WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,401–2,450 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 49 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Festy Theme festy Local File Inclusion No login needed ≤ 1.13.0 CVE-2025-58879 Patchstack
7.5 High Javo Core Plugin javo-core Broken Access Control Arbitrary Content Deletion No login needed ≤ 3.0.0.529 CVE-2025-58877 Patchstack
8.1 High Algenix Theme algenix Local File Inclusion No login needed ≤ 1.0 CVE-2025-58803 Patchstack
8.8 High Hotel Listing Plugin hotel-listing Privilege Escalation ≤ 1.4.0 CVE-2025-58710 Patchstack
8.1 High Legacy Theme legacy Local File Inclusion No login needed ≤ 1.9 CVE-2025-58709 Patchstack
8.1 High 777 Theme triple-seven Local File Inclusion No login needed ≤ 1.3 CVE-2025-58708 Patchstack
8.1 High Woo Hoo Theme woohoo Local File Inclusion No login needed ≤ 1.25 CVE-2025-58706 Patchstack
8.1 High Paragon Theme paragon Local File Inclusion No login needed ≤ 1.1 CVE-2025-58225 Patchstack
7.1 High Logtik Plugin logtik Cross-Site Scripting No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-57897 Patchstack
7.2 High PostX Plugin ultimate-post Privilege Escalation ≤ 4.1.35 Fixed in 4.1.36 CVE-2025-55707 Patchstack
7.1 High PostX Plugin ultimate-post Broken Access Control ≤ 4.1.36 Fixed in 4.1.37 CVE-2025-54751 Patchstack
8.1 High Hygia Theme hygia Local File Inclusion No login needed ≤ 1.16 CVE-2025-53453 Patchstack
8.1 High Convex Theme convex Local File Inclusion No login needed ≤ 1.11 CVE-2025-53449 Patchstack
8.1 High Rally Theme rally Local File Inclusion No login needed ≤ 1.1 CVE-2025-53448 Patchstack
8.1 High Assembly Theme assembly Local File Inclusion No login needed ≤ 1.1 CVE-2025-53447 Patchstack
8.1 High Beautique Theme beautique Local File Inclusion No login needed ≤ 1.5 CVE-2025-53446 Patchstack
8.1 High Catwalk Theme catwalk Local File Inclusion No login needed ≤ 1.4 CVE-2025-53445 Patchstack
8.1 High Smash Theme smash Local File Inclusion No login needed ≤ 1.7 CVE-2025-53443 Patchstack
8.1 High Rentic Theme rentic Local File Inclusion No login needed ≤ 1.1 CVE-2025-53442 Patchstack
8.1 High Greeny Theme greeny Local File Inclusion No login needed ≤ 2.6 CVE-2025-53441 Patchstack
8.1 High Harper Theme harper Local File Inclusion No login needed ≤ 1.13 CVE-2025-53439 Patchstack
8.1 High FitLine Theme fitline Local File Inclusion No login needed ≤ 1.6 CVE-2025-53438 Patchstack
8.1 High Greenorganic Plugin greenorganic Local File Inclusion No login needed ≤ 2.45 CVE-2025-53437 Patchstack
8.1 High Monki Plugin monki Local File Inclusion No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-53436 Patchstack
8.1 High Plan My Day Theme planmyday Local File Inclusion No login needed ≤ 1.1.13 CVE-2025-53435 Patchstack
8.1 High ChildHope Theme childhope Local File Inclusion No login needed ≤ 1.1.8 CVE-2025-53434 Patchstack
8.1 High Echo Theme echo Local File Inclusion No login needed ≤ 1.15.0 CVE-2025-53432 Patchstack
8.1 High Emberlyn Theme emberlyn Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-53431 Patchstack
8.1 High Etta Theme etta Local File Inclusion No login needed ≤ 1.14.0 CVE-2025-53430 Patchstack
8.1 High Exit Game Theme exit-game Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-53429 Patchstack
8.1 High Faith & Hope Theme faith-hope Local File Inclusion No login needed ≤ 2.13.0 CVE-2025-52768 Patchstack
8.1 High Farm Agrico Theme farmagrico Local File Inclusion No login needed ≤ 1.3.11 CVE-2025-52745 Patchstack
8.1 High Femme Theme femme Local File Inclusion No login needed ≤ 1.3.11 CVE-2025-49943 Patchstack
8.1 High Gardis Theme gardis Local File Inclusion No login needed ≤ 1.2.13 CVE-2025-49942 Patchstack
8.1 High GlamChic Theme glamchic Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-49941 Patchstack
7.2 High Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Privilege Escalation ≤ 1.2 Fixed in 1.3 CVE-2025-49379 Patchstack
8.1 High Strux Theme strux Local File Inclusion No login needed ≤ 1.9 CVE-2025-49371 Patchstack
8.1 High Lymcoin Theme lymcoin Local File Inclusion No login needed ≤ 1.3.12 CVE-2025-49370 Patchstack
8.1 High Lettuce Theme lettuce Local File Inclusion No login needed ≤ 1.1.7 CVE-2025-49369 Patchstack
8.1 High Palladio Theme palladio Local File Inclusion No login needed ≤ 1.1.10 CVE-2025-49368 Patchstack
8.1 High Monyxi Theme monyxi Local File Inclusion No login needed ≤ 1.1.8 CVE-2025-49367 Patchstack
8.1 High Hanani Theme hanani Local File Inclusion No login needed ≤ 1.2.11 CVE-2025-49366 Patchstack
8.1 High Jack Well Theme jack-well Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-49365 Patchstack
8.1 High Ludos Paradise Theme ludos-paradise Local File Inclusion No login needed ≤ 2.1.3 CVE-2025-49364 Patchstack
8.1 High Kings & Queens Theme kings-queens Local File Inclusion No login needed ≤ 1.1.16 CVE-2025-49363 Patchstack
8.1 High Gracioza Theme gracioza Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-49362 Patchstack
8.1 High Mamita Theme mamita Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-49361 Patchstack
8.1 High Militarology Theme militarology Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-49360 Patchstack
8.1 High ShieldGroup Theme shieldgroup Local File Inclusion No login needed ≤ 2.13 CVE-2025-49359 Patchstack
8.5 High PopupKit Plugin popup-builder-block SQL Injection ≤ 2.1.5 Fixed in 2.2.0 CVE-2025-14314 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only