WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,751–3,800 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 76 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High HandL UTM Grabber / Tracker Plugin handl-utm-grabber Cross-Site Scripting Reflected XSS via utm_source No login needed < 2.8.1 Fixed in 2.8.1 CVE-2025-13072 WPScan
7.5 High Hippoo Mobile App for WooCommerce Plugin hippoo Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 1.7.1 CVE-2025-13339 Wordfence
7.5 High The7 Elements Plugin dt-the7-core Local File Inclusion ≤ 2.7.11 Fixed in 2.7.12 CVE-2025-63076 Patchstack
7.5 High The7 Plugin dt-the7 Local File Inclusion ≤ 12.8.1.1 Fixed in 12.8.1.1 CVE-2025-63074 Patchstack
7.5 High UDesign Core Plugin u-design-core Local File Inclusion ≤ 4.14.0 CVE-2025-63062 Patchstack
7.5 High Ronneby Theme Core Plugin ronneby-core Local File Inclusion ≤ 1.5.68 CVE-2025-63036 Patchstack
7.1 High New User Approve Plugin new-user-approve Cross-Site Request Forgery No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-63030 Patchstack
7.5 High North - Required Plugin north-plugin Local File Inclusion Required Plugin plugin <= 1.4.2 - Local File Inclusion ≤ 1.4.2 CVE-2025-63003 Patchstack
8.5 High Image&Video FullScreen Background Plugin lbg_fullscreen_fullwidth_slider SQL Injection ≤ 1.6.7 CVE-2025-62093 Patchstack
7.1 High Create Posts & Terms Plugin create-posts-terms Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-49351 Patchstack
7.1 High WP sIFR Plugin wp-sifr Cross-Site Request Forgery No login needed ≤ 0.6.8.1 CVE-2025-49347 Patchstack
7.1 High PDF Creator Lite Plugin pdf-creator-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-49341 Patchstack
7.1 High Rencontre Plugin rencontre Cross-Site Request Forgery No login needed ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67534 Patchstack
7.1 High Themify Portfolio Post Plugin themify-portfolio-post Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-67533 Patchstack
7.5 High Hara Plugin hara Local File Inclusion ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-67532 Patchstack
7.5 High Turitor Theme turitor Local File Inclusion ≤ 1.5.3 Fixed in 1.5.3 CVE-2025-67531 Patchstack
7.5 High Besa Plugin besa Local File Inclusion ≤ 2.3.15 Fixed in 2.3.16 CVE-2025-67530 Patchstack
7.5 High Fashion Theme fashion2 Local File Inclusion ≤ 5.3.0 Fixed in 5.3.0 CVE-2025-67529 Patchstack
7.5 High Urna Plugin urna Local File Inclusion ≤ 2.5.12 Fixed in 2.5.13 CVE-2025-67528 Patchstack
7.5 High Digiqole Theme digiqole Local File Inclusion ≤ 2.2.7 Fixed in 2.2.7 CVE-2025-67527 Patchstack
7.5 High Sailing Theme sailing Local File Inclusion ≤ 4.4.6 Fixed in 4.4.6 CVE-2025-67526 Patchstack
7.5 High ekommart Theme ekommart Local File Inclusion ≤ 4.3.1 Fixed in 4.3.1 CVE-2025-67525 Patchstack
7.5 High Jobmonster Elementor Addon Plugin jobmonster-addon Local File Inclusion ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-67524 Patchstack
7.5 High Exhibz Theme exhibz Local File Inclusion ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-67523 Patchstack
7.5 High Jobmonster Theme noo-jobmonster Local File Inclusion ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-67522 Patchstack
7.5 High Select Core Plugin select-core Local File Inclusion ≤ 2.6 Fixed in 2.6 CVE-2025-67521 Patchstack
7.6 High Media Library Tools Plugin media-library-tools SQL Injection ≤ 1.6.15 Fixed in 1.7.0 CVE-2025-67520 Patchstack
7.6 High Ninja Tables Plugin ninja-tables SQL Injection ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-67519 Patchstack
8.5 High Accordion Slider PRO Plugin accordion_slider_pro SQL Injection ≤ 1.2 Fixed in 1.3 CVE-2025-67518 Patchstack
8.5 High ArtPlacer Widget Plugin artplacer-widget SQL Injection ≤ 2.22.9.2 Fixed in 2.23 CVE-2025-67517 Patchstack
8.5 High Store Locator Plugin agile-store-locator SQL Injection ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-67516 Patchstack
8.8 High Wilmër Plugin wilmer Local File Inclusion ≤ 3.5 Fixed in 3.5 CVE-2025-67515 Patchstack
7.2 High Social Reviews & Recommendations Plugin fb-reviews-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Social Media Reviews No login needed ≤ 2.5 CVE-2025-12705 Wordfence
7.1 High Custom Admin Menu Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2025-13071 WPScan
7.2 High Login Security, FireWall, Malware removal by CleanTalk Plugin security-malware-firewall Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Page URL No login needed ≤ 2.168 CVE-2025-13604 Wordfence
8.8 High Starter Templates Plugin astra-sites Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass ≤ 4.4.41 CVE-2025-13065 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Import ZIP 4.5.4 – 4.5.7 CVE-2025-12966 Wordfence
7.2 High Rich Shortcodes for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Google Review No login needed ≤ 6.8 CVE-2025-12499 Wordfence
7.2 High Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Google Reviews No login needed ≤ 13.2.4 CVE-2025-12510 Wordfence
8.1 High Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.29 CVE-2025-13614 Wordfence
8.8 High User Generator and Importer Plugin user-importer-and-generator Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Arbitrary Administrator Account Creation No login needed ≤ 1.2.2 CVE-2025-12879 Wordfence
8.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Local File Inclusion Unauthenticated Local File Inclusion via controller No login needed ≤ 3.6.32 CVE-2025-12851 Wordfence
7.5 High My auctions allegro Plugin my-auctions-allegro-free-edition SQL Injection Unauthenticated SQL Injection via auction_id No login needed ≤ 3.6.32 CVE-2025-12850 Wordfence
8.8 High Auto Thumbnailer Plugin auto-thumbnailer Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0 CVE-2025-12154 Wordfence
8.8 High Featured Image via URL Plugin featured-image-via-url Arbitrary File Upload Authenticated (Contributor+) Arbitrary FIle Upload ≤ 0.1 CVE-2025-12153 Wordfence
8.8 High ContentStudio Plugin contentstudio Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 1.3.7 CVE-2025-12181 Wordfence
8.8 High Demo Importer Plus Plugin demo-importer-plus Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass ≤ 2.0.6 CVE-2025-13066 Wordfence
8.8 High PostGallery Plugin postgallery Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.12.5 CVE-2025-13543 Wordfence
7.2 High Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto Plugin codistoconnect Cross-Site Scripting Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-11727 Wordfence
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only