WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,401–3,450 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 69 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WC Affiliate Plugin wc-affiliate PHP Object Injection ≤ 2.16 Fixed in 2.17 CVE-2025-47660 Patchstack
7.6 High Binary MLM Plan Plugin binary-mlm-plan SQL Injection ≤ 3.0 Fixed in 5.0 CVE-2025-47671 Patchstack
8.1 High WordPress Social Login and Register Plugin miniorange-login-openid Local File Inclusion No login needed ≤ 7.6.10 Fixed in 7.7.0 CVE-2025-47670 Patchstack
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.16 Fixed in 2.1.17 CVE-2025-47673 Patchstack
8.1 High miniOrange Discord Integration Plugin miniorange-discord-integration Local File Inclusion No login needed ≤ 2.2.2 CVE-2025-47672 Patchstack
7.1 High xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12.06 CVE-2025-47680 Patchstack
7.1 High FunnelCockpit Plugin funnelcockpit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-47678 Patchstack
8.8 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.1 Fixed in 3.2 CVE-2025-47690 Patchstack
7.1 High Quick Contact Form Plugin quick-contact-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.1 Fixed in 8.2.2 CVE-2025-48245 Patchstack
7.1 High Verge3D Plugin verge3d Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.3 Fixed in 4.9.4 CVE-2025-48241 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Path Traversal Arbitrary File Download No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48273 Patchstack
7.1 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 24.1209 Fixed in 25.0513 CVE-2025-48286 Patchstack
8.1 High Tourmaster Plugin tourmaster Local File Inclusion No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2025-48292 Patchstack
7.1 High Tiger Theme tiger Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31027 Patchstack
8.5 High Revy Plugin revy SQL Injection ≤ 2.1 CVE-2025-32924 Patchstack
8.3 High SUMO Reward Points Plugin rewardsystem Local File Inclusion No login needed ≤ 30.7.0 CVE-2025-32925 Patchstack
8.2 High wProject Theme wproject Broken Access Control Unauthenticated Post/Comment/Attachment Modification/Deletion No login needed < 5.8.0 Fixed in 5.8.0 CVE-2025-39350 Patchstack
8.2 High Grand Restaurant Plugin grandrestaurant Broken Access Control Arbitrary Options Deletion No login needed ≤ 7.0 CVE-2025-39352 Patchstack
8.5 High FAT Services Booking Plugin fat-services-booking SQL Injection ≤ 5.6 CVE-2025-39355 Patchstack
8.5 High Hospital Management System Plugin hospital-management SQL Injection ≤ 47.0(20-11-2023) CVE-2025-39357 Patchstack
7.1 High wProject Theme wproject Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.8.0 Fixed in 5.8.0 CVE-2025-39365 Patchstack
8.8 High wProject Theme wproject Privilege Escalation Subscriber+ Privilege Escalation < 5.8.0 Fixed in 5.8.0 CVE-2025-39366 Patchstack
7.1 High WordPress Events Calendar Registration & Tickets Plugin wpeventplus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-39372 Patchstack
7.1 High WPAMS Plugin apartment-management Cross-Site Scripting No login needed ≤ 44.0 (17-08-2023) CVE-2025-39392 Patchstack
7.1 High Hospital Management System Plugin hospital-management Cross-Site Scripting No login needed ≤ 47.0(20-11-2023) CVE-2025-39393 Patchstack
8.5 High WPAMS Plugin apartment-management SQL Injection ≤ 44.0 (17-08-2023) CVE-2025-39403 Patchstack
8.8 High WPAMS Plugin apartment-management Privilege Escalation ≤ 44.0 (17-08-2023) CVE-2025-39405 Patchstack
7.1 High Memberpress Plugin memberpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 1.12.0 Fixed in 1.12.0 CVE-2025-39407 Patchstack
7.1 High WordPress Video Robot - The Ultimate Video Importer Plugin wp-video-robot Cross-Site Scripting The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.0 CVE-2025-39409 Patchstack
7.5 High WhatsApp Click to Chat Plugin wpt-whatsapp Local File Inclusion No login needed ≤ 2.2.12 CVE-2025-39411 Patchstack
7.1 High Booster Plus for WooCommerce Plugin booster-plus-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.4 Fixed in 7.2.5 CVE-2025-39446 Patchstack
7.5 High JetElements For Elementor Plugin jet-elements Broken Access Control No login needed ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39447 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-39449 Patchstack
7.5 High JetBlocks For Elementor Plugin jet-blocks Broken Access Control No login needed ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-39451 Patchstack
8.1 High Foton Plugin foton Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.6.1 CVE-2025-39458 Patchstack
7.3 High Real Estate 7 Plugin realestate-7 Privilege Escalation No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2025-39459 Patchstack
7.1 High Remote Images Grabber Plugin remote-images-grabber Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6 CVE-2025-43832 Patchstack
7.1 High Syndicate Out Plugin syndicate-out Cross-Site Scripting No login needed ≤ 0.9 CVE-2025-43836 Patchstack
7.1 High Total Donations Plugin total-donations Cross-Site Scripting No login needed ≤ 3.0.8 CVE-2025-43837 Patchstack
7.1 High BP Messages Tool Plugin bp-messages-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 Fixed in 2.5 CVE-2025-43839 Patchstack
8.1 High Tastyc Theme tastyc Local File Inclusion No login needed ≤ 2.5.2 Fixed in 2.5.2 CVE-2025-27010 Patchstack
7.1 High Wireless Butler Plugin wireless-butler Cross-Site Scripting No login needed ≤ 1.0.11 CVE-2025-26997 Patchstack
7.5 High Grip Theme grip Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-26735 Patchstack
7.6 High Absolute Links Plugin absolute-links SQL Injection ≤ 1.1.1 CVE-2025-43833 Patchstack
7.5 High JetReviews Plugin jet-reviews Local File Inclusion ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39396 Patchstack
7.1 High CheckBot Plugin checkbot Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.05 CVE-2025-43840 Patchstack
7.1 High Best Posts Summary Plugin best-posts-summary Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-39374 Patchstack
7.6 High iCafe Library Plugin icafe-library SQL Injection ≤ 1.8.3 CVE-2025-39370 Patchstack
7.5 High Product Category Slider for WooCommerce Plugin woo-category-slider-by-pluginever Local File Inclusion ≤ 4.3.4 Fixed in 4.3.5 CVE-2025-39364 Patchstack
8.8 High Bimber - Viral Magazine Theme bimber Local File Inclusion Viral Magazine WordPress Theme theme <= 9.2.5 - Local File Inclusion ≤ 9.2.5 CVE-2025-47576 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only