WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 3,851–3,900 of 9,090 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 78 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Import any XML, CSV or Excel File to WordPress (WP All Import) Plugin wp-all-import Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Conditional Logic ≤ 3.9.6 CVE-2025-12733 Wordfence
7.6 High 0 Day Analytics Plugin 0-day-analytics SQL Injection ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-64293 Patchstack
7.2 High Easy Email Subscription Plugin email-subscription-with-secure-captcha Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-11994 Wordfence
7.5 High Payment Plugins Braintree For WooCommerce Plugin woo-payment-gateway Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed ≤ 3.2.78 CVE-2025-12903 Wordfence
7.5 High Booking Calendar | Appointment Booking | Bookit Plugin bookit Broken Access Control Missing Authorization to Unauthenticated Stripe Connection No login needed ≤ 2.5.0 CVE-2025-12633 Wordfence
7.1 High Team Members Showcase Plugin wps-team Cross-Site Scripting Reflected XSS No login needed < 3.5.0 Fixed in 3.5.0 CVE-2025-11560 WPScan
8.8 High Blocksy Companion Plugin blocksy-companion Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via SVG Upload Bypass ≤ 2.1.19 CVE-2025-12846 Wordfence
7.5 High Age Restriction Plugin Privilege Escalation Subscriber+ Privilege Escalation ≤ 3.0.2 CVE-2025-11855 WPScan
8.8 High WP Google Maps Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 9.0.48 Fixed in 9.0.48 CVE-2025-11307 WPScan
8.1 High Astra Security Suite – Firewall & Malware Scan Plugin getastra Arbitrary File Upload Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File Upload No login needed ≤ 0.2 CVE-2025-11521 Wordfence
8.8 High Elastic Theme Editor Plugin elastic-theme-editor Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 0.0.3 CVE-2025-12637 Wordfence
7.5 High Auto Amazon Links – Amazon Associates Affiliate Plugin amazon-auto-links Path Traversal Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read No login needed ≤ 5.4.3 CVE-2025-11451 Wordfence
8.8 High Mementor Core Plugin mementor-core Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.2.5 CVE-2025-11168 Wordfence
7.2 High Alex Reservations: Smart Restaurant Booking Plugin alex-reservations Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 2.2.3 CVE-2025-12399 Wordfence
7.2 High Mail Mint Plugin mail-mint Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.18.10 CVE-2025-11967 Wordfence
7.2 High Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy PHP Object Injection WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' ≤ 3.3.8 CVE-2025-12099 Wordfence
8.8 High Better Find and Replace Plugin real-time-auto-find-and-replace Remote Code Execution Authenticated (Subscriber+) Limited Code Injection ≤ 1.7.7 CVE-2025-9334 Wordfence
8.8 High Smart Auto Upload Images Plugin smart-auto-upload-images Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2.0 CVE-2025-12161 Wordfence
7.5 High Asgaros Forum Plugin asgaros-forum SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.1.0 CVE-2025-11452 Wordfence
8.8 High IDonate Plugin idonate Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function 2.1.5 – 2.1.9 CVE-2025-4519 Wordfence
8.1 High LC Wizard Plugin Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation No login needed 1.2.10 – 1.3.0 CVE-2025-5483 Wordfence
8.1 High Alloggio - Hotel Booking Theme alloggio Local File Inclusion Hotel Booking Theme theme <= 1.8 - Local File Inclusion No login needed ≤ 1.8 CVE-2025-64287 Patchstack
7.1 High Import from YML Plugin import-from-yml Cross-Site Scripting No login needed ≤ 3.1.17 Fixed in 4.0.0 CVE-2025-64232 Patchstack
7.1 High Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-64224 Patchstack
7.1 High Easy Social Share Buttons Plugin easy-social-share-buttons3 Cross-Site Scripting No login needed ≤ 10.7.1 Fixed in 10.7.1 CVE-2025-64198 Patchstack
7.1 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting No login needed ≤ 7.2.5 Fixed in 7.2.6 CVE-2025-64196 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62076 Patchstack
7.5 High Simple Payment Plugin simple-payment Local File Inclusion No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62075 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting No login needed ≤ 11.71 Fixed in 11.72 CVE-2025-62074 Patchstack
8.1 High Savory Plugin savory Local File Inclusion No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-62067 Patchstack
7.5 High Revolution Plugin revolution Local File Inclusion ≤ 2.5.8 Fixed in 2.5.8 CVE-2025-62066 Patchstack
7.1 High SureRank Plugin surerank Cross-Site Scripting No login needed ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-62059 Patchstack
7.1 High Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin < 4.2.0 - Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62057 Patchstack
8.1 High Academist Theme academist Local File Inclusion No login needed ≤ 1.3 Fixed in 1.3 CVE-2025-62055 Patchstack
8.1 High Houzez Plugin houzez Local File Inclusion No login needed ≤ 4.2.0 Fixed in 4.2.0 CVE-2025-62053 Patchstack
8.1 High TheGem Theme Elements (for WPBakery) Plugin thegem-elements Local File Inclusion No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62045 Patchstack
7.1 High TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62041 Patchstack
7.1 High YOP Poll Plugin yop-poll Cross-Site Scripting No login needed ≤ 6.5.37 Fixed in 6.5.38 CVE-2025-62040 Patchstack
7.5 High AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2025-62039 Patchstack
7.1 High Togo Plugin togo Cross-Site Scripting No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62036 Patchstack
8.8 High Togo Plugin togo PHP Object Injection ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62035 Patchstack
8.8 High Togo Plugin togo Privilege Escalation ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62034 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62031 Patchstack
8.1 High ITok Plugin itok Local File Inclusion No login needed ≤ 1.1.42 Fixed in 1.1.43.1 CVE-2025-62014 Patchstack
8.1 High Famita Plugin famita Local File Inclusion No login needed ≤ 1.54 Fixed in 1.55.1 CVE-2025-62010 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Local File Inclusion ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-60248 Patchstack
7.1 High TableOn Plugin posts-table-filterable Content Injection No login needed ≤ 1.0.5.1 CVE-2025-60244 Patchstack
7.5 High Download Counter Plugin download-counter Path Traversal Arbitrary File Download No login needed ≤ 1.4 CVE-2025-60242 Patchstack
7.5 High Premmerce Plugin premmerce Local File Inclusion No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-60241 Patchstack
7.5 High AnyComment Plugin anycomment Local File Inclusion No login needed ≤ 0.3.6 CVE-2025-60240 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only