WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,301–2,350 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 47 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64213 Patchstack
7.5 High Masterstudy Theme masterstudy Broken Access Control No login needed ≤ 4.8.122 Fixed in 4.8.122 CVE-2025-64209 Patchstack
7.1 High Jannah Plugin jannah Cross-Site Scripting No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64207 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64205 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting No login needed ≤ 4.1.14 Fixed in 4.1.14 CVE-2025-64203 Patchstack
7.5 High XStore Theme xstore Local File Inclusion ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64193 Patchstack
7.1 High XStore Theme xstore Cross-Site Scripting No login needed ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64191 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting No login needed ≤ 5.6 Fixed in 5.6 CVE-2025-64189 Patchstack
7.1 High Support Board Plugin supportboard Cross-Site Scripting No login needed ≤ 3.8.7 Fixed in 3.8.7 CVE-2025-60182 Patchstack
8.1 High Inset Plugin inset Local File Inclusion No login needed ≤ 1.18.0 CVE-2025-6326 Patchstack
7.1 High Easy Invoice Plugin easy-invoice Cross-Site Scripting No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-6324 Patchstack
7.5 High WP Voting Contest Plugin wp-voting-contest Broken Access Control No login needed ≤ 5.8 CVE-2025-60086 Patchstack
8.8 High PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60084 Patchstack
8.8 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60083 Patchstack
8.8 High PDF for WPForms Plugin pdf-for-wpforms PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60082 Patchstack
8.8 High PDF for Contact Form 7 Plugin pdf-for-contact-form-7 PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60081 Patchstack
7.5 High PDF for Gravity Forms + Drag And Drop Template Builder Plugin pdf-for-gravity-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60080 Patchstack
7.1 High Parallax Section block Plugin parallax-section Authentication Bypass Broken Authentication ≤ 1.0.9 Fixed in 2.0.0 CVE-2025-60079 Patchstack
7.5 High Task Manager Plugin task-manager Local File Inclusion ≤ 3.0.2 CVE-2025-60078 Patchstack
7.5 High YayPricing Plugin yaypricing Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-60077 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2025-60076 Patchstack
8.1 High Anchor smooth scroll Plugin anchor-smooth-scroll Local File Inclusion No login needed ≤ 1.0.2 CVE-2025-60072 Patchstack
8.1 High Riode Plugin riode Local File Inclusion No login needed ≤ 1.6.23 CVE-2025-60071 Patchstack
8.1 High MinimogWP Theme minimog Local File Inclusion No login needed ≤ 3.9.6 CVE-2025-60069 Patchstack
8.1 High Giardino Theme giardino Local File Inclusion No login needed ≤ 1.1.10 CVE-2025-60067 Patchstack
8.1 High Katelyn Theme katelyn Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60066 Patchstack
8.1 High Pinevale Theme pinevale Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-60065 Patchstack
8.1 High Renewal Theme renewal Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-60064 Patchstack
8.1 High Rosalinda Theme rosalinda Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-60063 Patchstack
8.1 High Kicker Theme kicker Local File Inclusion No login needed ≤ 2.2.0 CVE-2025-60061 Patchstack
8.1 High Pubzinne Theme pubzinne Local File Inclusion No login needed ≤ 1.0.12 CVE-2025-60060 Patchstack
8.1 High smart SEO Theme smartseo Local File Inclusion No login needed ≤ 2.12 CVE-2025-60059 Patchstack
8.1 High DetailX Theme detailx Local File Inclusion No login needed ≤ 1.10.0 CVE-2025-60058 Patchstack
8.1 High DJ Rainflow Theme dj-rainflow Local File Inclusion No login needed ≤ 1.3.13 CVE-2025-60057 Patchstack
8.1 High Winger Theme winger Local File Inclusion No login needed ≤ 1.0.16 CVE-2025-60056 Patchstack
8.1 High Fabrica Theme fabrica Local File Inclusion No login needed ≤ 1.8.1 CVE-2025-60055 Patchstack
8.1 High OnLeash Theme onleash Local File Inclusion No login needed ≤ 1.5.2 CVE-2025-60054 Patchstack
8.1 High MaxCube Theme maxcube Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-60053 Patchstack
8.1 High W&D Theme wd Local File Inclusion No login needed ≤ 1.0 CVE-2025-60052 Patchstack
8.1 High Rare Radio Theme rareradio Local File Inclusion No login needed ≤ 1.0.15.1 CVE-2025-60051 Patchstack
8.1 High Panda Theme panda Local File Inclusion No login needed ≤ 1.21 CVE-2025-60050 Patchstack
8.1 High Soleil Theme soleil Local File Inclusion No login needed ≤ 1.17 CVE-2025-60049 Patchstack
8.1 High Tripster Theme tripster Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60048 Patchstack
8.1 High IPharm Theme ipharm Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-60047 Patchstack
8.1 High HeartStar Theme heartstar Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-60046 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.11 CVE-2025-60045 Patchstack
8.1 High Fribbo Theme fribbo Local File Inclusion No login needed ≤ 1.1.0 CVE-2025-60044 Patchstack
8.1 High Wanderic Theme wanderic Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60043 Patchstack
8.1 High Chinchilla Theme chinchilla Local File Inclusion No login needed ≤ 1.16 CVE-2025-60042 Patchstack
8.8 High Sale! Immigration law, Visa services support, Migration Agent Consulting Plugin immiex Privilege Escalation ≤ 1.5.8 CVE-2025-59134 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only