WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,951–3,000 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 60 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg_universal_video_player_addon_visual_composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-53562 Patchstack
7.1 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg_radio_player_addon_visual_composer Cross-Site Scripting WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.5.2 CVE-2025-53564 Patchstack
7.1 High Youtube Vimeo Video Player and Slider Plugin video_player_youtube_vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-53563 Patchstack
8.1 High Ghost Kit Plugin ghostkit Local File Inclusion No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-53567 Patchstack
8.1 High Widget for Google Reviews Plugin business-reviews-wp Local File Inclusion No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-53565 Patchstack
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-54007 Patchstack
7.2 High Welcart e-Commerce Plugin usc-e-shop PHP Object Injection ≤ 2.11.16 Fixed in 2.11.17 CVE-2025-54012 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions Local File Inclusion No login needed ≤ 2.15.4 Fixed in 2.15.5 CVE-2025-54017 Patchstack
7.5 High Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download No login needed ≤ 6.1.14 Fixed in 6.1.15 CVE-2025-54021 Patchstack
7.1 High Support Board Plugin supportboard Cross-Site Scripting No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-54027 Patchstack
7.5 High CF7 WOW Styler Plugin cf7-styler Local File Inclusion No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-54028 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting No login needed ≤ 12.7.3 Fixed in 12.7.4 CVE-2025-54032 Patchstack
8.1 High Support Board Plugin supportboard Local File Inclusion No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-54031 Patchstack
7.5 High Newsletters Plugin newsletters-lite Local File Inclusion No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-54034 Patchstack
7.1 High Elite Video Player Plugin elite-video-player Cross-Site Scripting No login needed ≤ 10.0.5 Fixed in 10.0.7 CVE-2025-54044 Patchstack
7.5 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Local File Inclusion No login needed ≤ 5.0.0 Fixed in 5.0.1 CVE-2025-54052 Patchstack
7.1 High Druco Plugin druco Cross-Site Scripting No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54055 Patchstack
7.1 High oik Plugin oik Cross-Site Scripting No login needed ≤ 4.15.2 Fixed in 4.15.3 CVE-2025-54670 Patchstack
7.1 High Responsive HTML5 Audio Player PRO With Playlist Plugin lbg-audio2-html5 Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2025-54056 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.11.1 Fixed in 3.12.0 CVE-2025-54750 Patchstack
8.8 High CubeWP Plugin cubewp-framework Privilege Escalation ≤ 1.1.24 Fixed in 1.1.25 CVE-2025-54735 Patchstack
7.5 High Otter - Gutenberg Block Plugin otter-blocks Information Disclosure Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-55715 Patchstack
8.8 High Real Spaces - WordPress Properties Directory Theme Privilege Escalation WordPress Properties Directory Theme <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member' ≤ 3.5 CVE-2025-8218 Wordfence
8.8 High WPGYM - Wordpress Gym Management System Plugin Local File Inclusion Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 67.7.0 CVE-2025-3671 Wordfence
7.5 High School Management System Plugin wpschoolpress SQL Injection Unauthenticated SQL Injection No login needed ≤ 93.2.0 CVE-2024-12612 Wordfence
7.6 High Dropshix Plugin dropshipping-xox Cross-Site Scripting ≤ 4.0.14 CVE-2025-49898 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
7.1 High NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52765 Patchstack
8.2 High StoryMap Plugin wp-storymap Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-52797 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Request Forgery No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-53575 Patchstack
8.8 High Findgo Plugin findgo Cross-Site Request Forgery No login needed ≤ 1.3.57 Fixed in 1.3.58 CVE-2025-53587 Patchstack
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.2.4 Fixed in 10.2.5 CVE-2025-55708 Patchstack
8.1 High Unicamp Plugin unicamp Local File Inclusion No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2025-54701 Patchstack
8.1 High Makeaholic Plugin makeaholic Local File Inclusion No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54700 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-54697 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.9.0 Fixed in 3.0.0 CVE-2025-54692 Patchstack
8.1 High Xinterio Plugin xinterio Local File Inclusion No login needed ≤ 4.2 Fixed in 4.3 CVE-2025-54690 Patchstack
8.1 High Urna Plugin urna Local File Inclusion No login needed ≤ 2.5.7 Fixed in 2.5.8 CVE-2025-54689 Patchstack
7.5 High Neon Channel Product Customizer Free Plugin neon-channel-product-customizer-free Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-54679 Patchstack
7.5 High CSS & JavaScript Toolbox Plugin css-javascript-toolbox Local File Inclusion ≤ 12.0.3 Fixed in 12.0.3 CVE-2025-3703 Patchstack
7.5 High News Magazine X Plugin news-magazine-x Local File Inclusion No login needed ≤ 1.2.37 Fixed in 1.2.38 CVE-2025-24766 Patchstack
8.1 High VidMov Theme vidmov Local File Inclusion No login needed ≤ 1.9.4 CVE-2025-25172 Patchstack
7.1 High Alike - WordPress Custom Post Comparison Plugin alike Cross-Site Scripting WordPress Custom Post Comparison <= 3.0.1 - Cross Site Scripting (XSS) No login needed ≤ 3.0.1 CVE-2025-28975 Patchstack
8.1 High WP Pipes Plugin wp-pipes Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-28979 Patchstack
7.1 High WooCommerce Shop Page Builder Plugin dzs-wootable Cross-Site Scripting No login needed ≤ 2.27.7 CVE-2025-28999 Patchstack
7.1 High FoodMenu Plugin dzs-restaurantmenu Cross-Site Scripting No login needed ≤ 1.20 CVE-2025-29014 Patchstack
8.1 High IDonatePro Plugin idonate-pro Local File Inclusion No login needed ≤ 2.1.9 CVE-2025-30635 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-30626 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-30639 Patchstack
7.1 High Billplz Addon for Contact Form 7 Plugin billplz-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-31007 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only