WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 3,351–3,400 of 6,516 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 68 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WP Posts Carousel Plugin wp-posts-carousel PHP Object Injection ≤ 1.3.12 Fixed in 1.3.13 CVE-2025-39358 Patchstack
8.5 High Photography Theme photography PHP Object Injection ≤ 7.5.2 CVE-2025-47584 Patchstack
7.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-customers-exporter Information Disclosure Sensitive Data Exposure No login needed ≤ 5.0 CVE-2025-48331 Patchstack
7.7 High KBx Pro Ultimate Plugin knowledgebase-helpdesk-pro Arbitrary File Deletion ≤ 8.0.5 Fixed in 8.0.5 CVE-2025-31053 Patchstack
8.1 High Vizeon - Business Consulting Plugin vizeon Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.2.1 CVE-2025-31064 Patchstack
8.1 High Capie Theme capie Local File Inclusion No login needed ≤ 1.0.40 Fixed in 1.0.53.1 CVE-2025-31060 Patchstack
8.1 High La Boom Theme laboom Local File Inclusion No login needed ≤ 2.7 CVE-2025-31632 Patchstack
8.1 High Enzio - Responsive Business Plugin enzio Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-31912 Patchstack
7.1 High WP Post Modules for Elementor Plugin wp-post-modules-el Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-31636 Patchstack
8.1 High Kiamo - Responsive Business Service Theme kiamo Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-31633 Patchstack
8.1 High Ogami Theme ogami Local File Inclusion No login needed ≤ 1.53 Fixed in 1.61.1 CVE-2025-31913 Patchstack
8.8 High Crafts & Arts Plugin crafts-and-arts PHP Object Injection ≤ 2.5 CVE-2025-31924 Patchstack
8.8 High Pet World Theme petsworld PHP Object Injection ≤ 2.8 CVE-2025-32284 Patchstack
8.1 High Butcher Theme butcher Local File Inclusion No login needed ≤ 2.40 CVE-2025-32286 Patchstack
7.1 High Butcher Theme butcher Cross-Site Scripting No login needed ≤ 2.54 Fixed in 2.54 CVE-2025-32285 Patchstack
8.1 High Yozi Theme yozi Local File Inclusion No login needed ≤ 2.0.63 Fixed in 2.0.66.1 CVE-2025-32289 Patchstack
8.1 High Oxpitan Theme oxpitan Local File Inclusion No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-32294 Patchstack
8.8 High Finance Consultant Plugin finance PHP Object Injection ≤ 2.8 CVE-2025-32293 Patchstack
8.1 High Healsoul Theme healsoul Local File Inclusion No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-32309 Patchstack
8.1 High Winnex Plugin winnex Local File Inclusion No login needed ≤ 1.3.2 CVE-2025-32302 Patchstack
8.1 High Wilmër Plugin wilmer Local File Inclusion No login needed ≤ 3.4.2 Fixed in 3.4.2 CVE-2025-39494 Patchstack
8.1 High Backpack Traveler Theme backpacktraveler Local File Inclusion No login needed ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-39490 Patchstack
7.1 High Goodlayers Hostel Plugin gdlr-hostel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 CVE-2025-39502 Patchstack
7.1 High Goodlayers Hotel Plugin gdlr-hotel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.4 CVE-2025-39505 Patchstack
8.2 High JobHunt Job Alerts Plugin jobhunt-notifications Broken Access Control Arbitrary Content Deletion No login needed ≤ 3.6 CVE-2025-39536 Patchstack
8.1 High Nasa Core Plugin nasa-core Local File Inclusion No login needed ≤ 6.3.2 CVE-2025-39506 Patchstack
7.1 High kStats Reloaded Plugin kstats-reloaded Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7.4 CVE-2025-46440 Patchstack
7.1 High Tayori Form Plugin tayori Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 CVE-2025-46437 Patchstack
7.1 High Libro de Reclamaciones Plugin libro-de-reclamaciones Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-46446 Patchstack
8.1 High Ads Pro Plugin ap-plugin-scripteo Local File Inclusion No login needed ≤ 4.89 CVE-2025-46444 Patchstack
7.5 High Meta Keywords & Description Plugin wp-meta-keywords-meta-description Local File Inclusion No login needed ≤ 0.8 CVE-2025-46454 Patchstack
7.1 High Document Management System Plugin dms Cross-Site Scripting No login needed ≤ 1.24 CVE-2025-46448 Patchstack
7.1 High Theme Blvd Sliders Plugin theme-blvd-sliders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-46456 Patchstack
8.2 High occupancyplan Plugin occupancyplan Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.3.0 CVE-2025-46458 Patchstack
8.5 High Mailing Group Listserv Plugin wp-mailing-group SQL Injection ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-46463 Patchstack
8.1 High SEUR Oficial Plugin seur Local File Inclusion No login needed ≤ 2.2.23 Fixed in 2.2.24 CVE-2025-46474 Patchstack
7.1 High Visual Builder Plugin visual-builder Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-46488 Patchstack
7.1 High EC Authorize.net Plugin ec-authorizenet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2025-46487 Patchstack
7.1 High Category Widget Plugin category-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2025-46515 Patchstack
7.1 High My Custom Widgets Plugin mycustomwidget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 CVE-2025-46526 Patchstack
8.1 High WP Job Portal Plugin wp-job-portal Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-47438 Patchstack
7.1 High Section Widget Plugin section-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.1 CVE-2025-46537 Patchstack
7.1 High B2i Investor Tools Plugin b2i-investor-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7.9 Fixed in 1.0.8 CVE-2025-47458 Patchstack
8.1 High WP Smart Import Plugin wp-smart-import Local File Inclusion No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-47453 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.0 Fixed in 5.9.5.1 CVE-2025-47478 Patchstack
8.8 High Subaccounts for WooCommerce Plugin subaccounts-for-woocommerce Privilege Escalation Account Takeover ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-47461 Patchstack
8.6 High Tainacan Plugin tainacan Arbitrary File Deletion No login needed ≤ 0.21.14 Fixed in 0.21.15 CVE-2025-47512 Patchstack
8.6 High Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2025-47492 Patchstack
8.6 High Opal Woo Custom Product Variation Plugin opal-woo-custom-product-variation Arbitrary File Deletion No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-47535 Patchstack
7.5 High MapSVG Plugin mapsvg Broken Access Control No login needed ≤ 8.6.13 Fixed in 8.6.13 CVE-2025-47558 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only