WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,551–3,600 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 72 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Sprout Clients Plugin sprout-clients Cross-Site Scripting No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-66118 Patchstack
7.5 High Easy Form Plugin easy-form Broken Access Control No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2025-66117 Patchstack
7.5 High Ultimate Member Widgets for Elementor Plugin ultimate-member-widgets-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-66116 Patchstack
7.1 High FV Antispam Plugin fv-antispam Cross-Site Scripting No login needed ≤ 2.7 Fixed in 2.8 CVE-2025-66102 Patchstack
7.5 High PropertyHive Plugin propertyhive Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66088 Patchstack
7.5 High wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 2.4.10 Fixed in 2.4.11 CVE-2025-66070 Patchstack
7.5 High LearnPress Plugin learnpress Broken Access Control No login needed ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-66054 Patchstack
7.1 High ListingPro Theme listingpro Broken Access Control ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64378 Patchstack
8.1 High ListingPro Theme listingpro Local File Inclusion No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64377 Patchstack
7.1 High ListingPro Theme listingpro Cross-Site Scripting No login needed ≤ 2.9.10 Fixed in 2.9.10 CVE-2025-64376 Patchstack
8.1 High Traveler Plugin traveler Local File Inclusion No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64373 Patchstack
7.1 High Traveler Plugin traveler Cross-Site Scripting No login needed ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64372 Patchstack
8.5 High Traveler Plugin traveler SQL Injection ≤ 3.2.6 Fixed in 3.2.6 CVE-2025-64371 Patchstack
7.5 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.44 Fixed in 1.0.45 CVE-2025-64268 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
7.1 High ANAC XML Bandi di Gara Plugin avcp Cross-Site Scripting No login needed ≤ 7.7 Fixed in 7.7.1 CVE-2025-64260 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-64258 Patchstack
7.7 High Filr Plugin filr-protection Arbitrary File Deletion ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-64230 Patchstack
8.1 High PenNews Plugin pennews Local File Inclusion No login needed ≤ 6.7.3 Fixed in 6.7.3 CVE-2025-64223 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
7.1 High Reservation Plugin dt-reservation-plugin Cross-Site Scripting No login needed ≤ 1.6 Fixed in 1.7 CVE-2025-64221 Patchstack
7.5 High Passster Plugin content-protector Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.19 Fixed in 4.2.20 CVE-2025-64218 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.2 Fixed in 7.7.4 CVE-2025-64217 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64214 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64213 Patchstack
7.5 High Masterstudy Theme masterstudy Broken Access Control No login needed ≤ 4.8.122 Fixed in 4.8.122 CVE-2025-64209 Patchstack
7.1 High Jannah Plugin jannah Cross-Site Scripting No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64207 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64205 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting No login needed ≤ 4.1.14 Fixed in 4.1.14 CVE-2025-64203 Patchstack
7.5 High XStore Theme xstore Local File Inclusion ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64193 Patchstack
7.1 High XStore Theme xstore Cross-Site Scripting No login needed ≤ 9.6.1 Fixed in 9.6.1 CVE-2025-64191 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting No login needed ≤ 5.6 Fixed in 5.6 CVE-2025-64189 Patchstack
7.1 High Support Board Plugin supportboard Cross-Site Scripting No login needed ≤ 3.8.7 Fixed in 3.8.7 CVE-2025-60182 Patchstack
8.1 High Inset Plugin inset Local File Inclusion No login needed ≤ 1.18.0 CVE-2025-6326 Patchstack
7.1 High Easy Invoice Plugin easy-invoice Cross-Site Scripting No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-6324 Patchstack
7.5 High WP Voting Contest Plugin wp-voting-contest Broken Access Control No login needed ≤ 5.8 CVE-2025-60086 Patchstack
8.8 High PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60084 Patchstack
8.8 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60083 Patchstack
8.8 High PDF for WPForms Plugin pdf-for-wpforms PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60082 Patchstack
8.8 High PDF for Contact Form 7 Plugin pdf-for-contact-form-7 PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60081 Patchstack
7.5 High PDF for Gravity Forms + Drag And Drop Template Builder Plugin pdf-for-gravity-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60080 Patchstack
7.1 High Parallax Section block Plugin parallax-section Authentication Bypass Broken Authentication ≤ 1.0.9 Fixed in 2.0.0 CVE-2025-60079 Patchstack
7.5 High Task Manager Plugin task-manager Local File Inclusion ≤ 3.0.2 CVE-2025-60078 Patchstack
7.5 High YayPricing Plugin yaypricing Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-60077 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2025-60076 Patchstack
8.1 High Anchor smooth scroll Plugin anchor-smooth-scroll Local File Inclusion No login needed ≤ 1.0.2 CVE-2025-60072 Patchstack
8.1 High Riode Plugin riode Local File Inclusion No login needed ≤ 1.6.23 CVE-2025-60071 Patchstack
8.1 High MinimogWP Theme minimog Local File Inclusion No login needed ≤ 3.9.6 CVE-2025-60069 Patchstack
8.1 High Giardino Theme giardino Local File Inclusion No login needed ≤ 1.1.10 CVE-2025-60067 Patchstack
8.1 High Katelyn Theme katelyn Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60066 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only