WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,051–4,100 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 82 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Official Integration for Billingo Plugin billingo Privilege Escalation ≤ 4.3.0 CVE-2025-49950 Patchstack
7.1 High WP Super Edit Plugin wp-super-edit Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2025-49948 Patchstack
7.1 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Cross-Site Scripting Custom Signup Fields plugin <= 3.2.3 - Cross Site Scripting (XSS) No login needed ≤ 3.2.3 CVE-2025-49947 Patchstack
7.1 High Auto Login After Registration Plugin auto-login-after-registration Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-49946 Patchstack
7.1 High Shortcode Generator Plugin shortcode-generator Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-49945 Patchstack
7.1 High WPCode Content Ratio Plugin wpcode-content-ratio Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-49944 Patchstack
7.5 High WoodMart Theme woodmart Local File Inclusion ≤ 8.3.2 Fixed in 8.3.2 CVE-2025-49935 Patchstack
7.1 High JetSearch Plugin jet-search Cross-Site Scripting No login needed ≤ 3.5.10 Fixed in 3.5.10.1 CVE-2025-49930 Patchstack
7.2 High Kalium Theme kalium Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.25 Fixed in 3.26 CVE-2025-49926 Patchstack
7.5 High WPLMS Plugin wplms_plugin Broken Access Control No login needed ≤ 1.9.9.7 Fixed in 1.9.9.8 CVE-2025-49925 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.4.2 Fixed in 2.2.5 CVE-2025-49924 Patchstack
7.5 High JetReviews Plugin jet-reviews Local File Inclusion ≤ 3.0.0 Fixed in 3.0.0.1 CVE-2025-49921 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
7.1 High WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder Cross-Site Scripting No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49911 Patchstack
8.2 High WPGuppy Plugin wpguppy-lite Broken Access Control No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-49910 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49378 Patchstack
7.5 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Local File Inclusion No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-48338 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.1.8.8 Fixed in 5.1.8.9 CVE-2025-48098 Patchstack
7.1 High WSAnalytics Plugin wsanalytics-google-analytics-and-dashboards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-48097 Patchstack
7.1 High Password only login Plugin password-only-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-48093 Patchstack
7.1 High Fix Multiple Redirects Plugin fix-multiple-redirects Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-48092 Patchstack
8.5 High AnyComment Plugin anycomment SQL Injection ≤ 0.3.6 CVE-2025-48091 Patchstack
8.8 High Progress Planner Plugin progress-planner Privilege Escalation ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-48082 Patchstack
7.1 High Terms Dictionary Plugin terms-dictionary Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-39534 Patchstack
7.5 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion ≤ 2.1.7 CVE-2025-32657 Patchstack
8.8 High Solar Energy Theme solar PHP Object Injection ≤ 3.5 CVE-2025-32283 Patchstack
8.8 High Insurance Theme insurance PHP Object Injection ≤ 3.5 CVE-2025-31634 Patchstack
7.5 High Tablesome Table Premium Plugin tablesome-premium Broken Access Control No login needed ≤ 1.1.23 CVE-2025-30944 Patchstack
8.1 High Academy LMS Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via Social Login Addon No login needed ≤ 3.3.7 CVE-2025-11086 Wordfence
8.8 High Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed ≤ 3.0 CVE-2025-9890 Wordfence
7.5 High PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon SQL Injection Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection No login needed ≤ 33.0.15 CVE-2025-11691 Wordfence
7.5 High Event Tickets and Registration Plugin event-tickets Price Manipulation Unauthenticated Ticket Payment Bypass No login needed ≤ 5.26.5 CVE-2025-11517 Wordfence
7.2 High 10WebMapBuilder Plugin wd-google-maps Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change No login needed < 1.0.64 Fixed in 1.0.64 CVE-2020-36853 Wordfence
8.8 High Classified Pro Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.0.14 CVE-2025-10706 Wordfence
7.2 High Find And Replace content Plugin find-and-replace-content Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-10313 Wordfence
7.5 High Category and Products Accordion Panel Plugin accordion-panel-for-category-and-products Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2025-11722 Wordfence
7.5 High Outdoor Plugin outdoor SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.3.2 CVE-2025-10743 Wordfence
8.8 High WPBifröst – Instant Passwordless Temporary Login Links Plugin create-temporary-login Broken Access Control Instant Passwordless Temporary Login Links <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.7 CVE-2025-10299 Wordfence
7.5 High External Login Plugin external-login SQL Injection Unauthenticated SQL Injection via log No login needed ≤ 1.11.2 CVE-2025-11177 Wordfence
7.2 High Demo Import Kit Plugin demo-import-kit Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.1.0 CVE-2025-10051 Wordfence
8.8 High Keyy Two Factor Authentication (like Clef) Plugin keyy Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 1.2.3 CVE-2025-10293 Wordfence
7.2 High DocoDoco Store Locator Plugin docodoco-store-locator Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload ≤ 1.0.1 CVE-2025-10754 Wordfence
7.5 High Dynamically Display Posts Plugin dynamically-display-posts SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.1 CVE-2025-11501 Wordfence
7.3 High Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity Theme Privilege Escalation Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthenticated Privilege Escalation to Editor No login needed ≤ 1.4.0 CVE-2025-6042 Wordfence
8.8 High XStore | Multipurpose WooCommerce Theme Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 9.5.4 CVE-2025-11746 Wordfence
8.8 High GSheetConnector For Gravity Forms Plugin gsheetconnector-gravity-forms Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.3.27 CVE-2025-8593 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
8.8 High Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity Theme Privilege Escalation Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 1.4.0 CVE-2025-6038 Wordfence
7.2 High Cookie Notice & Consent Plugin cookie-notice-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.6.5 CVE-2025-10496 Wordfence
7.7 High Find Me On Plugin SQL Injection Subscriber+ SQL Injection ≤ 2.0.9.1 CVE-2025-10635 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only