WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,501–3,550 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 71 of 182
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Puca Plugin puca Local File Inclusion ≤ 2.6.39 CVE-2025-68984 Patchstack
7.5 High Greenmart Plugin greenmart Local File Inclusion ≤ 4.2.11 CVE-2025-68983 Patchstack
7.1 High Off Page SEO Plugin off-page-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.3 CVE-2025-23554 Patchstack
7.1 High Product Puller Plugin product-puller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23550 Patchstack
7.1 High Sleekplan Plugin sleekplan Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.0 CVE-2025-23469 Patchstack
7.1 High Ads24 Lite Plugin wp-ad-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23458 Patchstack
7.5 High CubeWP Plugin cubewp-framework Broken Access Control No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2025-68036 Patchstack
7.2 High Advanced Ads Plugin advanced-ads Remote Code Execution Authenticated (Editor+) Remote Code Execution via Shortcode ≤ 2.0.14 CVE-2025-13592 Wordfence
7.1 High Plugin Optimizer Plugin plugin-optimizer Broken Access Control ≤ 1.3.7 CVE-2025-68861 Patchstack
7.5 High CookieHint WP Plugin cookiehint-wp Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-68870 Patchstack
7.1 High Invelity SPS connect Plugin invelity-sps-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 CVE-2025-68876 Patchstack
7.5 High CedCommerce Integration for Good Market Plugin ced-good-market-integration Local File Inclusion No login needed ≤ 1.0.6 CVE-2025-68877 Patchstack
7.1 High Advanced Custom CSS Plugin advanced-custom-css Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-68878 Patchstack
7.1 High Content Grid Slider Plugin content-grid-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-68879 Patchstack
8.6 High Plugin Organizer Plugin plugin-organizer SQL Injection Subscriber+ SQLi No login needed < 10.2.4 Fixed in 10.2.4 CVE-2025-13417 WPScan
7.6 High Integration for Contact Form 7 HubSpot Plugin cf7-hubspot SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-68590 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.2.2 Fixed in 3.3.0 CVE-2025-68570 Patchstack
8.1 High Docket Cache Plugin docket-cache Local File Inclusion No login needed ≤ 24.07.03 Fixed in 24.07.04 CVE-2025-68506 Patchstack
7.2 High Icegram Express Pro Plugin email-subscribers-premium PHP Object Injection ≤ 5.9.14 Fixed in 5.9.14 CVE-2025-68038 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
7.1 High Evergreen Post Tweeter Plugin evergreen-post-tweeter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.8.9 CVE-2025-67622 Patchstack
8.6 High WPJobBoard Plugin wpjobboard SQL Injection Unauth. Blind SQL Injection (SQLi) No login needed ≤ 5.9.0 Fixed in 5.10.1 CVE-2023-36525 Patchstack
7.5 High Userpro Plugin userpro Broken Access Control No login needed ≤ 5.1.9 CVE-2025-68608 Patchstack
7.5 High Subscribe to Unlock Lite Plugin subscribe-to-unlock-lite Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-68563 Patchstack
7.5 High Fana Plugin fana Local File Inclusion ≤ 1.1.35 Fixed in 1.1.36 CVE-2025-68540 Patchstack
7.5 High Zota Plugin zota Local File Inclusion ≤ 1.3.14 Fixed in 1.3.15 CVE-2025-68537 Patchstack
7.5 High Bookory Theme bookory Local File Inclusion ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-68530 Patchstack
8.5 High Brands for WooCommerce Plugin brands-for-woocommerce SQL Injection ≤ 3.8.6.3 Fixed in 3.8.6.4 CVE-2025-68519 Patchstack
7.6 High User Feedback Plugin userfeedback-lite SQL Injection ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-68496 Patchstack
7.5 High PowerPack Pro for Elementor Plugin powerpack-elements Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 2.10.6 Fixed in 2.10.8 CVE-2024-24844 Patchstack
7.5 High Nika Plugin nika Local File Inclusion ≤ 1.2.14 Fixed in 1.2.15 CVE-2025-68546 Patchstack
7.5 High Diza Theme diza Local File Inclusion ≤ 1.3.15 Fixed in 1.3.16 CVE-2025-68544 Patchstack
7.6 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.1.13 Fixed in 1.1.14 CVE-2025-68550 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68560 Patchstack
7.6 High AutomatorWP Plugin automatorwp SQL Injection ≤ 5.2.4 Fixed in 5.2.5 CVE-2025-68561 Patchstack
8.1 High Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update ≤ 2.9.4.1 CVE-2025-12934 Wordfence
8.1 High Redirection for Contact Form 7 Plugin wpcf7-redirect Arbitrary File Upload Unauthenticated Arbitrary File Copy via move_file_to_upload No login needed ≤ 3.2.7 CVE-2025-14800 Wordfence
7.2 High SureForms Plugin sureforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2025-14855 Wordfence
7.2 High ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.3.4 CVE-2025-9343 Wordfence
7.5 High Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin ultimate-post Broken Access Control PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 5.0.3 CVE-2025-12980 Wordfence
7.5 High Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode ≤ 2.0.2 CVE-2025-14071 Wordfence
7.7 High HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25446 Patchstack
7.6 High WP JobHunt Plugin Broken Access Control Missing Authorization to Authenticated (Candidate+) Stored Cross-Site Scripting via 'status' ≤ 7.7 CVE-2025-7782 Wordfence
7.2 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.3.2 CVE-2025-14151 Wordfence
7.2 High HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player Plugin html5-audio-player Server-Side Request Forgery The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticated Server-Side Request Forgery No login needed 2.4.0 – 2.5.1 CVE-2025-13999 Wordfence
7.2 High Ocean Modal Window Plugin ocean-modal-window Remote Code Execution Editor+ Remote Code Execution via Modal Conditions < 2.3.3 Fixed in 2.3.3 CVE-2025-13307 WPScan
7.5 High Hummingbird Plugin hummingbird-performance Information Disclosure Unauthenticated Sensitive Information Exposure via Log File No login needed ≤ 3.18.0 CVE-2025-14437 Wordfence
8.8 High Demo Importer Plus Plugin demo-importer-plus Broken Access Control Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation ≤ 2.0.8 CVE-2025-14364 Wordfence
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template' ≤ 3.59.12 CVE-2025-13641 Wordfence
7.1 High Hostel Plugin hostel Cross-Site Scripting No login needed ≤ 1.1.5.9 Fixed in 1.1.6 CVE-2025-66119 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only