WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,801–3,850 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 77 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Modula Plugin modula-best-grid-gallery Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion 2.13.1 – 2.13.2 CVE-2025-13645 Wordfence
7.5 High VikRentCar Car Rental Management System Plugin vikrentcar SQL Injection Authenticated (Author+) SQL Injection via 'month' Parameter No login needed ≤ 1.4.4 CVE-2025-13724 Wordfence
8.1 High SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Plugin suremails Arbitrary File Upload SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.0 CVE-2025-13516 Wordfence
7.7 High DB Access Plugin SQL Injection Subscriber+ SQLi ≤ 0.8.7 CVE-2025-13000 WPScan
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.5.17 CVE-2025-13387 Wordfence
8.8 High Cost Calculator Builder Plugin cost-calculator-builder Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.6.3 CVE-2025-12529 Wordfence
7.2 High Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 2.0 CVE-2025-13692 Wordfence
8.8 High Blubrry PowerPress Plugin powerpress Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post' ≤ 11.15.2 CVE-2025-13536 Wordfence
8.8 High Tiger Theme Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 101.2.1 CVE-2025-13680 Wordfence
7.5 High SKT PayPal for WooCommerce Plugin skt-paypal-for-woocommerce Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.4 CVE-2025-7820 Wordfence
8.6 High Tax Service Electronic HDM Plugin virtual-hdm-for-taxservice-am Cross-Site Request Forgery Unauthenticated Arbitrary SQL Execution No login needed < 1.2.1 Fixed in 1.2.1 CVE-2025-12061 WPScan
7.2 High ProjectList Plugin projectlist Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload ≤ 0.3.0 CVE-2025-13376 Wordfence
7.2 High Telegram Bot & Channel Plugin telegram-bot Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Telegram Username No login needed ≤ 4.1 CVE-2025-13068 Wordfence
7.1 High Broken Link Manager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.6.5 CVE-2025-12629 WPScan
7.1 High Studiocart Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.9.0 CVE-2024-14015 WPScan
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id No login needed ≤ 4.95 CVE-2025-7402 Wordfence
7.5 High OneClick Chat to Order Plugin oneclick-whatsapp-order Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.8 CVE-2025-13526 Wordfence
7.5 High CP Contact Form with PayPal Plugin cp-contact-form-with-paypal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Payment Confirmation No login needed ≤ 1.3.56 CVE-2025-13384 Wordfence
8.8 High Zegen Core Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.0.1 CVE-2025-11087 Wordfence
7.2 High S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator Plugin s2b-ai-assistant Arbitrary File Upload ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.8 - Authenticated (Editor+) Arbitrary File Upload ≤ 1.7.8 CVE-2025-12973 Wordfence
8.5 High KiviCare Plugin kivicare-clinic-management-system SQL Injection ≤ 3.6.13 Fixed in 3.6.14 CVE-2025-66095 Patchstack
7.2 High WP Webhooks Plugin wp-webhooks PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66073 Patchstack
7.2 High Email Subscribers & Newsletters Plugin email-subscribers PHP Object Injection ≤ 5.9.10 Fixed in 5.9.11 CVE-2025-66055 Patchstack
7.2 High Simple User Registration Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 6.6 CVE-2025-12160 Wordfence
7.5 High WP Directory Kit Plugin wpdirectorykit SQL Injection Unauthenticated SQL Injection via select_2_ajax() Function No login needed ≤ 1.4.3 CVE-2025-13138 Wordfence
8.8 High Vitepos – Point of Sale (POS) for WooCommerce Plugin vitepos-lite Arbitrary File Upload Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution ≤ 3.3.0 CVE-2025-13156 Wordfence
8.8 High Realty Portal Plugin realty-portal Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update 0.1 – 0.4.1 CVE-2025-11985 Wordfence
7.1 High Flo Forms – Easy Drag & Drop Form Builder Plugin flo-forms Cross-Site Scripting Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG Upload No login needed ≤ 1.0.43 CVE-2025-13159 Wordfence
7.2 High WPBookit Plugin wpbookit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-12135 Wordfence
8.8 High URL Image Importer Plugin url-image-importer Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload 1.0 – 1.0.6 CVE-2025-12138 Wordfence
8.1 High WP AUDIO GALLERY Plugin wp-audio-gallery Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter ≤ 2.0 CVE-2025-13322 Wordfence
7.2 High GiveWP - Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name' No login needed ≤ 4.13.0 CVE-2025-13206 Wordfence
8.0 High Code Snippets Plugin code-snippets Remote Code Execution Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains ≤ 3.9.1 CVE-2025-13035 Wordfence
7.2 High Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers Plugin rafflepress Cross-Site Scripting Get More Website Traffic, Email Subscribers, and Social Followers <= 1.12.19 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.12.19 CVE-2025-12484 Wordfence
7.2 High WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer PHP Object Injection Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import ≤ 7.33.1 CVE-2025-13145 Wordfence
7.5 High Community Events Plugin community-events SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.5.4 CVE-2025-12646 Wordfence
8.8 High Enable SVG, WebP, and ICO Upload Plugin enable-svg-webp-ico-upload Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via ICO Upload Bypass ≤ 1.1.3 CVE-2025-13069 Wordfence
7.5 High Live sales notification for WooCommerce Plugin Broken Access Control Missing Authorization to Unauthenticated Customer Data Exposure No login needed ≤ 2.3.39 CVE-2025-12955 Wordfence
7.2 High Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2025-4212 Wordfence
8.8 High Category and Product Woocommerce Tabs Plugin category-and-product-woocommerce-tabs Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2025-13088 Wordfence
8.8 High WP Dropzone Plugin wp-dropzone Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.1.0 CVE-2025-12775 Wordfence
8.1 High Pie Forms for WP Plugin pie-forms-for-wp Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6 CVE-2025-12528 Wordfence
7.1 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.1.10 CVE-2025-12411 Wordfence
7.2 High Multiple Roles per User Plugin multiple-roles-per-user Broken Access Control Missing Authorization to Authenticated (Custom+) Privilege Escalation ≤ 1.0 CVE-2025-11620 Wordfence
8.1 High Gravity Forms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Legacy Chunked Upload No login needed ≤ 2.9.21.1 CVE-2025-12974 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
7.2 High Creta Testimonial Showcase Plugin creta-testimonial-showcase Local File Inclusion Editor+ Local File Inclusion < 1.2.4 Fixed in 1.2.4 CVE-2025-10686 WPScan
7.2 High SNORDIAN's H5PxAPIkatchu Plugin h5pxapikatchu Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via insert_data No login needed ≤ 0.4.17 CVE-2025-12904 Wordfence
7.1 High AI Engine Plugin ai-engine PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization ≤ 3.1.8 CVE-2025-12844 Wordfence
8.8 High LifterLMS Plugin lifterlms Privilege Escalation WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation 3.5.3 – 3.41.1, 4.0.0 – 4.21.3, 5.0.0 – 5.10.0, … CVE-2025-11923 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only