WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 3,951–4,000 of 9,213 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 80 of 185
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Flo Forms – Easy Drag & Drop Form Builder Plugin flo-forms Cross-Site Scripting Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG Upload No login needed ≤ 1.0.43 CVE-2025-13159 Wordfence
7.2 High WPBookit Plugin wpbookit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-12135 Wordfence
8.8 High URL Image Importer Plugin url-image-importer Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload 1.0 – 1.0.6 CVE-2025-12138 Wordfence
8.1 High WP AUDIO GALLERY Plugin wp-audio-gallery Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter ≤ 2.0 CVE-2025-13322 Wordfence
7.2 High GiveWP - Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name' No login needed ≤ 4.13.0 CVE-2025-13206 Wordfence
8.0 High Code Snippets Plugin code-snippets Remote Code Execution Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains ≤ 3.9.1 CVE-2025-13035 Wordfence
7.2 High Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers Plugin rafflepress Cross-Site Scripting Get More Website Traffic, Email Subscribers, and Social Followers <= 1.12.19 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.12.19 CVE-2025-12484 Wordfence
7.2 High WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer PHP Object Injection Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import ≤ 7.33.1 CVE-2025-13145 Wordfence
7.5 High Community Events Plugin community-events SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.5.4 CVE-2025-12646 Wordfence
8.8 High Enable SVG, WebP, and ICO Upload Plugin enable-svg-webp-ico-upload Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via ICO Upload Bypass ≤ 1.1.3 CVE-2025-13069 Wordfence
7.5 High Live sales notification for WooCommerce Plugin Broken Access Control Missing Authorization to Unauthenticated Customer Data Exposure No login needed ≤ 2.3.39 CVE-2025-12955 Wordfence
7.2 High Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2025-4212 Wordfence
8.8 High Category and Product Woocommerce Tabs Plugin category-and-product-woocommerce-tabs Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2025-13088 Wordfence
8.8 High WP Dropzone Plugin wp-dropzone Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.1.0 CVE-2025-12775 Wordfence
8.1 High Pie Forms for WP Plugin pie-forms-for-wp Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6 CVE-2025-12528 Wordfence
7.1 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.1.10 CVE-2025-12411 Wordfence
7.2 High Multiple Roles per User Plugin multiple-roles-per-user Broken Access Control Missing Authorization to Authenticated (Custom+) Privilege Escalation ≤ 1.0 CVE-2025-11620 Wordfence
8.1 High Gravity Forms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Legacy Chunked Upload No login needed ≤ 2.9.21.1 CVE-2025-12974 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
7.2 High Creta Testimonial Showcase Plugin creta-testimonial-showcase Local File Inclusion Editor+ Local File Inclusion < 1.2.4 Fixed in 1.2.4 CVE-2025-10686 WPScan
7.2 High SNORDIAN's H5PxAPIkatchu Plugin h5pxapikatchu Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via insert_data No login needed ≤ 0.4.17 CVE-2025-12904 Wordfence
7.1 High AI Engine Plugin ai-engine PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization ≤ 3.1.8 CVE-2025-12844 Wordfence
8.8 High LifterLMS Plugin lifterlms Privilege Escalation WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation 3.5.3 – 3.41.1, 4.0.0 – 4.21.3, 5.0.0 – 5.10.0, … CVE-2025-11923 Wordfence
8.8 High Import any XML, CSV or Excel File to WordPress (WP All Import) Plugin wp-all-import Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Conditional Logic ≤ 3.9.6 CVE-2025-12733 Wordfence
7.6 High 0 Day Analytics Plugin 0-day-analytics SQL Injection ≤ 4.0.0 Fixed in 4.1.0 CVE-2025-64293 Patchstack
7.2 High Easy Email Subscription Plugin email-subscription-with-secure-captcha Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-11994 Wordfence
7.5 High Payment Plugins Braintree For WooCommerce Plugin woo-payment-gateway Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed ≤ 3.2.78 CVE-2025-12903 Wordfence
7.5 High Booking Calendar | Appointment Booking | Bookit Plugin bookit Broken Access Control Missing Authorization to Unauthenticated Stripe Connection No login needed ≤ 2.5.0 CVE-2025-12633 Wordfence
7.1 High Team Members Showcase Plugin wps-team Cross-Site Scripting Reflected XSS No login needed < 3.5.0 Fixed in 3.5.0 CVE-2025-11560 WPScan
8.8 High Blocksy Companion Plugin blocksy-companion Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via SVG Upload Bypass ≤ 2.1.19 CVE-2025-12846 Wordfence
7.5 High Age Restriction Plugin Privilege Escalation Subscriber+ Privilege Escalation ≤ 3.0.2 CVE-2025-11855 WPScan
8.8 High WP Google Maps Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 9.0.48 Fixed in 9.0.48 CVE-2025-11307 WPScan
8.1 High Astra Security Suite – Firewall & Malware Scan Plugin getastra Arbitrary File Upload Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File Upload No login needed ≤ 0.2 CVE-2025-11521 Wordfence
8.8 High Elastic Theme Editor Plugin elastic-theme-editor Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 0.0.3 CVE-2025-12637 Wordfence
7.5 High Auto Amazon Links – Amazon Associates Affiliate Plugin amazon-auto-links Path Traversal Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read No login needed ≤ 5.4.3 CVE-2025-11451 Wordfence
8.8 High Mementor Core Plugin mementor-core Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.2.5 CVE-2025-11168 Wordfence
7.2 High Alex Reservations: Smart Restaurant Booking Plugin alex-reservations Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 2.2.3 CVE-2025-12399 Wordfence
7.2 High Mail Mint Plugin mail-mint Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.18.10 CVE-2025-11967 Wordfence
7.2 High Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy PHP Object Injection WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' ≤ 3.3.8 CVE-2025-12099 Wordfence
8.8 High Better Find and Replace Plugin real-time-auto-find-and-replace Remote Code Execution Authenticated (Subscriber+) Limited Code Injection ≤ 1.7.7 CVE-2025-9334 Wordfence
8.8 High Smart Auto Upload Images Plugin smart-auto-upload-images Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2.0 CVE-2025-12161 Wordfence
7.5 High Asgaros Forum Plugin asgaros-forum SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.1.0 CVE-2025-11452 Wordfence
8.8 High IDonate Plugin idonate Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function 2.1.5 – 2.1.9 CVE-2025-4519 Wordfence
8.1 High LC Wizard Plugin Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation No login needed 1.2.10 – 1.3.0 CVE-2025-5483 Wordfence
8.1 High Alloggio - Hotel Booking Theme alloggio Local File Inclusion Hotel Booking Theme theme <= 1.8 - Local File Inclusion No login needed ≤ 1.8 CVE-2025-64287 Patchstack
7.1 High Import from YML Plugin import-from-yml Cross-Site Scripting No login needed ≤ 3.1.17 Fixed in 4.0.0 CVE-2025-64232 Patchstack
7.1 High Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-64224 Patchstack
7.1 High Easy Social Share Buttons Plugin easy-social-share-buttons3 Cross-Site Scripting No login needed ≤ 10.7.1 Fixed in 10.7.1 CVE-2025-64198 Patchstack
7.1 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting No login needed ≤ 7.2.5 Fixed in 7.2.6 CVE-2025-64196 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-62076 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only