WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,051–2,100 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Anona Plugin anona Path Traversal Arbitrary File Download No login needed ≤ 8.0 CVE-2025-68902 Patchstack
8.6 High Anona Plugin anona Arbitrary File Deletion No login needed ≤ 8.0 CVE-2025-68901 Patchstack
8.8 High Vivagh Plugin vivagh PHP Object Injection ≤ 2.4 CVE-2025-68899 Patchstack
7.1 High ShoutOut Plugin shoutout Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.2 CVE-2025-68894 Patchstack
7.1 High WP Simple Redirect Plugin wp-simple-redirect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-68884 Patchstack
7.1 High bidorbuy Store Integrator Plugin bidorbuystoreintegrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.0 CVE-2025-68883 Patchstack
7.5 High Scalenut Plugin scalenut Broken Access Control No login needed ≤ 1.1.5 CVE-2025-68882 Patchstack
8.5 High AppExperts Plugin appexperts SQL Injection ≤ 1.4.5 CVE-2025-68881 Patchstack
7.1 High Dooodl Plugin dooodl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.0 CVE-2025-68871 Patchstack
7.1 High Dinatur Plugin dinatur Cross-Site Scripting No login needed ≤ 1.18 CVE-2025-68866 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting No login needed ≤ 2.15.11 CVE-2025-68864 Patchstack
7.1 High Syntax Highlighter Compress Plugin syntax-highlighter-compress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.83.3 CVE-2025-68859 Patchstack
7.1 High wpCAS Plugin wpcas Cross-Site Scripting No login needed ≤ 1.07 CVE-2025-68858 Patchstack
7.1 High Quote Master Plugin quote-master Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.1 CVE-2025-68849 Patchstack
7.1 High Easy Theme Options Plugin easy-theme-options Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-68839 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-68838 Patchstack
7.1 High Ravpage Plugin ravpage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.33 CVE-2025-68835 Patchstack
7.1 High Craft Theme craftcoffee Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68538 Patchstack
7.1 High DotLife Theme dotlife Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.5 Fixed in 4.9.5 CVE-2025-68520 Patchstack
7.1 High Hoteller Theme hoteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.8.9 Fixed in 6.8.9 CVE-2025-68518 Patchstack
8.1 High Photography Plugin photography Local File Inclusion No login needed ≤ 7.7.5 Fixed in 7.7.5 CVE-2025-68510 Patchstack
7.6 High Hotel Listing Plugin hotel-listing Broken Access Control ≤ 1.4.2 CVE-2025-68059 Patchstack
7.6 High Institutions Directory Plugin institutions-directory Broken Access Control ≤ 1.3..4 CVE-2025-68058 Patchstack
7.6 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control ≤ 1.3.9 CVE-2025-68057 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-68047 Patchstack
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
7.5 High Tabby Checkout Plugin tabby-checkout Information Disclosure Sensitive Data Exposure No login needed ≤ 5.8.4 Fixed in 5.9.1 CVE-2025-68035 Patchstack
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-68030 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Privilege Escalation No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68027 Patchstack
7.5 High Antideo Email Validator Plugin antideo-email-validator SQL Injection No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2025-68017 Patchstack
7.1 High CodeColorer Plugin codecolorer Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 0.10.1 Fixed in 0.10.2 CVE-2025-68012 Patchstack
7.1 High GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-68011 Patchstack
7.1 High Netgsm Plugin netgsm Cross-Site Scripting No login needed ≤ 2.9.63 Fixed in 2.9.64 CVE-2025-68010 Patchstack
7.1 High WP Mail Plugin wp-mail Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-68008 Patchstack
7.1 High My Post Order Plugin my-posts-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1.1 CVE-2025-68004 Patchstack
7.6 High Lawyer Directory Plugin lawyer-directory Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67967 Patchstack
8.8 High Lawyer Directory Plugin lawyer-directory Privilege Escalation ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67966 Patchstack
7.1 High Homey Core Plugin homey-core Cross-Site Scripting No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67964 Patchstack
8.6 High Movie Booking Plugin movie-booking Arbitrary File Deletion No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-67963 Patchstack
7.1 High WorkScout-Core Plugin workscout-core Cross-Site Scripting No login needed ≤ 1.7.06 Fixed in 1.7.07 CVE-2025-67960 Patchstack
7.1 High WorkScout Plugin workscout Cross-Site Scripting No login needed ≤ 4.1.07 Fixed in 4.1.08 CVE-2025-67959 Patchstack
8.1 High Listivo Core Plugin listivo-core Local File Inclusion No login needed ≤ 2.3.77 Fixed in 2.3.78 CVE-2025-67957 Patchstack
8.2 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 4.4.6 Fixed in 4.4.7 CVE-2025-67956 Patchstack
7.5 High MyHome Core Plugin myhome-core Local File Inclusion ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-67955 Patchstack
8.1 High Booking Activities Plugin booking-activities Privilege Escalation No login needed ≤ 1.16.44 Fixed in 1.16.45 CVE-2025-67953 Patchstack
7.1 High Grand Tour Plugin grandtour Cross-Site Scripting No login needed ≤ 5.6.2 Fixed in 5.6.2 CVE-2025-67952 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 94.3.6 Fixed in 94.3.6 CVE-2025-67949 Patchstack
7.1 High AdForest Elementor Plugin adforest-elementor Cross-Site Scripting No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2025-67947 Patchstack
8.1 High AdForest Theme adforest Local File Inclusion No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2025-67946 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.32 Fixed in 3.6.33 CVE-2025-67943 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only