WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,651–3,700 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 74 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Takeout Theme takeout Local File Inclusion No login needed ≤ 1.3.0 CVE-2025-58901 Patchstack
8.1 High UniTravel Theme unitravel Local File Inclusion No login needed ≤ 1.4.2 CVE-2025-58900 Patchstack
8.1 High Frame Theme frame Local File Inclusion No login needed ≤ 2.4.0 CVE-2025-58899 Patchstack
8.1 High HealthHub Theme healthhub Local File Inclusion No login needed ≤ 1.3.0 CVE-2025-58898 Patchstack
8.1 High Otaku Theme otaku Local File Inclusion No login needed ≤ 1.8.0 CVE-2025-58896 Patchstack
8.1 High Integro Theme integro Local File Inclusion No login needed ≤ 1.8.0 CVE-2025-58895 Patchstack
8.1 High Good Mood Theme good-mood Local File Inclusion No login needed ≤ 1.16 CVE-2025-58894 Patchstack
8.1 High Alright Theme alright Local File Inclusion No login needed ≤ 1.6.1 CVE-2025-58893 Patchstack
8.1 High Tourimo Theme tourimo Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-58892 Patchstack
8.1 High Sanger Theme sanger Local File Inclusion No login needed ≤ 1.24.0 CVE-2025-58891 Patchstack
8.1 High Playful Theme playful Local File Inclusion No login needed ≤ 1.19.0 CVE-2025-58890 Patchstack
8.1 High Towny Theme towny Local File Inclusion No login needed ≤ 1.16 CVE-2025-58889 Patchstack
8.1 High The Flash Theme theflash Local File Inclusion No login needed ≤ 1.15 CVE-2025-58888 Patchstack
8.1 High Pathfinder Theme pathfinder Local File Inclusion No login needed ≤ 1.16 CVE-2025-58885 Patchstack
8.1 High Festy Theme festy Local File Inclusion No login needed ≤ 1.13.0 CVE-2025-58879 Patchstack
7.5 High Javo Core Plugin javo-core Broken Access Control Arbitrary Content Deletion No login needed ≤ 3.0.0.529 CVE-2025-58877 Patchstack
8.1 High Algenix Theme algenix Local File Inclusion No login needed ≤ 1.0 CVE-2025-58803 Patchstack
8.8 High Hotel Listing Plugin hotel-listing Privilege Escalation ≤ 1.4.0 CVE-2025-58710 Patchstack
8.1 High Legacy Theme legacy Local File Inclusion No login needed ≤ 1.9 CVE-2025-58709 Patchstack
8.1 High 777 Theme triple-seven Local File Inclusion No login needed ≤ 1.3 CVE-2025-58708 Patchstack
8.1 High Woo Hoo Theme woohoo Local File Inclusion No login needed ≤ 1.25 CVE-2025-58706 Patchstack
8.1 High Paragon Theme paragon Local File Inclusion No login needed ≤ 1.1 CVE-2025-58225 Patchstack
7.1 High Logtik Plugin logtik Cross-Site Scripting No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-57897 Patchstack
7.2 High PostX Plugin ultimate-post Privilege Escalation ≤ 4.1.35 Fixed in 4.1.36 CVE-2025-55707 Patchstack
7.1 High PostX Plugin ultimate-post Broken Access Control ≤ 4.1.36 Fixed in 4.1.37 CVE-2025-54751 Patchstack
8.1 High Hygia Theme hygia Local File Inclusion No login needed ≤ 1.16 CVE-2025-53453 Patchstack
8.1 High Convex Theme convex Local File Inclusion No login needed ≤ 1.11 CVE-2025-53449 Patchstack
8.1 High Rally Theme rally Local File Inclusion No login needed ≤ 1.1 CVE-2025-53448 Patchstack
8.1 High Assembly Theme assembly Local File Inclusion No login needed ≤ 1.1 CVE-2025-53447 Patchstack
8.1 High Beautique Theme beautique Local File Inclusion No login needed ≤ 1.5 CVE-2025-53446 Patchstack
8.1 High Catwalk Theme catwalk Local File Inclusion No login needed ≤ 1.4 CVE-2025-53445 Patchstack
8.1 High Smash Theme smash Local File Inclusion No login needed ≤ 1.7 CVE-2025-53443 Patchstack
8.1 High Rentic Theme rentic Local File Inclusion No login needed ≤ 1.1 CVE-2025-53442 Patchstack
8.1 High Greeny Theme greeny Local File Inclusion No login needed ≤ 2.6 CVE-2025-53441 Patchstack
8.1 High Harper Theme harper Local File Inclusion No login needed ≤ 1.13 CVE-2025-53439 Patchstack
8.1 High FitLine Theme fitline Local File Inclusion No login needed ≤ 1.6 CVE-2025-53438 Patchstack
8.1 High Greenorganic Plugin greenorganic Local File Inclusion No login needed ≤ 2.45 CVE-2025-53437 Patchstack
8.1 High Monki Plugin monki Local File Inclusion No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-53436 Patchstack
8.1 High Plan My Day Theme planmyday Local File Inclusion No login needed ≤ 1.1.13 CVE-2025-53435 Patchstack
8.1 High ChildHope Theme childhope Local File Inclusion No login needed ≤ 1.1.8 CVE-2025-53434 Patchstack
8.1 High Echo Theme echo Local File Inclusion No login needed ≤ 1.15.0 CVE-2025-53432 Patchstack
8.1 High Emberlyn Theme emberlyn Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-53431 Patchstack
8.1 High Etta Theme etta Local File Inclusion No login needed ≤ 1.14.0 CVE-2025-53430 Patchstack
8.1 High Exit Game Theme exit-game Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-53429 Patchstack
8.1 High Faith & Hope Theme faith-hope Local File Inclusion No login needed ≤ 2.13.0 CVE-2025-52768 Patchstack
8.1 High Farm Agrico Theme farmagrico Local File Inclusion No login needed ≤ 1.3.11 CVE-2025-52745 Patchstack
8.1 High Femme Theme femme Local File Inclusion No login needed ≤ 1.3.11 CVE-2025-49943 Patchstack
8.1 High Gardis Theme gardis Local File Inclusion No login needed ≤ 1.2.13 CVE-2025-49942 Patchstack
8.1 High GlamChic Theme glamchic Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-49941 Patchstack
7.2 High Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Privilege Escalation ≤ 1.2 Fixed in 1.3 CVE-2025-49379 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only