WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,151–2,200 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 44 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Lobo Theme lobo SQL Injection ≤ 2.8.6 Fixed in 2.8.6 CVE-2025-67921 Patchstack
8.1 High Neo Ocular Theme neoocular Local File Inclusion No login needed ≤ 1.2 Fixed in 1.2 CVE-2025-67920 Patchstack
7.1 High Woffice Plugin woffice Cross-Site Scripting No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67918 Patchstack
7.1 High Jobify Theme jobify Cross-Site Scripting No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2025-67916 Patchstack
8.8 High Timetics Plugin timetics Authentication Bypass Broken Authentication ≤ 1.0.46 Fixed in 1.0.48 CVE-2025-67915 Patchstack
7.7 High VidMov Theme vidmov Path Traversal ≤ 2.3.8 Fixed in 2.3.9 CVE-2025-67914 Patchstack
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
7.1 High CountDown With Image or Video Background Plugin countdown-with-background Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-27002 Patchstack
8.5 High Workreap (theme's plugin) Plugin workreap SQL Injection ≤ 3.3.6 CVE-2025-22728 Patchstack
7.1 High WP Virtual Assistant Plugin virtualassistant Cross-Site Scripting No login needed ≤ 3.1 CVE-2025-22725 Patchstack
7.5 High WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Broken Access Control Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion No login needed ≤ 1.25 CVE-2025-22715 Patchstack
8.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei SQL Injection ≤ 5.4 CVE-2025-22713 Patchstack
8.1 High Typify Plugin typify Local File Inclusion No login needed ≤ 3.0.2 CVE-2025-22712 Patchstack
8.1 High Mitech Plugin mitech Local File Inclusion No login needed ≤ 2.3.4 CVE-2025-22708 Patchstack
8.1 High Moody Plugin tm-moody Local File Inclusion No login needed ≤ 2.7.3 CVE-2025-22707 Patchstack
8.1 High Atlas Plugin atlas Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-22509 Patchstack
8.1 High Navian Theme navian Local File Inclusion No login needed ≤ 1.5.4 CVE-2025-14431 Patchstack
8.1 High Brook Plugin brook Local File Inclusion Agency Business Creative theme <= 2.9.0 - Local File Inclusion No login needed ≤ 2.9.0 CVE-2025-14430 Patchstack
8.1 High AeroLand Plugin aeroland Local File Inclusion No login needed ≤ 1.6.6 CVE-2025-14429 Patchstack
7.5 High Blockons Plugin blockons Broken Access Control No login needed ≤ 1.2.19 CVE-2025-14360 Patchstack
8.1 High Oshine Theme oshin Local File Inclusion No login needed < 7.3.0 Fixed in 7.3.0 CVE-2025-14359 Patchstack
7.5 High REHub Framework Plugin rehub-framework Broken Access Control No login needed ≤ 19.9.5 Fixed in 19.9.9.6 CVE-2025-14358 Patchstack
7.1 High Real Estate Pro Plugin real-estate-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 CVE-2025-13504 Patchstack
7.1 High ListingHub Plugin listinghub Cross-Site Scripting No login needed ≤ 1.2.6 CVE-2025-12551 Patchstack
8.1 High OchaHouse Theme ochahouse Local File Inclusion No login needed ≤ 2.2.8 CVE-2025-12550 Patchstack
8.1 High Rozy - Flower Shop Theme rozy Local File Inclusion Flower Shop theme <= 1.2.25 - Local File Inclusion No login needed ≤ 1.2.25 CVE-2025-12549 Patchstack
7.1 High WidgetKit Pro Plugin widgetkit-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.1 CVE-2025-46494 Patchstack
7.1 High DZS Video Gallery Plugin dzs-videogallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.25 CVE-2025-32300 Patchstack
8.8 High WPCHURCH Plugin church-management Privilege Escalation ≤ 2.7.0 CVE-2025-31643 Patchstack
8.1 High Gecko Theme gecko Local File Inclusion No login needed ≤ 1.9.8 CVE-2025-69080 Patchstack
8.1 High Hope Theme charity-is-hope Local File Inclusion No login needed ≤ 3.0.0 CVE-2025-69081 Patchstack
7.1 High Arlo Plugin arlo Cross-Site Scripting No login needed ≤ 6.0.3 CVE-2025-69082 Patchstack
7.1 High WPCHURCH Plugin church-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.0 CVE-2025-31642 Patchstack
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
8.8 High Premium Age Verification / Restriction Plugin age-restriction Privilege Escalation Privilege Escalation Vulnerability in AA-Team WordPress plugins ≤ 3.0.2, ≤ 3.0 CVE-2025-29004 Patchstack
8.1 High WPCHURCH Plugin church-management Local File Inclusion No login needed ≤ 2.7.0 CVE-2025-32304 Patchstack
7.1 High Header Image Slider Plugin header-image-slider Cross-Site Scripting No login needed ≤ 0.3 CVE-2024-30547 Patchstack
8.8 High DZS Video Gallery Plugin dzs-videogallery PHP Object Injection ≤ 12.25 CVE-2025-47553 Patchstack
8.1 High Frappé Plugin frappe Local File Inclusion No login needed ≤ 1.8 CVE-2025-69083 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69356 Patchstack
8.5 High Ninja Tables Plugin ninja-tables SQL Injection ≤ 5.2.4 Fixed in 5.2.5 CVE-2025-69351 Patchstack
7.5 High Calafate Theme calafate Local File Inclusion ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-69342 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.26 Fixed in 2.7.7.27 CVE-2025-69084 Patchstack
7.1 High JobBank Plugin jobbank Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-69085 Patchstack
8.1 High Issabella Theme issabella Local File Inclusion No login needed ≤ 1.1.2 CVE-2025-69086 Patchstack
7.5 High LoginWP - Pro Plugin loginwp-pro Broken Access Control Pro Plugin <= 4.0.8.5 - Settings Change No login needed ≤ 4.0.8.5 Fixed in 4.0.8.6 CVE-2025-46255 Patchstack
7.1 High iPhone Webclip Manager Plugin iphone-webclip-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5 CVE-2024-53735 Patchstack
7.5 High Booking Package Plugin booking-package Price Manipulation No login needed ≤ 1.6.27 Fixed in 1.6.29 CVE-2024-30516 Patchstack
7.1 High Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30461 Patchstack
7.1 High Machic Core Plugin machic-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6 CVE-2023-49186 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only