WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,451–2,500 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 50 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Stockholm Plugin stockholm Local File Inclusion ≤ 9.14.1 CVE-2025-68068 Patchstack
7.5 High Stockholm Core Plugin stockholm-core Local File Inclusion ≤ 2.4.6 CVE-2025-68067 Patchstack
7.5 High Soledad Theme soledad Local File Inclusion ≤ 8.7.0 CVE-2025-68066 Patchstack
7.5 High Hub Core Plugin hub-core Local File Inclusion < 6.0.2 Fixed in 6.0.2 CVE-2025-68065 Patchstack
7.5 High MinimogWP Theme minimog Local File Inclusion ≤ 3.9.6 CVE-2025-68062 Patchstack
7.5 High EduMall Theme edumall Local File Inclusion ≤ 4.4.7 CVE-2025-68061 Patchstack
8.5 High LBG Zoominoutslider Plugin lbg_zoominoutslider SQL Injection ≤ 5.4.4 Fixed in 5.4.5 CVE-2025-68056 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68055 Patchstack
8.5 High CountDown With Image or Video Background Plugin countdown_with_background SQL Injection ≤ 1.5 CVE-2025-68054 Patchstack
8.5 High xPromoter Plugin top_bar_promoter SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-68053 Patchstack
7.6 High Newsletter Plugin newsletter SQL Injection ≤ 9.0.9 Fixed in 9.1.0 CVE-2025-67999 Patchstack
7.6 High Broken Link Checker Plugin broken-link-checker-seo SQL Injection ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-67962 Patchstack
8.5 High All In One SEO Pack Plugin all-in-one-seo-pack SQL Injection ≤ 4.9.1 Fixed in 4.9.1.1 CVE-2025-67950 Patchstack
7.5 High The7 Elements Plugin dt-the7-core Local File Inclusion ≤ 2.7.11 Fixed in 2.7.12 CVE-2025-63076 Patchstack
7.5 High The7 Plugin dt-the7 Local File Inclusion ≤ 12.8.1.1 Fixed in 12.8.1.1 CVE-2025-63074 Patchstack
7.5 High UDesign Core Plugin u-design-core Local File Inclusion ≤ 4.14.0 CVE-2025-63062 Patchstack
7.5 High Ronneby Theme Core Plugin ronneby-core Local File Inclusion ≤ 1.5.68 CVE-2025-63036 Patchstack
7.1 High New User Approve Plugin new-user-approve Cross-Site Request Forgery No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-63030 Patchstack
7.5 High North - Required Plugin north-plugin Local File Inclusion Required Plugin plugin <= 1.4.2 - Local File Inclusion ≤ 1.4.2 CVE-2025-63003 Patchstack
8.5 High Image&Video FullScreen Background Plugin lbg_fullscreen_fullwidth_slider SQL Injection ≤ 1.6.7 CVE-2025-62093 Patchstack
7.1 High Create Posts & Terms Plugin create-posts-terms Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-49351 Patchstack
7.1 High WP sIFR Plugin wp-sifr Cross-Site Request Forgery No login needed ≤ 0.6.8.1 CVE-2025-49347 Patchstack
7.1 High PDF Creator Lite Plugin pdf-creator-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-49341 Patchstack
7.1 High Rencontre Plugin rencontre Cross-Site Request Forgery No login needed ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67534 Patchstack
7.1 High Themify Portfolio Post Plugin themify-portfolio-post Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-67533 Patchstack
7.5 High Hara Plugin hara Local File Inclusion ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-67532 Patchstack
7.5 High Turitor Theme turitor Local File Inclusion ≤ 1.5.3 Fixed in 1.5.3 CVE-2025-67531 Patchstack
7.5 High Besa Plugin besa Local File Inclusion ≤ 2.3.15 Fixed in 2.3.16 CVE-2025-67530 Patchstack
7.5 High Fashion Theme fashion2 Local File Inclusion ≤ 5.3.0 Fixed in 5.3.0 CVE-2025-67529 Patchstack
7.5 High Urna Plugin urna Local File Inclusion ≤ 2.5.12 Fixed in 2.5.13 CVE-2025-67528 Patchstack
7.5 High Digiqole Theme digiqole Local File Inclusion ≤ 2.2.7 Fixed in 2.2.7 CVE-2025-67527 Patchstack
7.5 High Sailing Theme sailing Local File Inclusion ≤ 4.4.6 Fixed in 4.4.6 CVE-2025-67526 Patchstack
7.5 High ekommart Theme ekommart Local File Inclusion ≤ 4.3.1 Fixed in 4.3.1 CVE-2025-67525 Patchstack
7.5 High Jobmonster Elementor Addon Plugin jobmonster-addon Local File Inclusion ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-67524 Patchstack
7.5 High Exhibz Theme exhibz Local File Inclusion ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-67523 Patchstack
7.5 High Jobmonster Theme noo-jobmonster Local File Inclusion ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-67522 Patchstack
7.5 High Select Core Plugin select-core Local File Inclusion ≤ 2.6 Fixed in 2.6 CVE-2025-67521 Patchstack
7.6 High Media Library Tools Plugin media-library-tools SQL Injection ≤ 1.6.15 Fixed in 1.7.0 CVE-2025-67520 Patchstack
7.6 High Ninja Tables Plugin ninja-tables SQL Injection ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-67519 Patchstack
8.5 High Accordion Slider PRO Plugin accordion_slider_pro SQL Injection ≤ 1.2 Fixed in 1.3 CVE-2025-67518 Patchstack
8.5 High ArtPlacer Widget Plugin artplacer-widget SQL Injection ≤ 2.22.9.2 Fixed in 2.23 CVE-2025-67517 Patchstack
8.5 High Store Locator Plugin agile-store-locator SQL Injection ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-67516 Patchstack
8.8 High Wilmër Plugin wilmer Local File Inclusion ≤ 3.5 Fixed in 3.5 CVE-2025-67515 Patchstack
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id No login needed ≤ 4.95 CVE-2025-7402 Wordfence
8.5 High KiviCare Plugin kivicare-clinic-management-system SQL Injection ≤ 3.6.13 Fixed in 3.6.14 CVE-2025-66095 Patchstack
7.2 High WP Webhooks Plugin wp-webhooks PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66073 Patchstack
7.2 High Email Subscribers & Newsletters Plugin email-subscribers PHP Object Injection ≤ 5.9.10 Fixed in 5.9.11 CVE-2025-66055 Patchstack
7.2 High WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer PHP Object Injection Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import ≤ 7.33.1 CVE-2025-13145 Wordfence
8.8 High Import any XML, CSV or Excel File to WordPress (WP All Import) Plugin wp-all-import Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Conditional Logic ≤ 3.9.6 CVE-2025-12733 Wordfence
7.6 High 0 Day Analytics Plugin 0-day-analytics SQL Injection ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-64293 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only