WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,601–3,650 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 73 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Pinevale Theme pinevale Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-60065 Patchstack
8.1 High Renewal Theme renewal Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-60064 Patchstack
8.1 High Rosalinda Theme rosalinda Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-60063 Patchstack
8.1 High Kicker Theme kicker Local File Inclusion No login needed ≤ 2.2.0 CVE-2025-60061 Patchstack
8.1 High Pubzinne Theme pubzinne Local File Inclusion No login needed ≤ 1.0.12 CVE-2025-60060 Patchstack
8.1 High smart SEO Theme smartseo Local File Inclusion No login needed ≤ 2.12 CVE-2025-60059 Patchstack
8.1 High DetailX Theme detailx Local File Inclusion No login needed ≤ 1.10.0 CVE-2025-60058 Patchstack
8.1 High DJ Rainflow Theme dj-rainflow Local File Inclusion No login needed ≤ 1.3.13 CVE-2025-60057 Patchstack
8.1 High Winger Theme winger Local File Inclusion No login needed ≤ 1.0.16 CVE-2025-60056 Patchstack
8.1 High Fabrica Theme fabrica Local File Inclusion No login needed ≤ 1.8.1 CVE-2025-60055 Patchstack
8.1 High OnLeash Theme onleash Local File Inclusion No login needed ≤ 1.5.2 CVE-2025-60054 Patchstack
8.1 High MaxCube Theme maxcube Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-60053 Patchstack
8.1 High W&D Theme wd Local File Inclusion No login needed ≤ 1.0 CVE-2025-60052 Patchstack
8.1 High Rare Radio Theme rareradio Local File Inclusion No login needed ≤ 1.0.15.1 CVE-2025-60051 Patchstack
8.1 High Panda Theme panda Local File Inclusion No login needed ≤ 1.21 CVE-2025-60050 Patchstack
8.1 High Soleil Theme soleil Local File Inclusion No login needed ≤ 1.17 CVE-2025-60049 Patchstack
8.1 High Tripster Theme tripster Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60048 Patchstack
8.1 High IPharm Theme ipharm Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-60047 Patchstack
8.1 High HeartStar Theme heartstar Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-60046 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.11 CVE-2025-60045 Patchstack
8.1 High Fribbo Theme fribbo Local File Inclusion No login needed ≤ 1.1.0 CVE-2025-60044 Patchstack
8.1 High Wanderic Theme wanderic Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-60043 Patchstack
8.1 High Chinchilla Theme chinchilla Local File Inclusion No login needed ≤ 1.16 CVE-2025-60042 Patchstack
8.8 High Sale! Immigration law, Visa services support, Migration Agent Consulting Plugin immiex Privilege Escalation ≤ 1.5.8 CVE-2025-59134 Patchstack
8.1 High Lione Theme lione Local File Inclusion No login needed ≤ 1.16 CVE-2025-58950 Patchstack
8.1 High Spock Theme spock Local File Inclusion No login needed ≤ 1.17 CVE-2025-58949 Patchstack
8.1 High Aromatica Theme aromatica Local File Inclusion No login needed ≤ 1.8 CVE-2025-58948 Patchstack
8.1 High Athos Theme athos Local File Inclusion No login needed ≤ 1.9 CVE-2025-58947 Patchstack
8.1 High Vocal Theme vocal Local File Inclusion No login needed ≤ 1.12 CVE-2025-58946 Patchstack
8.1 High EcoGrow Theme ecogrow Local File Inclusion No login needed ≤ 1.7 CVE-2025-58945 Patchstack
8.1 High Manufactory Theme manufactory Local File Inclusion No login needed ≤ 1.4 CVE-2025-58944 Patchstack
8.1 High Agricola Theme agricola Local File Inclusion No login needed ≤ 1.1.0 CVE-2025-58943 Patchstack
8.1 High Dwell Theme dwell Local File Inclusion No login needed ≤ 1.7.0 CVE-2025-58942 Patchstack
8.1 High Fabric Theme fabric Local File Inclusion No login needed ≤ 1.5.0 CVE-2025-58941 Patchstack
8.1 High Basil Theme basil Local File Inclusion No login needed ≤ 1.3.12 CVE-2025-58940 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-58938 Patchstack
8.1 High Tacticool Theme tacticool Local File Inclusion No login needed ≤ 1.0.13 CVE-2025-58937 Patchstack
8.1 High Catamaran Theme catamaran Local File Inclusion No login needed ≤ 1.15 CVE-2025-58936 Patchstack
8.1 High Lunna Theme lunna Local File Inclusion No login needed ≤ 1.15 CVE-2025-58935 Patchstack
8.1 High The Gig Theme thegig Local File Inclusion No login needed ≤ 1.18.0 CVE-2025-58934 Patchstack
8.1 High Anubis Theme anubis Local File Inclusion No login needed ≤ 1.25 CVE-2025-58933 Patchstack
8.1 High Prisma Theme prisma Local File Inclusion No login needed ≤ 1.10 CVE-2025-58932 Patchstack
8.1 High Palatio Theme palatio Local File Inclusion No login needed ≤ 1.6 CVE-2025-58931 Patchstack
8.1 High FitFlex Theme fitflex Local File Inclusion No login needed ≤ 1.6 CVE-2025-58930 Patchstack
8.1 High Pantry Theme pantry Local File Inclusion No login needed ≤ 1.4 CVE-2025-58929 Patchstack
8.1 High Heart Theme heart Local File Inclusion No login needed ≤ 1.8 CVE-2025-58928 Patchstack
8.1 High Stallion Theme stallion Local File Inclusion No login needed ≤ 1.17 CVE-2025-58927 Patchstack
8.1 High Cerebrum Theme cerebrum Local File Inclusion No login needed ≤ 1.12 CVE-2025-58926 Patchstack
8.1 High Neptunus Theme neptunus Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-58925 Patchstack
8.1 High Critique Theme critique Local File Inclusion No login needed ≤ 1.17 CVE-2025-58923 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only