WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,151–3,200 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 64 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control No login needed ≤ 1.3.9 CVE-2025-69186 Patchstack
7.3 High Hotel Listing Plugin hotel-listing Broken Access Control No login needed ≤ 1.4.2 CVE-2025-69185 Patchstack
7.3 High Institutions Directory Plugin institutions-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69184 Patchstack
8.8 High Hospital Doctor Directory Plugin hospital-doctor-directory Privilege Escalation ≤ 1.3.9 CVE-2025-69183 Patchstack
8.8 High Institutions Directory Plugin institutions-directory Privilege Escalation ≤ 1.3.4 CVE-2025-69182 Patchstack
7.3 High Lawyer Directory Plugin lawyer-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69181 Patchstack
8.5 High Ultra Portfolio Plugin ultra-portfolio SQL Injection ≤ 6.7 CVE-2025-69180 Patchstack
7.1 High WP Test Email Plugin wp-test-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.7 CVE-2025-69102 Patchstack
8.1 High North Theme north-wp Local File Inclusion No login needed ≤ 5.7.5 CVE-2025-69100 Patchstack
8.8 High North Theme north-wp PHP Object Injection ≤ 5.7.5 CVE-2025-69099 Patchstack
7.1 High Hide My WP Plugin hide_my_wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.2.12 CVE-2025-69098 Patchstack
8.6 High WPLMS Plugin wplms_plugin Arbitrary File Deletion No login needed ≤ 1.9.9.5.4 CVE-2025-69097 Patchstack
8.1 High Malta Theme malta Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69078 Patchstack
8.1 High Hobo Theme hobo Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-69077 Patchstack
8.1 High Modern Housewife Theme modernhousewife Local File Inclusion No login needed ≤ 1.0.12 CVE-2025-69076 Patchstack
8.1 High Yolox Theme yolox Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-69075 Patchstack
8.1 High Pearson Specter Theme pearsonspecter Local File Inclusion No login needed ≤ 1.11.3 CVE-2025-69074 Patchstack
8.1 High Piqes Theme piqes Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-69073 Patchstack
8.1 High Prider Theme prider Local File Inclusion No login needed ≤ 1.1.3.1 CVE-2025-69072 Patchstack
8.1 High TanTum Theme tantum Local File Inclusion No login needed ≤ 1.1.13 CVE-2025-69071 Patchstack
8.1 High Tornados Theme tornados Local File Inclusion No login needed ≤ 2.1 CVE-2025-69070 Patchstack
8.1 High Muji Theme muji Local File Inclusion No login needed ≤ 1.2.0 CVE-2025-69068 Patchstack
8.1 High Tails Theme tails Local File Inclusion No login needed ≤ 1.4.12 CVE-2025-69067 Patchstack
8.1 High Indoor Plants Theme indoor-plants Local File Inclusion No login needed ≤ 1.2.7 CVE-2025-69066 Patchstack
8.1 High Snow Mountain Theme snowmountain Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69065 Patchstack
8.1 High Pets Land Theme petsland Local File Inclusion No login needed ≤ 1.2.8 CVE-2025-69064 Patchstack
8.1 High Weedles Theme weedles Local File Inclusion No login needed ≤ 1.1.12 CVE-2025-69062 Patchstack
8.1 High MoveMe Theme moveme Local File Inclusion No login needed ≤ 1.2.15 CVE-2025-69061 Patchstack
8.1 High uReach Theme ureach Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69060 Patchstack
8.1 High DiveIt Theme diveit Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69059 Patchstack
8.1 High PartyMaker Theme partymaker Local File Inclusion No login needed ≤ 1.1.15 CVE-2025-69058 Patchstack
8.1 High Eldon Plugin eldon Local File Inclusion No login needed ≤ 1.0 CVE-2025-69057 Patchstack
7.1 High Hotel Listing Plugin hotel-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-69056 Patchstack
7.1 High Super Logos Showcase Plugin superlogoshowcase-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 CVE-2025-69054 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69053 Patchstack
7.1 High ListingPro Reviews Plugin listingpro-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.11 Fixed in 2.9.11 CVE-2025-69051 Patchstack
8.1 High Overworld Plugin overworld Local File Inclusion No login needed ≤ 1.3 CVE-2025-69050 Patchstack
8.1 High Töbel Plugin tobel Local File Inclusion No login needed ≤ 1.6 CVE-2025-69049 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69048 Patchstack
8.1 High MaxShop Plugin sw_maxshop Local File Inclusion No login needed ≤ 3.6.20 CVE-2025-69047 Patchstack
8.1 High iRecco Core Plugin irecco-core Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69046 Patchstack
8.5 High FooEvents for WooCommerce Plugin fooevents SQL Injection ≤ 1.20.4 Fixed in 1.20.5 CVE-2025-69045 Patchstack
8.1 High Vango Plugin vango Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69044 Patchstack
8.1 High Rashy Plugin rashy Local File Inclusion No login needed ≤ 1.1.3 CVE-2025-69043 Patchstack
8.1 High Lindo Plugin lindo Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69042 Patchstack
8.1 High Dekoro Plugin dekoro Local File Inclusion No login needed ≤ 1.0.7 CVE-2025-69041 Patchstack
8.1 High Bfres Plugin bfres Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-69040 Patchstack
8.1 High Bailly Plugin bailly Local File Inclusion No login needed ≤ 1.3.4 CVE-2025-69039 Patchstack
8.1 High Hyori Plugin hyori Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69038 Patchstack
8.1 High Pippo Plugin pippo Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-69037 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only