WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,951–2,000 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 40 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Demo Importer Plus Plugin demo-importer-plus Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-69091 Patchstack
6.5 Medium Auto Listings Plugin auto-listings Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-69089 Patchstack
6.5 Medium Combo Offers WooCommerce Plugin woo-combo-offers Cross-Site Scripting ≤ 4.2 Fixed in 4.3 CVE-2025-69088 Patchstack
6.5 Medium Blog Filter Plugin blog-filter Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-69033 Patchstack
5.4 Medium FiveStar Theme fivestar Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2025-69032 Patchstack
5.3 Medium Arcane Theme arcane Broken Access Control No login needed ≤ 3.6.6 CVE-2025-69031 Patchstack
5.4 Medium Backpack Traveler Theme backpacktraveler Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.3 CVE-2025-69030 Patchstack
5.4 Medium Struktur Theme struktur Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.1 CVE-2025-69029 Patchstack
5.3 Medium weForms Plugin weforms Broken Access Control No login needed ≤ 1.6.25 Fixed in 1.6.26 CVE-2025-69028 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 3.2.0 - Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-69027 Patchstack
4.3 Medium PopupKit Plugin popup-builder-block Information Disclosure Sensitive Data Exposure ≤ 2.1.5 Fixed in 2.2.1 CVE-2025-69026 Patchstack
4.3 Medium Poptics Plugin poptics Information Disclosure Sensitive Data Exposure ≤ 1.0.20 Fixed in 1.0.21 CVE-2025-69025 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
4.3 Medium Discussion Board Plugin wp-discussion-board Broken Access Control ≤ 2.5.7 Fixed in 2.5.8 CVE-2025-69023 Patchstack
5.4 Medium HR Management Lite Plugin hr-management-lite Broken Access Control No login needed ≤ 3.6 CVE-2025-69022 Patchstack
5.4 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 6.0.7 Fixed in 6.0.8 CVE-2025-69021 Patchstack
6.5 Medium Newsletters Plugin newsletters-lite Cross-Site Scripting ≤ 4.12 Fixed in 4.13 CVE-2025-69020 Patchstack
6.5 Medium FlippingBook Plugin flippingbook Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-69019 Patchstack
6.5 Medium Web Directory Free Plugin web-directory-free Cross-Site Scripting ≤ 1.7.12 Fixed in 1.7.13 CVE-2025-69018 Patchstack
6.5 Medium RestroPress Plugin restropress Cross-Site Scripting ≤ 3.2.8.6 Fixed in 3.2.8.6.1 CVE-2025-69017 Patchstack
4.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.17.15 CVE-2025-69016 Patchstack
4.9 Medium Youzify Plugin youzify Server-Side Request Forgery ≤ 1.3.7 CVE-2025-69014 Patchstack
4.3 Medium Stratum Plugin stratum Broken Access Control ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-69013 Patchstack
4.3 Medium Event Organiser Plugin event-organiser Broken Access Control ≤ 3.12.8 CVE-2025-69012 Patchstack
5.3 Medium Themebeez Toolkit Plugin themebeez-toolkit Broken Access Control No login needed ≤ 1.3.5 CVE-2025-69010 Patchstack
5.3 Medium Medicalequipment Theme medicalequipment Broken Access Control No login needed ≤ 1.0.9 CVE-2025-69009 Patchstack
5.9 Medium Inboxify Sign Up Form Plugin inboxify-sign-up-form Cross-Site Scripting ≤ 1.0.4 CVE-2025-69008 Patchstack
5.9 Medium Popping Sidebars and Widgets Light Plugin popping-sidebars-and-widgets-light Cross-Site Scripting ≤ 1.27 CVE-2025-69007 Patchstack
5.9 Medium AM Events Plugin am-events Cross-Site Scripting ≤ 1.13.1 CVE-2025-69006 Patchstack
5.4 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2025-68998 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 7.6.43 Fixed in 7.6.44 CVE-2025-68997 Patchstack
4.3 Medium My Sticky Elements Plugin mystickyelements Broken Access Control ≤ 2.3.3 Fixed in 2.3.4 CVE-2025-68995 Patchstack
5.3 Medium Product Loops for WooCommerce Plugin product-loops Broken Access Control No login needed ≤ 2.1.2 CVE-2025-68994 Patchstack
5.3 Medium Share, Print and PDF Products for WooCommerce Plugin share-print-pdf-woocommerce Broken Access Control No login needed ≤ 3.1.2 CVE-2025-68993 Patchstack
6.5 Medium BWL Knowledge Base Manager Plugin bwl-kb-manager Cross-Site Scripting ≤ 1.6.3 CVE-2025-68992 Patchstack
6.5 Medium BWL Pro Voting Manager Plugin bwl-pro-voting-manager Cross-Site Scripting ≤ 1.4.9 CVE-2025-68991 Patchstack
4.3 Medium contact-form-7-mailchimp-extension Plugin contact-form-7-mailchimp-extension Information Disclosure Sensitive Data Exposure ≤ 0.9.68 Fixed in 0.9.69 CVE-2025-68989 Patchstack
5.3 Medium E-Invoice App Malaysia Plugin einvoiceapp-malaysia Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.0 CVE-2025-68988 Patchstack
5.3 Medium DesignThemes LMS Addon Plugin designthemes-lms-addon Broken Access Control No login needed ≤ 2.6 CVE-2025-68982 Patchstack
5.3 Medium HomeFix Elementor Portfolio Plugin homefix-ele-portfolio Broken Access Control No login needed ≤ 1.0.1 CVE-2025-68981 Patchstack
5.3 Medium WeDesignTech Portfolio Plugin wedesigntech-portfolio Broken Access Control No login needed ≤ 1.0.2 CVE-2025-68980 Patchstack
5.3 Medium Google Calendar Events Plugin google-calendar-events Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2025-68979 Patchstack
6.5 Medium DesignThemes Core Plugin designthemes-core Cross-Site Scripting ≤ 1.6 CVE-2025-68978 Patchstack
6.5 Medium DesignThemes Portfolio Addon Plugin designthemes-portfolio-addon Cross-Site Scripting ≤ 1.5 CVE-2025-68977 Patchstack
5.4 Medium Eagle Booking Plugin eagle-booking Broken Access Control Settings Change ≤ 1.3.4.3 CVE-2025-68976 Patchstack
4.3 Medium Eagle Booking Plugin eagle-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.4.3 CVE-2025-68975 Patchstack
6.6 Medium WordPress Social Login and Register Plugin miniorange-login-openid Local File Inclusion ≤ 7.7.0 CVE-2025-68974 Patchstack
6.5 Medium WP Project Manager Plugin wedevs-project-manager Information Disclosure Sensitive Data Exposure ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-68040 Patchstack
5.4 Medium Better Elementor Addons Plugin better-elementor-addons Broken Access Control ≤ 1.3.7 Fixed in 1.3.9 CVE-2023-41656 Patchstack
5.4 Medium TheGem (Elementor) Theme thegem-elementor Broken Access Control < 5.8.1.1 Fixed in 5.8.1.1 CVE-2023-32238 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only