WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,051–3,100 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 62 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Invico - WordPress Consulting Business Plugin invico Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-31427 Patchstack
8.8 High Visual Art | Gallery Plugin visual-arts PHP Object Injection ≤ 2.4 CVE-2025-31422 Patchstack
7.1 High Wordpress Auto Spinner Plugin wp-auto-spinner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.26.0 CVE-2025-46500 Patchstack
8.5 High WPGYM Plugin gym-management SQL Injection ≤ 65.0 CVE-2025-32574 Patchstack
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
7.1 High CSS3 Compare Pricing Tables Plugin css3_web_pricing_tables_grids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.6 Fixed in 11.7 CVE-2025-47554 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 26.0.6 Fixed in 26.0.7 CVE-2025-48291 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13.4 Fixed in 2.13.5 CVE-2025-47652 Patchstack
7.1 High SMu Manual DoFollow Plugin manuall-dofollow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 CVE-2025-49031 Patchstack
7.1 High Contact Form 7 Editor Button Plugin cf7-editor-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-48345 Patchstack
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.10.2 Fixed in 3.11.0 CVE-2025-49034 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49876 Patchstack
7.1 High PW WooCommerce On Sale! Plugin pw-woocommerce-on-sale Broken Access Control ≤ 1.39 Fixed in 1.40 CVE-2025-49888 Patchstack
7.1 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-52777 Patchstack
7.1 High Media Folder Plugin media-folder Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-52786 Patchstack
7.1 High Dot html,php,xml etc pages Plugin dot-htmlphpxml-etc-pages Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-52779 Patchstack
7.5 High Sala Theme sala Broken Access Control No login needed ≤ 1.1.3 CVE-2025-52803 Patchstack
7.1 High Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2025-52787 Patchstack
8.5 High Pakke Envíos Plugin pakke SQL Injection ≤ 1.0.2 CVE-2025-52819 Patchstack
7.5 High Nuss Plugin nuss Broken Access Control No login needed ≤ 1.3.7.1 CVE-2025-52804 Patchstack
7.1 High Import CDN-Remote Images Plugin import-cdn-remote-images Cross-Site Request Forgery No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-48153 Patchstack
7.6 High YaySMTP Plugin smtp-sendinblue SQL Injection ≤ 1.3 Fixed in 1.3.1 CVE-2025-48161 Patchstack
7.6 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid SQL Injection YaySMTP plugin <= 1.5 - SQL Injection ≤ 1.5 Fixed in 1.5.1 CVE-2025-48301 Patchstack
7.6 High YayExtra Plugin yayextra SQL Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48299 Patchstack
7.6 High SMTP for Amazon SES Plugin smtp-amazon-ses SQL Injection ≤ 1.9 Fixed in 1.9.1 CVE-2025-54043 Patchstack
8.5 High GymBase Theme Classes Plugin gymbase_classes SQL Injection ≤ 1.4 Fixed in 1.5 CVE-2025-54026 Patchstack
7.2 High JetFormBuilder Plugin jetformbuilder PHP Object Injection ≤ 3.5.1.2 Fixed in 3.5.2 CVE-2025-53990 Patchstack
8.1 High Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin wp-malware-removal Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.0 CVE-2025-6043 Wordfence
8.8 High Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.3 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 1.6.3 CVE-2025-1313 Wordfence
7.5 High WPGYM - Wordpress Gym Management System Plugin SQL Injection Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection No login needed < 67.8.0 Fixed in 67.8.0 CVE-2025-7442 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms PHP Object Injection Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6742 Wordfence
8.1 High SureForms – Drag and Drop Form Builder Plugin sureforms Arbitrary File Deletion Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6691 Wordfence
7.1 High Zilom Plugin zilom Cross-Site Scripting No login needed ≤ 1.4.5 Fixed in 1.4.5 CVE-2024-43334 Patchstack
7.1 High Content Manager Light Plugin content-manager-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2 CVE-2025-24771 Patchstack
7.1 High WP Wall Plugin wp-wall Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-28968 Patchstack
8.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24780 Patchstack
7.1 High SB Breadcrumbs Plugin sb-breadcrumbs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-28978 Patchstack
7.7 High Aviation Weather from NOAA Plugin aviation-weather-from-noaa Arbitrary File Deletion ≤ 0.7.2 CVE-2025-28980 Patchstack
7.1 High Homey Plugin homey Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2025-31037 Patchstack
7.1 High Pressroom Theme pressroom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0 Fixed in 7.1 CVE-2025-32311 Patchstack
8.5 High Simple Link Directory Plugin qc-simple-link-directory SQL Injection ≤ 14.8.1 Fixed in 14.8.1 CVE-2025-32297 Patchstack
7.1 High Rankie Plugin valvepress-rankie Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-39487 Patchstack
7.5 High PrivateContent - Mail Actions Plugin private-content-mail-actions Local File Inclusion Mail Actions plugin <= 2.3.2 - Local File Inclusion No login needed ≤ 2.3.2 CVE-2025-47627 Patchstack
7.1 High Testimonials Showcase Plugin testimonials-showcase Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49245 Patchstack
7.1 High Neom Blog Plugin neom-blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.9 Fixed in 0.1.0 CVE-2025-49274 Patchstack
7.1 High Team Showcase Plugin team-showcase-cm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49247 Patchstack
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions SQL Injection No login needed ≤ 2.15.1 Fixed in 2.15.2 CVE-2025-49870 Patchstack
7.1 High Video List Manager Plugin video-list-manager Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-52776 Patchstack
7.2 High Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.2 Fixed in 7.8.5 CVE-2025-52718 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only