WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,451–3,500 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 70 of 182
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High JobBank Plugin jobbank Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-69085 Patchstack
8.1 High Issabella Theme issabella Local File Inclusion No login needed ≤ 1.1.2 CVE-2025-69086 Patchstack
8.8 High BuddyPress Xprofile Custom Field Types Plugin bp-xprofile-custom-field-types Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.2.8 CVE-2025-14997 Wordfence
7.3 High Download Manager Plugin download-manager Privilege Escalation Unauthenticated Limited Privilege Escalation via updatePassword No login needed ≤ 3.3.40 CVE-2025-15364 Wordfence
7.5 High LoginWP - Pro Plugin loginwp-pro Broken Access Control Pro Plugin <= 4.0.8.5 - Settings Change No login needed ≤ 4.0.8.5 Fixed in 4.0.8.6 CVE-2025-46255 Patchstack
7.1 High iPhone Webclip Manager Plugin iphone-webclip-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5 CVE-2024-53735 Patchstack
7.5 High Booking Package Plugin booking-package Price Manipulation No login needed ≤ 1.6.27 Fixed in 1.6.29 CVE-2024-30516 Patchstack
7.1 High Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30461 Patchstack
7.1 High Machic Core Plugin machic-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6 CVE-2023-49186 Patchstack
7.5 High Sell Downloads Plugin sell-downloads Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.2.0 CVE-2025-68850 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-68547 Patchstack
8.6 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68044 Patchstack
7.5 High Custom Related Posts Plugin custom-related-posts Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-68033 Patchstack
8.8 High Themify Edmin Theme edmin PHP Object Injection ≤ 2.0.0 CVE-2025-31047 Patchstack
8.5 High Premium SEO Pack Plugin premium-seo-pack SQL Injection ≤ 3.3.2 CVE-2025-31044 Patchstack
8.1 High FreeAgent Theme freeagent Local File Inclusion No login needed ≤ 2.1.2 CVE-2025-69087 Patchstack
8.6 High Team Plugin tlp-team SQL Injection Unauthenticated SQLi No login needed < 5.0.11 Fixed in 5.0.11 CVE-2025-14124 WPScan
7.1 High Easy Social Plugin easy-social-media Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-53235 Patchstack
7.1 High Sala Theme sala Cross-Site Scripting No login needed ≤ 1.1.3 CVE-2025-52739 Patchstack
7.1 High Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin yournewsapp Cross-Site Scripting Your native, mobile iPhone App and Android App Plugin <= 0.8.8.8 - Cross Site Scripting (XSS) No login needed ≤ 0.8.8.8 CVE-2025-50053 Patchstack
7.1 High ZoomSounds Plugin dzs-zoomsounds Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.91 CVE-2025-47566 Patchstack
7.1 High Bloggie Theme bloggie Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2025-31054 Patchstack
8.5 High Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) Plugin azon-addon-js-composer SQL Injection ≤ 1.2 CVE-2025-30628 Patchstack
8.5 High Mediabay - WordPress Media Library Folders Plugin mediabay SQL Injection WordPress Media Library Folders <= 1.4 - SQL Injection ≤ 1.4 CVE-2025-28949 Patchstack
7.1 High ZD Scribd iPaper Plugin zd-scribd-ipaper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23757 Patchstack
7.1 High ZhinaTwitterWidget Plugin zhina-twitter-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23719 Patchstack
7.1 High En Masse Plugin en-masse-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23707 Patchstack
7.1 High Zielke Design Project Gallery Plugin zielke-design-project-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23705 Patchstack
7.1 High custom-post-edit Plugin front-end-post-edit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-23667 Patchstack
7.1 High LIVE TV Plugin live-tv Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23608 Patchstack
7.1 High Zoho ZeptoMail Plugin transmail Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-49028 Patchstack
7.5 High Knowband Mobile App Builder for wooCommerce Plugin Broken Access Control Unauthenticated Arbitrary User Deletion No login needed < 3.0.0 Fixed in 3.0.0 CVE-2025-13029 WPScan
7.1 High Custom Style Plugin custom-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49342 Patchstack
7.1 High Noindex by Path Plugin noindex-by-path Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49353 Patchstack
7.1 High Custom Post Status Plugin custom-post-status Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.0 CVE-2025-68885 Patchstack
7.1 High Recent Posts From Each Category Plugin recent-posts-from-each-category Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-49354 Patchstack
7.1 High Social Profilr Plugin social-profilr-display-social-network-profile Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49343 Patchstack
7.1 High SensitiveTagCloud Plugin sensitive-tag-cloud Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-49344 Patchstack
7.1 High WP-EasyArchives Plugin wp-easyarchives Cross-Site Request Forgery No login needed ≤ 3.1.2 CVE-2025-49345 Patchstack
7.1 High Simple Archive Generator Plugin simple-archive-generator Cross-Site Request Forgery No login needed ≤ 5.2 CVE-2025-49346 Patchstack
7.1 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Request Forgery No login needed ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-59137 Patchstack
7.1 High WP-CalDav2ICS Plugin wp-caldav2ics Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-59131 Patchstack
7.5 High MAS Videos Plugin masvideos Local File Inclusion ≤ 1.3.4 CVE-2025-62753 Patchstack
7.6 High Appointify Plugin appointify SQL Injection ≤ 1.0.8 CVE-2025-59129 Patchstack
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
8.1 High Lekker Theme lekker Local File Inclusion No login needed ≤ 1.8 CVE-2025-69034 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.1 CVE-2025-68996 Patchstack
8.5 High BWL Pro Voting Manager Plugin bwl-pro-voting-manager SQL Injection ≤ 1.4.9 CVE-2025-68990 Patchstack
7.5 High Cinerama Theme cinerama Local File Inclusion ≤ 2.9 CVE-2025-68987 Patchstack
7.5 High Aora Theme aora Local File Inclusion ≤ 1.3.15 CVE-2025-68985 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only