WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,001–2,050 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 41 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Yolox Theme yolox Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-69075 Patchstack
8.1 High Pearson Specter Theme pearsonspecter Local File Inclusion No login needed ≤ 1.11.3 CVE-2025-69074 Patchstack
8.1 High Piqes Theme piqes Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-69073 Patchstack
8.1 High Prider Theme prider Local File Inclusion No login needed ≤ 1.1.3.1 CVE-2025-69072 Patchstack
8.1 High TanTum Theme tantum Local File Inclusion No login needed ≤ 1.1.13 CVE-2025-69071 Patchstack
8.1 High Tornados Theme tornados Local File Inclusion No login needed ≤ 2.1 CVE-2025-69070 Patchstack
8.1 High Muji Theme muji Local File Inclusion No login needed ≤ 1.2.0 CVE-2025-69068 Patchstack
8.1 High Tails Theme tails Local File Inclusion No login needed ≤ 1.4.12 CVE-2025-69067 Patchstack
8.1 High Indoor Plants Theme indoor-plants Local File Inclusion No login needed ≤ 1.2.7 CVE-2025-69066 Patchstack
8.1 High Snow Mountain Theme snowmountain Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69065 Patchstack
8.1 High Pets Land Theme petsland Local File Inclusion No login needed ≤ 1.2.8 CVE-2025-69064 Patchstack
8.1 High Weedles Theme weedles Local File Inclusion No login needed ≤ 1.1.12 CVE-2025-69062 Patchstack
8.1 High MoveMe Theme moveme Local File Inclusion No login needed ≤ 1.2.15 CVE-2025-69061 Patchstack
8.1 High uReach Theme ureach Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69060 Patchstack
8.1 High DiveIt Theme diveit Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69059 Patchstack
8.1 High PartyMaker Theme partymaker Local File Inclusion No login needed ≤ 1.1.15 CVE-2025-69058 Patchstack
8.1 High Eldon Plugin eldon Local File Inclusion No login needed ≤ 1.0 CVE-2025-69057 Patchstack
7.1 High Hotel Listing Plugin hotel-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-69056 Patchstack
7.1 High Super Logos Showcase Plugin superlogoshowcase-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 CVE-2025-69054 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69053 Patchstack
7.1 High ListingPro Reviews Plugin listingpro-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.11 Fixed in 2.9.11 CVE-2025-69051 Patchstack
8.1 High Overworld Plugin overworld Local File Inclusion No login needed ≤ 1.3 CVE-2025-69050 Patchstack
8.1 High Töbel Plugin tobel Local File Inclusion No login needed ≤ 1.6 CVE-2025-69049 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69048 Patchstack
8.1 High MaxShop Plugin sw_maxshop Local File Inclusion No login needed ≤ 3.6.20 CVE-2025-69047 Patchstack
8.1 High iRecco Core Plugin irecco-core Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69046 Patchstack
8.5 High FooEvents for WooCommerce Plugin fooevents SQL Injection ≤ 1.20.4 Fixed in 1.20.5 CVE-2025-69045 Patchstack
8.1 High Vango Plugin vango Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69044 Patchstack
8.1 High Rashy Plugin rashy Local File Inclusion No login needed ≤ 1.1.3 CVE-2025-69043 Patchstack
8.1 High Lindo Plugin lindo Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69042 Patchstack
8.1 High Dekoro Plugin dekoro Local File Inclusion No login needed ≤ 1.0.7 CVE-2025-69041 Patchstack
8.1 High Bfres Plugin bfres Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-69040 Patchstack
8.1 High Bailly Plugin bailly Local File Inclusion No login needed ≤ 1.3.4 CVE-2025-69039 Patchstack
8.1 High Hyori Plugin hyori Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69038 Patchstack
8.1 High Pippo Plugin pippo Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-69037 Patchstack
8.8 High Tech Life CPT Plugin techlife-cpt PHP Object Injection ≤ 16.4 CVE-2025-69036 Patchstack
8.8 High Dental Care CPT Plugin dentalcare-cpt PHP Object Injection ≤ 20.2 CVE-2025-69035 Patchstack
8.1 High Search & Go Plugin search-and-go Local File Inclusion No login needed ≤ 2.8 CVE-2025-69005 Patchstack
8.1 High Bajaar - Highly Customizable WooCommerce Theme bajaar Local File Inclusion Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-69004 Patchstack
7.1 High KenthaRadio Plugin qt-kentharadio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2025-69003 Patchstack
8.8 High OneLife Plugin onelife PHP Object Injection ≤ 3.9 CVE-2025-69002 Patchstack
8.5 High Happy Addons for Elementor Plugin happy-elementor-addons SQL Injection ≤ 3.20.4 Fixed in 3.20.6 CVE-2025-68999 Patchstack
7.5 High Miion Plugin miion Local File Inclusion ≤ 1.2.7 CVE-2025-68913 Patchstack
8.6 High HDForms Plugin hdforms Arbitrary File Deletion No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-68912 Patchstack
8.1 High Barberry Plugin barberry Local File Inclusion No login needed ≤ 2.9.9.87 CVE-2025-68908 Patchstack
7.5 High Hostme v2 Plugin hostmev2 Arbitrary File Deletion No login needed ≤ 7.0 CVE-2025-68907 Patchstack
7.1 High JNews - Video Plugin jnews-video Cross-Site Scripting Video plugin <= 11.0.2 - Reflected Cross Site Scripting (XSS) No login needed ≤ 11.0.2 CVE-2025-68906 Patchstack
7.5 High JNews - Pay Writer Plugin jnews-pay-writer Local File Inclusion Pay Writer plugin <= 11.0.0 - Local File Inclusion ≤ 11.0.0 CVE-2025-68905 Patchstack
7.1 High JNews - Frontend Submit Plugin jnews-frontend-submit Cross-Site Scripting Frontend Submit plugin <= 11.0.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 11.0.0 CVE-2025-68904 Patchstack
8.8 High Anona Plugin anona PHP Object Injection ≤ 8.0 CVE-2025-68903 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only