WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,501–2,550 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 51 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy PHP Object Injection WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' ≤ 3.3.8 CVE-2025-12099 Wordfence
8.1 High Alloggio - Hotel Booking Theme alloggio Local File Inclusion Hotel Booking Theme theme <= 1.8 - Local File Inclusion No login needed ≤ 1.8 CVE-2025-64287 Patchstack
7.1 High Import from YML Plugin import-from-yml Cross-Site Scripting No login needed ≤ 3.1.17 Fixed in 4.0.0 CVE-2025-64232 Patchstack
7.1 High Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-64224 Patchstack
7.1 High Easy Social Share Buttons Plugin easy-social-share-buttons3 Cross-Site Scripting No login needed ≤ 10.7.1 Fixed in 10.7.1 CVE-2025-64198 Patchstack
7.1 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting No login needed ≤ 7.2.5 Fixed in 7.2.6 CVE-2025-64196 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62076 Patchstack
7.5 High Simple Payment Plugin simple-payment Local File Inclusion No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62075 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting No login needed ≤ 11.71 Fixed in 11.72 CVE-2025-62074 Patchstack
8.1 High Savory Plugin savory Local File Inclusion No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-62067 Patchstack
7.5 High Revolution Plugin revolution Local File Inclusion ≤ 2.5.8 Fixed in 2.5.8 CVE-2025-62066 Patchstack
7.1 High SureRank Plugin surerank Cross-Site Scripting No login needed ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-62059 Patchstack
7.1 High Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62057 Patchstack
8.1 High Academist Theme academist Local File Inclusion No login needed ≤ 1.3 Fixed in 1.3 CVE-2025-62055 Patchstack
8.1 High Houzez Plugin houzez Local File Inclusion No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62053 Patchstack
8.1 High TheGem Theme Elements (for WPBakery) Plugin thegem-elements Local File Inclusion No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62045 Patchstack
7.1 High TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62041 Patchstack
7.1 High YOP Poll Plugin yop-poll Cross-Site Scripting No login needed ≤ 6.5.37 Fixed in 6.5.38 CVE-2025-62040 Patchstack
7.5 High AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2025-62039 Patchstack
7.1 High Togo Plugin togo Cross-Site Scripting No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62036 Patchstack
8.8 High Togo Plugin togo PHP Object Injection ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62035 Patchstack
8.8 High Togo Plugin togo Privilege Escalation ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62034 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62031 Patchstack
8.1 High ITok Plugin itok Local File Inclusion No login needed ≤ 1.1.42 Fixed in 1.1.43.1 CVE-2025-62014 Patchstack
8.1 High Famita Plugin famita Local File Inclusion No login needed ≤ 1.54 Fixed in 1.55.1 CVE-2025-62010 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Local File Inclusion ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-60248 Patchstack
7.1 High TableOn Plugin posts-table-filterable Content Injection No login needed ≤ 1.0.5.1 CVE-2025-60244 Patchstack
7.5 High Download Counter Plugin download-counter Path Traversal Arbitrary File Download No login needed ≤ 1.4 CVE-2025-60242 Patchstack
7.5 High Premmerce Plugin premmerce Local File Inclusion No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-60241 Patchstack
7.5 High AnyComment Plugin anycomment Local File Inclusion No login needed ≤ 0.3.6 CVE-2025-60240 Patchstack
8.5 High CoSchool LMS Plugin coschool SQL Injection ≤ 1.4.3 CVE-2025-60239 Patchstack
7.5 High WooCommerce Store Toolkit Plugin woocommerce-store-toolkit Local File Inclusion No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-60204 Patchstack
7.5 High Store Exporter Plugin woocommerce-exporter Local File Inclusion No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2025-60203 Patchstack
7.5 High Favorites Plugin favorites Local File Inclusion No login needed ≤ 2.3.6 CVE-2025-60202 Patchstack
7.5 High WP Customer Area Plugin customer-area Local File Inclusion No login needed ≤ 8.3.5 CVE-2025-60201 Patchstack
7.5 High LearnPress Export Import Plugin learnpress-import-export Local File Inclusion No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2025-60200 Patchstack
8.1 High InHype - Blog & Magazine Plugin inhype Local File Inclusion Blog & Magazine WordPress Theme theme <= 1.5.2 - Local File Inclusion No login needed ≤ 1.5.2 CVE-2025-60199 Patchstack
8.1 High Saxon - Viral Content Blog & Magazine Marketing Plugin saxon Local File Inclusion Viral Content Blog & Magazine Marketing WordPress Theme theme <= 1.9.3 - Local File Inclusion No login needed ≤ 1.9.3 CVE-2025-60198 Patchstack
8.1 High Simple Contact Forms Plugin simple-contact-forms Local File Inclusion No login needed ≤ 1.6.4 CVE-2025-60197 Patchstack
7.5 High Clearblue® Ovulation Calculator Plugin clearblue-ovulation-calculator Local File Inclusion No login needed ≤ 1.2.4 CVE-2025-60196 Patchstack
7.5 High Premmerce Product Search for WooCommerce Plugin premmerce-search Local File Inclusion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-60194 Patchstack
7.5 High Premmerce User Roles Plugin premmerce-user-roles Local File Inclusion No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-60193 Patchstack
7.5 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60192 Patchstack
7.5 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60191 Patchstack
8.1 High Immocaster Plugin immocaster Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-60190 Patchstack
7.5 High PoloPag – Pix Automático para Woocommerce Plugin wc-polo-payments Local File Inclusion Pix Automático para Woocommerce plugin <= 2.0.9 - Local File Inclusion No login needed ≤ 2.0.9 Fixed in 3.0.0 CVE-2025-60189 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60188 Patchstack
7.5 High Lazy Load Optimizer Plugin lazy-load-optimizer Local File Inclusion No login needed ≤ 1.4.7 CVE-2025-60074 Patchstack
7.5 High Responsive Sidebar Plugin responsive-sidebar Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-60073 Patchstack
7.1 High GoStore Plugin gostore Cross-Site Scripting No login needed ≤ 1.6.4 Fixed in 1.6.4 CVE-2025-59556 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only