WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 301–350 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 7.6.43 Fixed in 7.6.44 CVE-2025-68997 Patchstack
5.3 Medium Google Calendar Events Plugin google-calendar-events Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2025-68979 Patchstack
4.3 Medium Eagle Booking Plugin eagle-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.4.3 CVE-2025-68975 Patchstack
4.3 Medium JetPopup Plugin jet-popup Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.20.1 Fixed in 2.0.20.2 CVE-2025-68502 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
4.3 Medium Radius Blocks Plugin radius-blocks Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.2.1 CVE-2025-64282 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.3.60 Fixed in 1.3.61 CVE-2025-10019 Patchstack
6.5 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.3.2 CVE-2025-68071 Patchstack
5.3 Medium Document Library Lite Plugin document-library-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.7 Fixed in 1.2.0 CVE-2025-67985 Patchstack
5.3 Medium FAPI Member Plugin fapi-member Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.30 CVE-2025-66132 Patchstack
4.9 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control ≤ 3.7.1 CVE-2025-64631 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67594 Patchstack
4.3 Medium WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors Plugin wc-vendors Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed ≤ 2.6.4 CVE-2025-12130 Wordfence
2.7 Low Timetable and Event Schedule by MotoPress Plugin mp-timetable Information Disclosure Contributor+ Event Disclosure via IDOR < 2.4.16 Fixed in 2.4.16 CVE-2025-12954 WPScan
9.8 Critical Mstoreapp Mobile (App Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0.8, ≤ 9.0.1 CVE-2025-11127 WPScan
9.8 Critical Miraculous Core Plugin miraculouscore Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2025-58627 Patchstack
8.1 High Dør Plugin dor Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4.1 CVE-2025-39466 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-64283 Patchstack
6.5 Medium Houzez Plugin houzez Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.5 CVE-2025-49952 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
5.5 Medium Academy LMS Plugin academy Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.4 Fixed in 3.3.5 CVE-2025-59562 Patchstack
5.3 Medium Envíos Coordinadora Woocommerce Plugin coordinadora Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.32 CVE-2025-57922 Patchstack
5.4 Medium Upcoming Events Lists Plugin upcoming-events-lists Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.0 CVE-2025-57994 Patchstack
3.8 Low Content Mask Plugin content-mask Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8.5.3 CVE-2025-58012 Patchstack
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting ≤ 2.0.92 Fixed in 2.1.00 CVE-2025-58702 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-58597 Patchstack
9.1 Critical bidorbuy Store Integrator Plugin bidorbuystoreintegrator Remote Code Execution ≤ 2.12.0 CVE-2025-48100 Patchstack
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation ≤ 4.0.5 CVE-2025-5931 Wordfence
5.4 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.30.0 Fixed in 1.30.1 CVE-2025-57886 Patchstack
7.5 High Maya Business Plugin paymaya-checkout-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-53208 Patchstack
5.3 Medium Motors Plugin motors-car-dealership-classified-listings Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.80 Fixed in 1.4.81 CVE-2025-54691 Patchstack
6.5 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.0.2 Fixed in 8.0.3 CVE-2025-39362 Patchstack
4.3 Medium JobSearch Plugin wp-jobsearch Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.0.6 Fixed in 3.0.6 CVE-2025-49978 Patchstack
5.3 Medium Download Attachments Plugin download-attachments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-49995 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack
4.3 Medium Slack Notifications by dorzki Plugin dorzki-notifications-to-slack Broken Access Control ≤ 2.0.7 CVE-2025-30978 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2025-49263 Patchstack
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-48272 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48263 Patchstack
4.3 Medium MultiVendorX – WooCommerce Multivendor Marketplace Solutions Plugin dc-woocommerce-multi-vendor Broken Access Control WooCommerce Multivendor Marketplace Solutions <= 4.2.22 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Post Deletion ≤ 4.2.22 CVE-2025-4101 Wordfence
3.5 Low BuddyBoss platform Plugin Broken Access Control Private Comment Exposure via IDOR < 2.7.60 Fixed in 2.7.60 CVE-2024-12767 WPScan
7.5 High wp-dashboard-notes Plugin Broken Access Control Contributor+ Arbitrary Private Notes Update via IDOR No login needed < 1.0.11 Fixed in 1.0.11 CVE-2023-7239 WPScan
7.3 High Wolmart | Multi-Vendor Marketplace WooCommerce Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed ≤ 1.8.11 CVE-2024-13793 Wordfence
4.3 Medium Avatar Plugin avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 0.1.4 CVE-2025-39434 Patchstack
5.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion No login needed ≤ 4.2.19 CVE-2025-2789 Wordfence
5.3 Medium Sliced Invoices Plugin sliced-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.10.0 CVE-2025-31628 Patchstack
5.4 Medium JS Job Manager Plugin js-jobs Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2 CVE-2025-31867 Patchstack
4.9 Medium JobBoard Job listing Plugin job-board-light Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2.8 CVE-2025-31833 Patchstack
4.3 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Insecure Direct Object References (IDOR) ≤ 8.0.2 CVE-2025-31609 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only