WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,001–3,050 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 61 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP Links Page Plugin wp-links-page SQL Injection ≤ 4.9.6 Fixed in 5.0 CVE-2025-30998 Patchstack
7.5 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32288 Patchstack
7.5 High WP Lead Capturing Pages Plugin leadcapture Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31425 Patchstack
8.5 High Pinterest Automatic Pin Plugin wp-pinterest-automatic SQL Injection ≤ 4.19.0 Fixed in 4.19.0 CVE-2025-39510 Patchstack
7.2 High Content Egg Plugin content-egg PHP Object Injection ≤ 7.0.0 Fixed in 8.0.0 CVE-2025-47536 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-47689 Patchstack
7.5 High Gutenberg Blocks Plugin advanced-gutenberg Local File Inclusion No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-48332 Patchstack
8.1 High Premium Addons for KingComposer Plugin premium-addons-for-kingcomposer Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-49036 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.3 Fixed in 5.9.5.4 CVE-2025-49033 Patchstack
7.1 High WP Dynamic Links Plugin wp-dynamic-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-49038 Patchstack
7.1 High Authentication and xmlrpc log writer Plugin authentication-and-xmlrpc-log-writer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-49037 Patchstack
7.1 High Simple Poll Plugin simple-poll Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-49044 Patchstack
7.1 High Time Sheets Plugin time-sheets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.3 CVE-2025-49054 Patchstack
7.1 High 多说社会化评论框 Plugin duoshuo Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-49056 Patchstack
7.1 High SoundSt SEO Search Plugin soundst-seo-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-49058 Patchstack
7.1 High WP Voting Plugin wp-voting Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-49057 Patchstack
7.1 High BaiduXZH Submit(百度熊掌号) Plugin i3geek-baiduxzh Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-49063 Patchstack
7.1 High WP-jScrollPane Plugin wp-jscrollpane Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-49062 Patchstack
7.1 High Visit Counter Plugin visit-counter Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49065 Patchstack
7.1 High User Language Switch Plugin user-language-switch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.10 CVE-2025-49064 Patchstack
8.5 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element SQL Injection ≤ 3.28.3 Fixed in 3.28.5 CVE-2025-49267 Patchstack
7.5 High Cloud SAML SSO - Single Sign On Login Plugin cloud-sso-single-sign-on Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-49264 Patchstack
7.5 High GravityWP - Merge Tags Plugin gravitywp-merge-tags Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-49271 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.0.31 Fixed in 4.0.32 CVE-2025-49869 Patchstack
7.5 High WP REST Cache Plugin wp-rest-cache Local File Inclusion No login needed ≤ 2025.1.0 Fixed in 2025.1.1 CVE-2025-52716 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.0 Fixed in 15.1 CVE-2025-52728 Patchstack
7.5 High Event Manager, Event Calendar and Booking Plugin eventin-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52731 Patchstack
7.1 High Project Cost Calculator Plugin project-cost-calculator Broken Access Control ≤ 1.0.0 CVE-2025-52775 Patchstack
8.8 High GMap Targeting Plugin gmap-targeting Local File Inclusion ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-52732 Patchstack
7.1 High SMM API Plugin smm-api Broken Access Control ≤ 6.0.31 CVE-2025-52785 Patchstack
7.3 High The E-Commerce ERP Plugin profitori Broken Access Control No login needed ≤ 2.1.1.3 CVE-2025-52800 Patchstack
7.1 High CaptionPix Plugin captionpix Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-52788 Patchstack
7.5 High JobSearch Plugin wp-jobsearch Local File Inclusion ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-52806 Patchstack
7.3 High TheBooking Plugin thebooking Broken Access Control No login needed ≤ 1.4.4 CVE-2025-52801 Patchstack
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
8.5 High Cube Portfolio Plugin cubeportfolio SQL Injection ≤ 1.16.8 CVE-2025-52823 Patchstack
8.8 High Post SMTP Plugin post-smtp Privilege Escalation Account Takeover ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-24000 Patchstack
7.2 High Use-your-Drive | Google Drive Plugin Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed ≤ 3.3.1 CVE-2025-7050 Wordfence
7.5 High MinimogWP – The High Converting eCommerce Theme Price Manipulation The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation No login needed ≤ 3.9.0 CVE-2025-8198 Wordfence
8.8 High WPLMS Learning Management System for WordPress, WordPress LMS Theme Privilege Escalation ≤ 1.8.4.1 CVE-2015-10139 Wordfence
8.8 High School Management System Plugin wpschoolpress Local File Inclusion Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 93.1.0 CVE-2025-3740 Wordfence
7.5 High Easy Video Player Wordpress & WooCommerce Plugin fwdevp Path Traversal Arbitrary File Download No login needed ≤ 10.0 CVE-2025-28955 Patchstack
8.8 High Yogi Plugin yogi PHP Object Injection ≤ 2.9.3 Fixed in 2.9.3 CVE-2025-24779 Patchstack
8.8 High Hillter Theme hillter PHP Object Injection ≤ 3.0.7 CVE-2025-24777 Patchstack
8.6 High URL Shortener Plugin exact-links Broken Access Control No login needed ≤ 3.0.7 CVE-2025-28965 Patchstack
7.5 High Multi-language Responsive Contact Form Plugin responsive-contact-form Broken Access Control No login needed ≤ 2.8 CVE-2025-29000 Patchstack
7.1 High ListingEasy Plugin listingeasy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2025-30955 Patchstack
7.1 High Electrician - Electrical Service Plugin electrician Cross-Site Scripting Electrical Service WordPress theme <= 1.0 - Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-31055 Patchstack
7.1 High Ofiz - WordPress Business Consulting Plugin ofiz Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31072 Patchstack
7.5 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg-cleverbakery Path Traversal WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download No login needed ≤ 2.5 Fixed in 2.5.3 CVE-2025-31070 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only