WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,701–3,750 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 75 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Strux Theme strux Local File Inclusion No login needed ≤ 1.9 CVE-2025-49371 Patchstack
8.1 High Lymcoin Theme lymcoin Local File Inclusion No login needed ≤ 1.3.12 CVE-2025-49370 Patchstack
8.1 High Lettuce Theme lettuce Local File Inclusion No login needed ≤ 1.1.7 CVE-2025-49369 Patchstack
8.1 High Palladio Theme palladio Local File Inclusion No login needed ≤ 1.1.10 CVE-2025-49368 Patchstack
8.1 High Monyxi Theme monyxi Local File Inclusion No login needed ≤ 1.1.8 CVE-2025-49367 Patchstack
8.1 High Hanani Theme hanani Local File Inclusion No login needed ≤ 1.2.11 CVE-2025-49366 Patchstack
8.1 High Jack Well Theme jack-well Local File Inclusion No login needed ≤ 1.0.14 CVE-2025-49365 Patchstack
8.1 High Ludos Paradise Theme ludos-paradise Local File Inclusion No login needed ≤ 2.1.3 CVE-2025-49364 Patchstack
8.1 High Kings & Queens Theme kings-queens Local File Inclusion No login needed ≤ 1.1.16 CVE-2025-49363 Patchstack
8.1 High Gracioza Theme gracioza Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-49362 Patchstack
8.1 High Mamita Theme mamita Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-49361 Patchstack
8.1 High Militarology Theme militarology Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-49360 Patchstack
8.1 High ShieldGroup Theme shieldgroup Local File Inclusion No login needed ≤ 2.13 CVE-2025-49359 Patchstack
8.5 High PopupKit Plugin popup-builder-block SQL Injection ≤ 2.1.5 Fixed in 2.2.0 CVE-2025-14314 Patchstack
7.5 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Broken Access Control The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token No login needed ≤ 3.13.2 CVE-2025-11924 Wordfence
8.1 High WPCOM Member Plugin wpcom-member Authentication Bypass Authentication Bypass via Weak OTP No login needed ≤ 1.7.16 CVE-2025-14002 Wordfence
7.5 High Stockholm Plugin stockholm Local File Inclusion ≤ 9.14.1 CVE-2025-68068 Patchstack
7.5 High Stockholm Core Plugin stockholm-core Local File Inclusion ≤ 2.4.6 CVE-2025-68067 Patchstack
7.5 High Soledad Theme soledad Local File Inclusion ≤ 8.7.0 CVE-2025-68066 Patchstack
7.5 High Hub Core Plugin hub-core Local File Inclusion < 6.0.2 Fixed in 6.0.2 CVE-2025-68065 Patchstack
7.5 High MinimogWP Theme minimog Local File Inclusion ≤ 3.9.6 CVE-2025-68062 Patchstack
7.5 High EduMall Theme edumall Local File Inclusion ≤ 4.4.7 CVE-2025-68061 Patchstack
8.5 High LBG Zoominoutslider Plugin lbg_zoominoutslider SQL Injection ≤ 5.4.4 Fixed in 5.4.5 CVE-2025-68056 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68055 Patchstack
8.5 High CountDown With Image or Video Background Plugin countdown_with_background SQL Injection ≤ 1.5 CVE-2025-68054 Patchstack
8.5 High xPromoter Plugin top_bar_promoter SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-68053 Patchstack
7.6 High Newsletter Plugin newsletter SQL Injection ≤ 9.0.9 Fixed in 9.1.0 CVE-2025-67999 Patchstack
7.6 High Broken Link Checker Plugin broken-link-checker-seo SQL Injection ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-67962 Patchstack
8.5 High All In One SEO Pack Plugin all-in-one-seo-pack SQL Injection ≤ 4.9.1 Fixed in 4.9.1.1 CVE-2025-67950 Patchstack
7.5 High Booking Calendar Plugin booking SQL Injection Unauthenticated SQL Injection via dates_to_check No login needed ≤ 10.14.8 CVE-2025-14383 Wordfence
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting Reflected XSS No login needed < 1.11.4 Fixed in 1.11.4 CVE-2025-13355 WPScan
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting Reflected XSS No login needed < 1.11.3 Fixed in 1.11.3 CVE-2025-12684 WPScan
7.5 High wpForo Forum Plugin wpforo SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.4.12 CVE-2025-13126 Wordfence
7.5 High افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce Plugin payamito-sms-woocommerce SQL Injection Unauthenticated Time-Based Blind SQL Injection No login needed ≤ 1.3.5 CVE-2025-13077 Wordfence
8.8 High Doubly Plugin doubly PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via ZIP File Import ≤ 1.0.46 CVE-2025-14476 Wordfence
8.1 High Extensive VC Addons for WPBakery page builder Plugin extensive-vc-addon Local File Inclusion Unauthenticated Local File Inclusion via 'shortcode_name' Parameter No login needed ≤ 1.9.1 CVE-2025-14475 Wordfence
8.8 High WP3D Model Import Viewer Plugin wp3d-model-import-block Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.7 CVE-2025-13094 Wordfence
8.8 High Postem Ipsum Plugin postem-ipsum Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation in postem_ipsum_generate_users ≤ 3.0.1 CVE-2025-14397 Wordfence
7.5 High WP Directory Kit Plugin wpdirectorykit SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.4.7 CVE-2025-13089 Wordfence
7.3 High WooMulti Plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 1.7 CVE-2025-12835 WPScan
7.5 High FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder SQL Injection Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection No login needed ≤ 3.13.1.5 CVE-2025-14169 Wordfence
7.5 High WPNakama Plugin wpnakama SQL Injection Unauthenticated SQL Injection via 'order_by' Parameter No login needed ≤ 0.6.3 CVE-2025-14068 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 6.4.8 CVE-2025-12570 Wordfence
8.1 High Blaze Demo Importer Plugin blaze-demo-importer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Database Reset and File Deletion 1.0.0 – 1.0.13 CVE-2025-13334 Wordfence
8.1 High Visitor Logic Lite Plugin logic-pro PHP Object Injection Unauthenticated PHP Object Injection via 'lpblocks' Cookie No login needed ≤ 1.0.3 CVE-2025-14044 Wordfence
8.8 High Infility Global Plugin infility-global Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.14.42 CVE-2025-12968 Wordfence
8.8 High Player Leaderboard Plugin player-leaderboard Local File Inclusion Authenticated (Contributor+) Local File Inclusion 1.0.0 – 1.0.2 CVE-2025-12824 Wordfence
7.5 High LT Unleashed Plugin lt-unleashed Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Parameter ≤ 1.1.1 CVE-2025-13886 Wordfence
8.8 High Video Merchant Plugin video-merchant Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 5.0.4 CVE-2025-14390 Wordfence
7.1 High HandL UTM Grabber / Tracker Plugin handl-utm-grabber Cross-Site Scripting Reflected XSS via handl_landing_page No login needed < 2.8.1 Fixed in 2.8.1 CVE-2025-13073 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only