WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,251–3,300 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 66 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Zagg - Electronics & Accessories WooCommerce Theme Local File Inclusion Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.1 CVE-2025-4200 Wordfence
8.8 High Automatic Plugin - AI content generator and auto poster Plugin Arbitrary File Upload AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File Upload ≤ 3.115.0 CVE-2025-5395 Wordfence
8.1 High TinySalt Theme tinysalt Local File Inclusion No login needed ≤ 3.10.0 Fixed in 3.10.0 CVE-2025-49454 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
8.8 High RH - Real Estate Theme Privilege Escalation Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 4.4.0 CVE-2025-4601 Wordfence
8.1 High Fitrush Theme bw-fitrush Local File Inclusion No login needed ≤ 1.3.4 CVE-2023-26005 Patchstack
8.1 High BodyCenter - Gym, Fitness WooCommerce Theme bodycenter Local File Inclusion Gym, Fitness WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2023-25999 Patchstack
8.1 High One-Login Plugin one-login Privilege Escalation No login needed ≤ 1.4 CVE-2025-23974 Patchstack
8.1 High CraftXtore Plugin bw-craftxtore Local File Inclusion No login needed ≤ 1.7 CVE-2025-24770 Patchstack
8.1 High Nitan Plugin snsnitan Local File Inclusion No login needed ≤ 2.9 CVE-2025-24768 Patchstack
8.1 High Lab Plugin lab Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-26592 Patchstack
8.1 High Petito Plugin bw-petito Local File Inclusion No login needed ≤ 1.6.6 Fixed in 1.6.6 CVE-2025-27362 Patchstack
8.1 High Avaz Plugin snsavaz Local File Inclusion No login needed ≤ 2.8 CVE-2025-28944 Patchstack
8.1 High GiftXtore Plugin bw-giftxtore Local File Inclusion No login needed ≤ 1.7.7 Fixed in 1.7.7 CVE-2025-28888 Patchstack
8.1 High Valen - Sport, Fashion WooCommerce Plugin valen Local File Inclusion Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2025-28945 Patchstack
8.8 High Password Policy Manager Plugin password-policy-manager Privilege Escalation Account Takeover ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-31019 Patchstack
8.1 High SNS Anton Plugin snsanton Local File Inclusion No login needed ≤ 4.1 CVE-2025-28992 Patchstack
7.5 High elfsight Contact Form widget Plugin elfsight-contact-form Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.1 CVE-2025-31045 Patchstack
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
7.1 High Universal Video Player Plugin elementor_widget_universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-31057 Patchstack
7.1 High Revolution Video Player Plugin revolution_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.2 CVE-2025-31058 Patchstack
7.1 High Wishlist Plugin wishlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-31061 Patchstack
7.1 High Sticky Radio Player Plugin lbg-audio5-html5-shoutcast_sticky Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4 CVE-2025-31426 Patchstack
7.5 High CLEVER Plugin lbg-audio11-html5-shoutcast_history Path Traversal Arbitrary File Download No login needed ≤ 2.6 CVE-2025-31635 Patchstack
7.1 High Spare Theme spare Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-31638 Patchstack
7.1 High Universal Video Player Plugin universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.3 CVE-2025-31917 Patchstack
8.5 High WP Guppy Plugin wp-guppy SQL Injection ≤ 4.3.3 CVE-2025-31920 Patchstack
7.1 High SHOUT Plugin lbg-audio8-html5-radio_ads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.3 CVE-2025-31925 Patchstack
7.1 High FlatNews Theme flatnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 6.2 CVE-2025-32305 Patchstack
7.6 High Team Builder Plugin a-team-showcase Broken Access Control ≤ 1.5.7 CVE-2025-32308 Patchstack
8.1 High Seofy Core Plugin seofy-core Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.11 CVE-2025-39473 Patchstack
8.1 High Krowd Theme krowd Local File Inclusion No login needed ≤ 1.5.0 Fixed in 1.5.0 CVE-2025-32595 Patchstack
8.1 High Arlo Plugin arlo Local File Inclusion No login needed ≤ 6.0.3 CVE-2025-39475 Patchstack
7.5 High Revo Plugin revo Local File Inclusion No login needed ≤ 4.0.26 CVE-2025-39476 Patchstack
7.1 High WP Email Delivery Plugin wp-email-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.11.23 CVE-2025-39539 Patchstack
7.1 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.23 Fixed in 1.22.24 CVE-2025-47477 Patchstack
7.1 High Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-47463 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47487 Patchstack
8.8 High MapSVG Plugin mapsvg Privilege Escalation ≤ 8.6.13 Fixed in 8.6.13 CVE-2025-47561 Patchstack
7.1 High Icegram Collect Plugin icegram-rainmaker Broken Access Control Easy Form, Lead Collection and Subscription plugin <= 1.3.18 - Broken Access Control ≤ 1.3.18 Fixed in 1.3.19 CVE-2025-47527 Patchstack
8.5 High Infility Global Plugin infility-global SQL Injection ≤ 2.15.06 CVE-2025-47651 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Path Traversal Light plugin <= 2.4.37 - Arbitrary File Download No login needed ≤ 2.4.37 CVE-2025-48124 Patchstack
8.1 High WP Event Manager Plugin wp-event-manager Local File Inclusion No login needed ≤ 3.1.51 Fixed in 3.2.0 CVE-2025-48125 Patchstack
8.1 High Essential Real Estate Plugin essential-real-estate Local File Inclusion No login needed ≤ 5.2.9 CVE-2025-48126 Patchstack
7.5 High Spice Blocks Plugin spice-blocks Path Traversal Arbitrary File Download No login needed ≤ 2.0.7.4 Fixed in 2.0.7.5 CVE-2025-48130 Patchstack
7.1 High Formulario de contacto SalesUp! Plugin formularios-de-contacto-salesup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.14 CVE-2025-48143 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack
8.6 High WP Pipes Plugin wp-pipes Arbitrary File Deletion No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-48267 Patchstack
7.1 High WC MyParcel Belgium Plugin wc-myparcel-belgium Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed 4.5.5 – beta Fixed in 4.5.6 CVE-2025-48279 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.8.1 Fixed in 2.8.2 CVE-2025-49265 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only