WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,751–3,800 of 6,509 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 76 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Review Wave – Google Places Reviews Plugin review-wave-google-places-reviews Cross-Site Request Forgery Google Places Reviews plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.4.7 CVE-2025-39442 Patchstack
7.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.32 Fixed in 2.2.33 CVE-2025-39452 Patchstack
7.1 High IP2Location Variables Plugin ip2location-variables Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.9.5 Fixed in 2.9.6 CVE-2025-39455 Patchstack
7.5 High Docket Cache Plugin docket-cache Local File Inclusion No login needed ≤ 24.07.02 Fixed in 24.07.03 CVE-2025-39461 Patchstack
7.5 High Smart Agreements Plugin smart-agreements Local File Inclusion No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-39462 Patchstack
7.1 High AdminQuickbar Plugin adminquickbar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-39464 Patchstack
7.6 High BMA Lite Plugin bma-lite-appointment-booking-and-scheduling SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-39518 Patchstack
7.1 High Site Search 360 Plugin site-search-360 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to stored XSS No login needed ≤ 2.1.8 CVE-2025-39530 Patchstack
7.4 High WP Tools Plugin wptools Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 5.18 Fixed in 5.19 CVE-2025-39544 Patchstack
7.1 High Internal Link Optimiser Plugin internal-link-finder Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.1.3 Fixed in 5.1.4 CVE-2025-39547 Patchstack
7.1 High Right Click Disable OR Ban Plugin right-click-disable-or-ban Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.17 Fixed in 1.2.0 CVE-2025-39548 Patchstack
7.6 High Hostel Plugin hostel SQL Injection ≤ 1.1.5.6 Fixed in 1.1.5.7 CVE-2025-39566 Patchstack
8.8 High WPCOM Member Plugin wpcom-member Local File Inclusion ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-39570 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion ≤ 4.0.25 Fixed in 4.0.26 CVE-2025-39584 Patchstack
7.5 High Subscribe to Unlock Lite Plugin subscribe-to-unlock-lite Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-39592 Patchstack
8.3 High FS Poster Plugin fs-poster Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 6.5.8 Fixed in 7.1.8 CVE-2025-30960 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.1 CVE-2025-32923 Patchstack
7.1 High SEO Tools Plugin seo-automatic-seo-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.7 CVE-2025-30984 Patchstack
7.1 High Easy Contact Plugin easy-contact Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.2 CVE-2025-30970 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-27011 Patchstack
7.5 High Unlimited Timeline Plugin unlimited-timeline Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.1 CVE-2025-27008 Patchstack
7.5 High JetMenu Plugin jet-menu Broken Access Control No login needed ≤ 2.4.9 Fixed in 2.4.9.1 CVE-2025-26953 Patchstack
7.6 High Kargo Entegratör Plugin kargo-entegrator SQL Injection ≤ 1.1.14 Fixed in 1.1.15 CVE-2025-26908 Patchstack
8.1 High Arkhe Plugin arkhe Cross-Site Request Forgery CSRF to Local File Inclusion No login needed ≤ 3.12.0 CVE-2025-26748 Patchstack
7.1 High Advanced Custom Fields: Link Picker Field Plugin acf-link-picker-field Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-26746 Patchstack
7.5 High Macro Calculator with Admin Email Optin & Data Plugin macro-admin-email-data-optin-calculator Information Disclosure Multiple Vulnerabilities No login needed ≤ 1.0 CVE-2025-26730 Patchstack
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8.0 CVE-2025-22263 Patchstack
7.1 High SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Scripting No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-31011 Patchstack
7.1 High FS Poster Plugin fs-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.5.8 Fixed in 6.5.9 CVE-2025-30962 Patchstack
8.8 High Administrator Z Plugin administrator-z Privilege Escalation ≤ 2025.03.24 Fixed in 2025.03.27 CVE-2025-26959 Patchstack
7.5 High JetBlog Plugin jet-blog Broken Access Control No login needed ≤ 2.4.3 Fixed in 2.4.3.1 CVE-2025-26958 Patchstack
7.1 High ZooEffect Plugin 1-jquery-photo-gallery-slideshow-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.11 CVE-2025-26954 Patchstack
7.5 High JetPopup Plugin jet-popup Broken Access Control No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2025-26944 Patchstack
7.5 High JetTricks Plugin jet-tricks Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.5.1.1 CVE-2025-26942 Patchstack
7.5 High Coming Soon, Maintenance Mode Plugin site-mode Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-26894 Patchstack
7.5 High hockeydata LOS Plugin hockeydata-los Local File Inclusion No login needed ≤ 1.2.4 CVE-2025-26889 Patchstack
7.1 High Advance WP Query Search Filter Plugin advance-wp-query-search-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.10 CVE-2025-26743 Patchstack
8.8 High Email Notifications for Updates Plugin wp-update-mail-notification Privilege Escalation ≤ 1.1.6 Fixed in 1.2.0 CVE-2025-26741 Patchstack
7.5 High Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-32929 Patchstack
7.1 High Landing Page Cat Plugin landing-page-cat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-26992 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-27009 Patchstack
8.5 High Error Log Viewer Plugin error-log-viewer-wp SQL Injection ≤ 1.0.5 CVE-2025-32681 Patchstack
8.1 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-32672 Patchstack
7.5 High Print Science Designer Plugin print-science-designer Path Traversal Arbitrary File Download No login needed ≤ 1.3.155 CVE-2025-32671 Patchstack
8.1 High FAT Cooming Soon Plugin fat-coming-soon Local File Inclusion No login needed ≤ 1.1 CVE-2025-32663 Patchstack
8.1 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion No login needed ≤ 2.3.15 CVE-2025-32656 Patchstack
8.1 High Motors Plugin motors-car-dealership-classified-listings Local File Inclusion No login needed ≤ 1.4.71 Fixed in 1.4.72 CVE-2025-32654 Patchstack
8.5 High Accessibility Suite Plugin online-accessibility SQL Injection ≤ 4.18 Fixed in 4.19 CVE-2025-32650 Patchstack
8.6 High Database Toolset Plugin database-toolset Arbitrary File Deletion No login needed ≤ 1.8.4 CVE-2025-32633 Patchstack
7.1 High Automatic Ban IP Plugin automatic-ban-ip Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 CVE-2025-32632 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only