WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,501–3,550 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 71 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High theMarketer Plugin themarketer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47655 Patchstack
7.5 High WP-Recall Plugin wp-recall Local File Inclusion ≤ 16.26.14 CVE-2025-47653 Patchstack
8.8 High Open Close WooCommerce Store Plugin woc-open-close Local File Inclusion ≤ 4.9.9 CVE-2025-47649 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.6 High ELEX Product Feed for WooCommerce Plugin elex-product-feed SQL Injection ≤ 3.1.2 CVE-2025-47643 Patchstack
7.1 High Supertext Translation and Proofreading Plugin polylang-supertext Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.26 CVE-2025-47639 Patchstack
7.5 High List category posts Plugin list-category-posts Local File Inclusion ≤ 0.91.0 Fixed in 0.92.0 CVE-2025-47636 Patchstack
7.2 High WP-CRM System Plugin wp-crm-system PHP Object Injection ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-47629 Patchstack
7.1 High Martins Free Monetized Ad Exchange Network Plugin martins-free-and-easy-ad-network-get-more-visitors Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-47620 Patchstack
7.6 High YaySMTP Plugin yaysmtp SQL Injection ≤ 2.6.4 Fixed in 2.6.5 CVE-2025-47587 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47546 Patchstack
7.6 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing SQL Injection ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-47544 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
7.5 High XT Event Widget for Social Events Plugin xt-facebook-events Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-47531 Patchstack
7.1 High Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2025-47517 Patchstack
7.1 High ELI's Related Posts Footer Links and Widget Plugin spostarbust Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.04.20 Fixed in 1.2.04.25 CVE-2025-47514 Patchstack
7.5 High Display Eventbrite Events Plugin widget-for-eventbrite-api Local File Inclusion ≤ 6.3 Fixed in 6.3 CVE-2025-47510 Patchstack
7.5 High GamiPress Plugin gamipress Local File Inclusion ≤ 7.3.7 Fixed in 7.3.8 CVE-2025-47508 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.6 Fixed in 3.7 CVE-2025-47498 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Local File Inclusion ≤ 4.7.5 Fixed in 4.7.6 CVE-2025-47496 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-47494 Patchstack
7.4 High Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47491 Patchstack
8.5 High Ultimate WP Mail Plugin ultimate-wp-mail SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-47490 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
7.6 High TrackShip for WooCommerce Plugin trackship-for-woocommerce SQL Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47460 Patchstack
7.5 High WPAdverts Plugin wpadverts Local File Inclusion ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-47440 Patchstack
7.5 High Download Monitor Plugin download-monitor Local File Inclusion ≤ 5.0.22 Fixed in 5.0.23 CVE-2025-47439 Patchstack
7.3 High Motors - Car Dealer, Rental & Listing Theme Arbitrary Shortcode Execution Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.6.65 CVE-2024-13738 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.88 - Unauthenticated SQL Injection No login needed ≤ 4.88 CVE-2024-13322 Wordfence
8.1 High Projectopia – WordPress Project Management Plugin projectopia-core Broken Access Control WordPress Project Management <= 5.1.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 5.1.16 CVE-2025-3952 Wordfence
7.2 High boot-store Theme boot-store Cross-Site Scripting The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. No login needed 1.6.4 CVE-2015-4582 mitre
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
7.2 High Social Counter Plugin social-counter PHP Object Injection ≤ 2.0.5 Fixed in 2.1 CVE-2025-46473 Patchstack
7.1 High Unsafe Mimetypes Plugin unsafe-mimetypes Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.1.4 CVE-2025-46507 Patchstack
7.2 High Flickr Shortcode Importer Plugin flickr-shortcode-importer PHP Object Injection ≤ 2.2.3 CVE-2025-46481 Patchstack
7.1 High Loan Calculator Plugin repayment-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-46442 Patchstack
7.1 High Wp Custom CMS Block Plugin wp-custom-cms-block Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-46457 Patchstack
7.1 High WoWHead Tooltips Plugin wowhead-tooltips Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2025-46449 Patchstack
7.1 High Hacklog Remote Attachment Plugin hacklog-remote-attachment Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2025-46530 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High WP Filter Post Category Plugin wp-filter-post-categories Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 2.1.4 CVE-2025-46524 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
7.1 High Related Posts via Taxonomies Plugin related-posts-via-taxonomies Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.1 CVE-2025-46520 Patchstack
7.1 High Twitter Card Generator Plugin twitter-card-generator Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.5 CVE-2025-46516 Patchstack
7.1 High Milat jQuery Automatic Popup Plugin milat-jquery-automatic-popup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2025-46514 Patchstack
7.1 High Custom Functions Plugin custom-functions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-46512 Patchstack
7.1 High Contact Form 7 Calendar Plugin cf7-calendar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.1 CVE-2025-46510 Patchstack
7.1 High Advanced lazy load Plugin advanced-lazy-load Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.0 CVE-2025-46508 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only