WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,251–2,300 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 46 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Content Grid Slider Plugin content-grid-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-68879 Patchstack
7.6 High Integration for Contact Form 7 HubSpot Plugin cf7-hubspot SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-68590 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.2.2 Fixed in 3.3.0 CVE-2025-68570 Patchstack
8.1 High Docket Cache Plugin docket-cache Local File Inclusion No login needed ≤ 24.07.03 Fixed in 24.07.04 CVE-2025-68506 Patchstack
7.2 High Icegram Express Pro Plugin email-subscribers-premium PHP Object Injection ≤ 5.9.14 Fixed in 5.9.14 CVE-2025-68038 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
7.1 High Evergreen Post Tweeter Plugin evergreen-post-tweeter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.8.9 CVE-2025-67622 Patchstack
8.6 High WPJobBoard Plugin wpjobboard SQL Injection Unauth. Blind SQL Injection (SQLi) No login needed ≤ 5.9.0 Fixed in 5.10.1 CVE-2023-36525 Patchstack
7.5 High Userpro Plugin userpro Broken Access Control No login needed ≤ 5.1.9 CVE-2025-68608 Patchstack
7.5 High Subscribe to Unlock Lite Plugin subscribe-to-unlock-lite Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-68563 Patchstack
7.5 High Fana Plugin fana Local File Inclusion ≤ 1.1.35 Fixed in 1.1.36 CVE-2025-68540 Patchstack
7.5 High Zota Plugin zota Local File Inclusion ≤ 1.3.14 Fixed in 1.3.15 CVE-2025-68537 Patchstack
7.5 High Bookory Theme bookory Local File Inclusion ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-68530 Patchstack
8.5 High Brands for WooCommerce Plugin brands-for-woocommerce SQL Injection ≤ 3.8.6.3 Fixed in 3.8.6.4 CVE-2025-68519 Patchstack
7.6 High User Feedback Plugin userfeedback-lite SQL Injection ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-68496 Patchstack
7.5 High PowerPack Pro for Elementor Plugin powerpack-elements Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 2.10.6 Fixed in 2.10.8 CVE-2024-24844 Patchstack
7.5 High Nika Plugin nika Local File Inclusion ≤ 1.2.14 Fixed in 1.2.15 CVE-2025-68546 Patchstack
7.5 High Diza Theme diza Local File Inclusion ≤ 1.3.15 Fixed in 1.3.16 CVE-2025-68544 Patchstack
7.6 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.1.13 Fixed in 1.1.14 CVE-2025-68550 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68560 Patchstack
7.6 High AutomatorWP Plugin automatorwp SQL Injection ≤ 5.2.4 Fixed in 5.2.5 CVE-2025-68561 Patchstack
8.1 High Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update ≤ 2.9.4.1 CVE-2025-12934 Wordfence
7.2 High ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.3.4 CVE-2025-9343 Wordfence
7.5 High Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode ≤ 2.0.2 CVE-2025-14071 Wordfence
7.7 High HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25446 Patchstack
7.1 High Hostel Plugin hostel Cross-Site Scripting No login needed ≤ 1.1.5.9 Fixed in 1.1.6 CVE-2025-66119 Patchstack
7.1 High Sprout Clients Plugin sprout-clients Cross-Site Scripting No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-66118 Patchstack
7.5 High Easy Form Plugin easy-form Broken Access Control No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2025-66117 Patchstack
7.5 High Ultimate Member Widgets for Elementor Plugin ultimate-member-widgets-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-66116 Patchstack
7.1 High FV Antispam Plugin fv-antispam Cross-Site Scripting No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-66102 Patchstack
7.5 High PropertyHive Plugin propertyhive Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66088 Patchstack
7.5 High wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 2.4.10 Fixed in 2.4.11 CVE-2025-66070 Patchstack
7.5 High LearnPress Plugin learnpress Broken Access Control No login needed ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-66054 Patchstack
7.1 High ListingPro Theme listingpro Broken Access Control ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64378 Patchstack
8.1 High ListingPro Theme listingpro Local File Inclusion No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64377 Patchstack
7.1 High ListingPro Theme listingpro Cross-Site Scripting No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64376 Patchstack
8.1 High Traveler Plugin traveler Local File Inclusion No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64373 Patchstack
7.1 High Traveler Plugin traveler Cross-Site Scripting No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64372 Patchstack
8.5 High Traveler Plugin traveler SQL Injection ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64371 Patchstack
7.5 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.44 Fixed in 1.0.45 CVE-2025-64268 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
7.1 High ANAC XML Bandi di Gara Plugin avcp Cross-Site Scripting No login needed ≤ 7.7 Fixed in 7.7.1 CVE-2025-64260 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-64258 Patchstack
7.7 High Filr Plugin filr-protection Arbitrary File Deletion ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-64230 Patchstack
8.1 High PenNews Plugin pennews Local File Inclusion No login needed ≤ 6.7.3 Fixed in 6.7.3 CVE-2025-64223 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
7.1 High Reservation Plugin dt-reservation-plugin Cross-Site Scripting No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64221 Patchstack
7.5 High Passster Plugin content-protector Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.19 Fixed in 4.2.20 CVE-2025-64218 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.2 Fixed in 7.7.4 CVE-2025-64217 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64214 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only