munk-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.0.7 CVE-2025-25101 Patchstack
9.6 Critical OneStore Sites Plugin onestore-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 0.1.1 CVE-2025-25107 Patchstack
9.6 Critical Starter Templates by FancyWP Plugin starter-templates Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.0.0 CVE-2025-25106 Patchstack
9.8 Critical Nextend Social Login Pro Plugin Authentication Bypass Authentication Bypass via Apple OAuth provider No login needed ≤ 3.1.16 CVE-2025-1061 Wordfence
9.9 Critical Post/Page Copying Tool Plugin postpage-import-export-with-custom-fields-taxonomies Remote Code Execution ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-24677 Patchstack
9.0 Critical Traveler Code Plugin traveler-code SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.1.2 Fixed in 3.1.2 CVE-2025-22699 Patchstack
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Local File Inclusion The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion No login needed ≤ 4.2.14 CVE-2025-0493 Wordfence
9.8 Critical Media Manager for UserPro Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Options Update No login needed ≤ 3.11.0 CVE-2024-12822 Wordfence
9.8 Critical iControlWP – Multiple WordPress Site Manager Plugin worpit-admin-dashboard-plugin PHP Object Injection Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.5 CVE-2024-13742 Wordfence
9.8 Critical ThemeREX Addons Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data No login needed ≤ 2.32.3 CVE-2024-13448 Wordfence
9.8 Critical Save as PDF Plugin save-as-pdf-by-pdfcrowd PHP Object Injection No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2025-24671 Patchstack
9.3 Critical Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection No login needed ≤ 5.2.17 Fixed in 5.2.18 CVE-2025-24667 Patchstack
9.3 Critical Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition SQL Injection No login needed ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-24665 Patchstack
9.3 Critical LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition SQL Injection No login needed ≤ 5.0.20 Fixed in 5.0.21 CVE-2025-24664 Patchstack
9.3 Critical Shipping for Nova Poshta Plugin nova-poshta-ttn SQL Injection No login needed ≤ 1.19.6 Fixed in 1.19.7 CVE-2025-24612 Patchstack
9.8 Critical FundPress Plugin fundpress PHP Object Injection No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24601 Patchstack
9.8 Critical WPBookit Plugin wpbookit Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6.9 CVE-2025-0357 Wordfence
9.1 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.15.3 Fixed in 2.15.4 CVE-2025-24650 Patchstack
9.8 Critical Bootstrap Ultimate Theme bootstrap-ultimate Local File Inclusion Unauthenticated Limited Local File Inclusion No login needed ≤ 1.4.9 CVE-2024-13545 Wordfence
9.8 Critical Muzaara Google Ads Report Plugin muzaara-adwords-optimize-dashboard PHP Object Injection No login needed ≤ 3.1 CVE-2025-23914 Patchstack
10.0 Critical user files Plugin user-files Arbitrary File Upload No login needed ≤ 2.4.2 CVE-2025-23953 Patchstack
9.1 Critical WP Load Gallery Plugin wp-load-gallery Arbitrary File Upload ≤ 2.1.6 CVE-2025-23942 Patchstack
9.8 Critical Quick Count Plugin quick-count PHP Object Injection No login needed ≤ 3.00 CVE-2025-23932 Patchstack
9.3 Critical WordPress Local SEO Plugin dh-local-seo SQL Injection No login needed ≤ 2.3 CVE-2025-23931 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only