WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,701–2,750 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 55 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP-Click-Tracker Plugin wp-click-track Cross-Site Scripting No login needed ≤ 0.7.3 CVE-2025-49954 Patchstack
7.1 High ShareBang, Ultimate Social Share Buttons Plugin sharebang Cross-Site Scripting No login needed ≤ 1.4 CVE-2025-49953 Patchstack
7.1 High gAppointments Plugin gappointments Cross-Site Scripting No login needed ≤ 1.14.1 CVE-2025-49951 Patchstack
7.2 High Official Integration for Billingo Plugin billingo Privilege Escalation ≤ 4.3.0 CVE-2025-49950 Patchstack
7.1 High WP Super Edit Plugin wp-super-edit Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2025-49948 Patchstack
7.1 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Cross-Site Scripting Custom Signup Fields plugin <= 3.2.3 - Cross Site Scripting (XSS) No login needed ≤ 3.2.3 CVE-2025-49947 Patchstack
7.1 High Auto Login After Registration Plugin auto-login-after-registration Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-49946 Patchstack
7.1 High Shortcode Generator Plugin shortcode-generator Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-49945 Patchstack
7.1 High WPCode Content Ratio Plugin wpcode-content-ratio Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-49944 Patchstack
7.5 High WoodMart Theme woodmart Local File Inclusion ≤ 8.3.2 Fixed in 8.3.2 CVE-2025-49935 Patchstack
7.1 High JetSearch Plugin jet-search Cross-Site Scripting No login needed ≤ 3.5.10 Fixed in 3.5.10.1 CVE-2025-49930 Patchstack
7.2 High Kalium Theme kalium Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.25 Fixed in 3.26 CVE-2025-49926 Patchstack
7.5 High WPLMS Plugin wplms_plugin Broken Access Control No login needed ≤ 1.9.9.7 Fixed in 1.9.9.8 CVE-2025-49925 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.4.2 Fixed in 2.2.5 CVE-2025-49924 Patchstack
7.5 High JetReviews Plugin jet-reviews Local File Inclusion ≤ 3.0.0 Fixed in 3.0.0.1 CVE-2025-49921 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
7.1 High WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder Cross-Site Scripting No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49911 Patchstack
8.2 High WPGuppy Plugin wpguppy-lite Broken Access Control No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-49910 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49378 Patchstack
7.5 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Local File Inclusion No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-48338 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.1.8.8 Fixed in 5.1.8.9 CVE-2025-48098 Patchstack
7.1 High WSAnalytics Plugin wsanalytics-google-analytics-and-dashboards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-48097 Patchstack
7.1 High Password only login Plugin password-only-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-48093 Patchstack
7.1 High Fix Multiple Redirects Plugin fix-multiple-redirects Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-48092 Patchstack
8.5 High AnyComment Plugin anycomment SQL Injection ≤ 0.3.6 CVE-2025-48091 Patchstack
8.8 High Progress Planner Plugin progress-planner Privilege Escalation ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-48082 Patchstack
7.1 High Terms Dictionary Plugin terms-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-39534 Patchstack
7.5 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion ≤ 2.1.7 CVE-2025-32657 Patchstack
8.8 High Solar Energy Theme solar PHP Object Injection ≤ 3.5 CVE-2025-32283 Patchstack
8.8 High Insurance Theme insurance PHP Object Injection ≤ 3.5 CVE-2025-31634 Patchstack
7.5 High Tablesome Table Premium Plugin tablesome-premium Broken Access Control No login needed ≤ 1.1.23 CVE-2025-30944 Patchstack
7.2 High Find And Replace content Plugin find-and-replace-content Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-10313 Wordfence
7.3 High Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity Theme Privilege Escalation Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthenticated Privilege Escalation to Editor No login needed ≤ 1.4.0 CVE-2025-6042 Wordfence
8.8 High Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity Theme Privilege Escalation Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 1.4.0 CVE-2025-6038 Wordfence
8.1 High Bei Fen – WordPress Backup Plugin bei-fen Local File Inclusion WordPress Backup Plugin <= 1.4.2 - Authenticated (Subscriber+) Local File Inclusion No login needed ≤ 1.4.2 CVE-2025-9993 Wordfence
7.1 High GST for WooCommerce Plugin gst-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-60173 Patchstack
7.1 High Flytedesk Digital Plugin flytedesk-digital Cross-Site Request Forgery No login needed ≤ 20181101 CVE-2025-60172 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High HTACCESS IP Blocker Plugin htaccess-ip-blocker Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-60170 Patchstack
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
7.1 High NewsmanApp Plugin newsmanapp Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 3.0.0 CVE-2025-60164 Patchstack
7.5 High Subscribe To Unlock Plugin subscribe-to-unlock Local File Inclusion ≤ 1.1.5 CVE-2025-60153 Patchstack
7.5 High Subscribe to Download Plugin subscribe-to-download Local File Inclusion ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60150 Patchstack
8.8 High Testimonial Slider Plugin testimonial-add Local File Inclusion ≤ 3.5.8.6 CVE-2025-60126 Patchstack
8.5 High PGS Core Plugin pgs-core SQL Injection ≤ 5.9.0 CVE-2025-60118 Patchstack
8.8 High Javo Core Plugin javo-core Cross-Site Request Forgery No login needed ≤ 3.0.0.266 CVE-2025-60111 Patchstack
8.5 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator SQL Injection Banner Rotator Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60110 Patchstack
8.5 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider SQL Injection AllInOne - Content Slider Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60109 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner SQL Injection AllInOne - Banner with Thumbnails Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60108 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist SQL Injection AllInOne - Banner with Playlist Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60107 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only