WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 3,001–3,050 of 9,029 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.3 High | Plugin BlueX for WooCommerce | Broken Access Control No login needed |
≤ 3.1.6 |
CVE-2025-68022 |
Patchstack | |
| 8.8 High | Miraculous Elementor | Authentication Bypass Broken Authentication |
≤ 2.0.7 Fixed in 2.0.8 |
CVE-2025-67998 |
Patchstack | |
| 7.5 High | YayCurrency | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 3.3 Fixed in 3.3.1 |
CVE-2025-67994 |
Patchstack | |
| 8.1 High | PatioTime | Local File Inclusion No login needed |
≤ 2.1 Fixed in 2.1 |
CVE-2025-67992 |
Patchstack | |
| 7.1 High | User Extra Fields | Cross-Site Scripting No login needed |
≤ 16.8 Fixed in 16.9 |
CVE-2025-67991 |
Patchstack | |
| 7.1 High | GMap Targeting | Cross-Site Scripting No login needed |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-67990 |
Patchstack | |
| 8.1 High | CozyStay | Local File Inclusion No login needed |
≤ 1.9.1 Fixed in 1.9.1 |
CVE-2025-67988 |
Patchstack | |
| 8.5 High | Quiz And Survey Master | SQL Injection |
≤ 10.3.1 Fixed in 10.3.2 |
CVE-2025-67987 |
Patchstack | |
| 7.1 High | NPS computy | Cross-Site Scripting No login needed |
≤ 2.8.2 Fixed in 2.8.3 |
CVE-2025-67984 |
Patchstack | |
| 8.1 High | Urna | Local File Inclusion No login needed |
≤ 2.5.12 Fixed in 2.5.13 |
CVE-2025-67982 |
Patchstack | |
| 8.1 High | Besa | Local File Inclusion No login needed |
≤ 2.3.15 Fixed in 2.3.16 |
CVE-2025-67981 |
Patchstack | |
| 8.1 High | Hara | Local File Inclusion No login needed |
≤ 1.2.17 Fixed in 1.2.18 |
CVE-2025-67980 |
Patchstack | |
| 7.1 High | Educare | Cross-Site Scripting No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2025-67978 |
Patchstack | |
| 8.2 High | HAPPY | Broken Access Control No login needed |
≤ 1.0.8 Fixed in 1.0.9 |
CVE-2025-67977 |
Patchstack | |
| 7.5 High | WPLegalPages | Broken Access Control No login needed |
≤ 3.5.4 Fixed in 3.5.5 |
CVE-2025-67974 |
Patchstack | |
| 7.1 High | FluentCart | Cross-Site Scripting No login needed |
≤ 1.3.0 Fixed in 1.3.0 |
CVE-2025-67971 |
Patchstack | |
| 8.1 High | Extensive VC Addons for WPBakery page builder | Local File Inclusion No login needed |
≤ 1.9.1 |
CVE-2025-60087 |
Patchstack | |
| 7.1 High | WP Wizard Cloak | Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-53237 |
Patchstack | |
| 7.1 High | Storyform | Cross-Site Scripting No login needed |
≤ 0.6.14 |
CVE-2025-53233 |
Patchstack | |
| 7.1 High | Easy Taxonomy Images | Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-53231 |
Patchstack | |
| 7.1 High | bbpress Simple Advert Units | Cross-Site Scripting No login needed |
≤ 0.41 |
CVE-2025-53228 |
Patchstack | |
| 7.6 High | AIO WP Builder | Broken Access Control |
≤ 2.0.2 |
CVE-2025-53217 |
Patchstack | |
| 7.7 High | Inpersttion For | Remote Code Execution Arbitrary Code Execution |
≤ 1.0 |
CVE-2025-52744 |
Patchstack | |
| 7.5 High | Airtifact | Local File Inclusion |
≤ 1.2.91 |
CVE-2026-27343 |
Patchstack | |
| 7.5 High | Product Table and List Builder for WooCommerce Lite | SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed |
≤ 4.6.2 |
CVE-2026-2232 |
Wordfence | |
| 7.5 High | wpForo Forum | SQL Injection Unauthenticated Time-Based SQL Injection No login needed |
≤ 2.4.14 |
CVE-2026-1581 |
Wordfence | |
| 7.5 High | Sales Countdown Timer for WooCommerce and | Local File Inclusion |
≤ 1.1.9 Fixed in 1.1.9 |
CVE-2026-27052 |
Patchstack | |
| 7.6 High | Bit Form | SQL Injection |
≤ 2.21.10 Fixed in 2.21.11 |
CVE-2026-25418 |
Patchstack | |
| 7.6 High | Nelio AB Testing | SQL Injection |
≤ 8.2.4 Fixed in 8.2.5 |
CVE-2026-25378 |
Patchstack | |
| 7.5 High | CMSMasters Content Composer | Local File Inclusion |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2026-25326 |
Patchstack | |
| 7.2 High | CartFlows | PHP Object Injection |
≤ 2.1.19 Fixed in 2.2.0 |
CVE-2026-25316 |
Patchstack | |
| 7.6 High | Media Search Enhanced | SQL Injection |
≤ 0.9.1 Fixed in 0.9.2 |
CVE-2026-23805 |
Patchstack | |
| 7.2 High | Smart Auto Upload Images | Server-Side Request Forgery |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2026-23803 |
Patchstack | |
| 7.1 High | CMSMasters Content Composer | Broken Access Control |
≤ 2.5.8 Fixed in 2.5.9 |
CVE-2026-23547 |
Patchstack | |
| 8.8 High | Valenti | PHP Object Injection |
≤ 5.6.3.5 |
CVE-2026-23544 |
Patchstack | |
| 7.5 High | Mail Mint | Broken Access Control No login needed |
≤ 1.19.4 Fixed in 1.19.5 |
CVE-2026-23541 |
Patchstack | |
| 7.2 High | YITH WooCommerce Compare | PHP Object Injection Deserialization of untrusted data |
≤ 3.6.0 Fixed in 3.7.0 |
CVE-2026-22333 |
Patchstack | |
| 7.2 High | WP Customer Reviews | Cross-Site Scripting Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter No login needed |
≤ 3.7.5 |
CVE-2025-14452 |
Wordfence | |
| 8.8 High | Orderable | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation |
≤ 1.20.0 |
CVE-2026-0974 |
Wordfence | |
| 8.8 High | WP AUDIO GALLERY | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation |
≤ 2.0 |
CVE-2025-13603 |
Wordfence | |
| 8.8 High | IDonate | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function |
2.1.5 – 2.1.9 |
CVE-2025-4521 |
Wordfence | |
| 8.8 High | Toret Manager | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update via AJAX actions |
≤ 1.2.7 |
CVE-2026-0912 |
Wordfence | |
| 7.2 High | CTX Feed – WooCommerce Product Feed Manager | Broken Access Control WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation |
≤ 6.6.11 |
CVE-2025-12975 |
Wordfence | |
| 7.2 High | BackWPup | Privilege Escalation Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update |
≤ 5.6.2 |
CVE-2025-15041 |
Wordfence | |
| 8.8 High | Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent | Broken Access Control Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 - 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation |
0.5.4 – 1.2.1 |
CVE-2025-12845 |
Wordfence | |
| 8.8 High | NewsBlogger | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed |
0.2.5.6 – 0.2.5.9 |
CVE-2025-12821 |
Wordfence | |
| 7.5 High | Library Management System | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 3.2.1 |
CVE-2025-12707 |
Wordfence | |
| 7.5 High | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent | Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed |
≤ 4.1.2 |
CVE-2025-11754 |
Wordfence | |
| 8.8 High | Advanced AJAX Product Filters | PHP Object Injection Authenticated (Author+) PHP Object Injection via Live Composer Compatibility |
≤ 3.1.9.6 |
CVE-2026-1426 |
Wordfence | |
| 7.5 High | WPNakama | SQL Injection Unauthenticated SQL Injection via 'order' REST API Parameter No login needed |
≤ 0.6.5 |
CVE-2026-2495 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.