WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,351–2,400 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 48 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Lione Theme lione Local File Inclusion No login needed ≤ 1.16 CVE-2025-58950 Patchstack
8.1 High Spock Theme spock Local File Inclusion No login needed ≤ 1.17 CVE-2025-58949 Patchstack
8.1 High Aromatica Theme aromatica Local File Inclusion No login needed ≤ 1.8 CVE-2025-58948 Patchstack
8.1 High Athos Theme athos Local File Inclusion No login needed ≤ 1.9 CVE-2025-58947 Patchstack
8.1 High Vocal Theme vocal Local File Inclusion No login needed ≤ 1.12 CVE-2025-58946 Patchstack
8.1 High EcoGrow Theme ecogrow Local File Inclusion No login needed ≤ 1.7 CVE-2025-58945 Patchstack
8.1 High Manufactory Theme manufactory Local File Inclusion No login needed ≤ 1.4 CVE-2025-58944 Patchstack
8.1 High Agricola Theme agricola Local File Inclusion No login needed ≤ 1.1.0 CVE-2025-58943 Patchstack
8.1 High Dwell Theme dwell Local File Inclusion No login needed ≤ 1.7.0 CVE-2025-58942 Patchstack
8.1 High Fabric Theme fabric Local File Inclusion No login needed ≤ 1.5.0 CVE-2025-58941 Patchstack
8.1 High Basil Theme basil Local File Inclusion No login needed ≤ 1.3.12 CVE-2025-58940 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-58938 Patchstack
8.1 High Tacticool Theme tacticool Local File Inclusion No login needed ≤ 1.0.13 CVE-2025-58937 Patchstack
8.1 High Catamaran Theme catamaran Local File Inclusion No login needed ≤ 1.15 CVE-2025-58936 Patchstack
8.1 High Lunna Theme lunna Local File Inclusion No login needed ≤ 1.15 CVE-2025-58935 Patchstack
8.1 High The Gig Theme thegig Local File Inclusion No login needed ≤ 1.18.0 CVE-2025-58934 Patchstack
8.1 High Anubis Theme anubis Local File Inclusion No login needed ≤ 1.25 CVE-2025-58933 Patchstack
8.1 High Prisma Theme prisma Local File Inclusion No login needed ≤ 1.10 CVE-2025-58932 Patchstack
8.1 High Palatio Theme palatio Local File Inclusion No login needed ≤ 1.6 CVE-2025-58931 Patchstack
8.1 High FitFlex Theme fitflex Local File Inclusion No login needed ≤ 1.6 CVE-2025-58930 Patchstack
8.1 High Pantry Theme pantry Local File Inclusion No login needed ≤ 1.4 CVE-2025-58929 Patchstack
8.1 High Heart Theme heart Local File Inclusion No login needed ≤ 1.8 CVE-2025-58928 Patchstack
8.1 High Stallion Theme stallion Local File Inclusion No login needed ≤ 1.17 CVE-2025-58927 Patchstack
8.1 High Cerebrum Theme cerebrum Local File Inclusion No login needed ≤ 1.12 CVE-2025-58926 Patchstack
8.1 High Neptunus Theme neptunus Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-58925 Patchstack
8.1 High Critique Theme critique Local File Inclusion No login needed ≤ 1.17 CVE-2025-58923 Patchstack
8.1 High Takeout Theme takeout Local File Inclusion No login needed ≤ 1.3.0 CVE-2025-58901 Patchstack
8.1 High UniTravel Theme unitravel Local File Inclusion No login needed ≤ 1.4.2 CVE-2025-58900 Patchstack
8.1 High Frame Theme frame Local File Inclusion No login needed ≤ 2.4.0 CVE-2025-58899 Patchstack
8.1 High HealthHub Theme healthhub Local File Inclusion No login needed ≤ 1.3.0 CVE-2025-58898 Patchstack
8.1 High Otaku Theme otaku Local File Inclusion No login needed ≤ 1.8.0 CVE-2025-58896 Patchstack
8.1 High Integro Theme integro Local File Inclusion No login needed ≤ 1.8.0 CVE-2025-58895 Patchstack
8.1 High Good Mood Theme good-mood Local File Inclusion No login needed ≤ 1.16 CVE-2025-58894 Patchstack
8.1 High Alright Theme alright Local File Inclusion No login needed ≤ 1.6.1 CVE-2025-58893 Patchstack
8.1 High Tourimo Theme tourimo Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-58892 Patchstack
8.1 High Sanger Theme sanger Local File Inclusion No login needed ≤ 1.24.0 CVE-2025-58891 Patchstack
8.1 High Playful Theme playful Local File Inclusion No login needed ≤ 1.19.0 CVE-2025-58890 Patchstack
8.1 High Towny Theme towny Local File Inclusion No login needed ≤ 1.16 CVE-2025-58889 Patchstack
8.1 High The Flash Theme theflash Local File Inclusion No login needed ≤ 1.15 CVE-2025-58888 Patchstack
8.1 High Pathfinder Theme pathfinder Local File Inclusion No login needed ≤ 1.16 CVE-2025-58885 Patchstack
8.1 High Festy Theme festy Local File Inclusion No login needed ≤ 1.13.0 CVE-2025-58879 Patchstack
7.5 High Javo Core Plugin javo-core Broken Access Control Arbitrary Content Deletion No login needed ≤ 3.0.0.529 CVE-2025-58877 Patchstack
8.1 High Algenix Theme algenix Local File Inclusion No login needed ≤ 1.0 CVE-2025-58803 Patchstack
8.8 High Hotel Listing Plugin hotel-listing Privilege Escalation ≤ 1.4.0 CVE-2025-58710 Patchstack
8.1 High Legacy Theme legacy Local File Inclusion No login needed ≤ 1.9 CVE-2025-58709 Patchstack
8.1 High 777 Theme triple-seven Local File Inclusion No login needed ≤ 1.3 CVE-2025-58708 Patchstack
8.1 High Woo Hoo Theme woohoo Local File Inclusion No login needed ≤ 1.25 CVE-2025-58706 Patchstack
8.1 High Paragon Theme paragon Local File Inclusion No login needed ≤ 1.1 CVE-2025-58225 Patchstack
7.1 High Logtik Plugin logtik Cross-Site Scripting No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-57897 Patchstack
7.2 High PostX Plugin ultimate-post Privilege Escalation ≤ 4.1.35 Fixed in 4.1.36 CVE-2025-55707 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only