WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,101–4,150 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 83 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High SEO Plugin by Squirrly SEO Plugin squirrly-seo SQL Injection ≤ 12.4.03 Fixed in 12.4.06 CVE-2025-22783 Patchstack
7.1 High Filled In Plugin filled-in Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-22628 Patchstack
7.6 High Payment Forms for Paystack Plugin payment-forms-for-paystack SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-22652 Patchstack
7.1 High Listings for Appfolio Plugin listings-for-appfolio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22658 Patchstack
7.1 High Secret Meta Plugin facebook-secret-meta Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-25086 Patchstack
7.1 High Cazamba Plugin cazamba Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25100 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.9.9.7 Fixed in 4.9.9.8 CVE-2025-30921 Patchstack
7.1 High Store Locator Widget Plugin store-locator-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2025r2 Fixed in 2025r3 CVE-2025-30919 Patchstack
7.5 High WpEvently Plugin mage-eventpress PHP Object Injection ≤ 4.2.9 Fixed in 4.3.0 CVE-2025-30895 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager Local File Inclusion ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30891 Patchstack
7.5 High Login Widget for Ultimate Member Plugin login-widget-for-ultimate-member Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-30890 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.8.9 Fixed in 1.9.0 CVE-2025-30879 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-30871 Patchstack
7.5 High Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.23 Fixed in 2.2.0 CVE-2025-30868 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
8.8 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion ≤ 2.4.4 Fixed in 2.4.5 CVE-2025-30846 Patchstack
7.5 High The Pack Elementor addons Plugin the-pack-addon Local File Inclusion ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30845 Patchstack
7.6 High bizcalendar-web Plugin bizcalendar-web SQL Injection ≤ 1.1.0.34 Fixed in 1.1.0.35 CVE-2025-30843 Patchstack
7.5 High Themify Event Post Plugin themify-event-post Local File Inclusion ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-30831 Patchstack
7.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.31 Fixed in 2.2.32 CVE-2025-30829 Patchstack
7.5 High WishSuite Plugin wishsuite Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-30820 Patchstack
8.5 High Simple Giveaways Plugin giveasap SQL Injection ≤ 2.48.1 Fixed in 2.48.2 CVE-2025-30819 Patchstack
7.5 High The Post Grid Plugin the-post-grid Local File Inclusion ≤ 7.7.17 Fixed in 7.7.18 CVE-2025-30814 Patchstack
8.5 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm SQL Injection ≤ 3.0.1 Fixed in 3.1 CVE-2025-30810 Patchstack
8.5 High Vimeotheque Plugin codeflavors-vimeo-video-post-lite SQL Injection ≤ 2.3.4.2 Fixed in 2.3.4.3 CVE-2025-30806 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
7.5 High Subscribe to Download Lite Plugin subscribe-to-download-lite Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-30785 Patchstack
8.5 High WP Subscription Forms Plugin wp-subscription-forms SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-30784 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
8.5 High WPGuppy Plugin wpguppy-lite SQL Injection ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-30775 Patchstack
7.2 High TranslatePress Plugin translatepress-multilingual PHP Object Injection ≤ 2.9.6 Fixed in 2.9.7 CVE-2025-30773 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
8.1 High Pearl - Corporate Business Plugin pearl Local File Inclusion No login needed ≤ 3.4.8 Fixed in 3.4.8 CVE-2025-26986 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 30.1 Fixed in 30.1 CVE-2025-27014 Patchstack
7.5 High Hostiko Plugin hostiko Local File Inclusion ≤ 30.1 Fixed in 30.1 CVE-2025-27015 Patchstack
8.5 High WP Google Calendar Manager Plugin wp-gcalendar SQL Injection ≤ 2.1 CVE-2025-28939 Patchstack
7.1 High Fancybox Plus Plugin fancybox-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-28935 Patchstack
7.1 High Simple Post Series Plugin simple-post-series Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2025-28934 Patchstack
7.1 High Are you robot google recaptcha Plugin are-you-robot-recaptcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-28928 Patchstack
7.1 High ZenphotoPress Plugin zenphotopress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-28924 Patchstack
7.1 High SpatialMatch IDX Plugin spatialmatch-free-lifestyle-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 CVE-2025-28921 Patchstack
7.1 High Custom Smilies Plugin custom-smilies-se Cross-Site Scripting No login needed ≤ 2.9.2 CVE-2025-28917 Patchstack
7.1 High Gravity 2 PDF Plugin gf2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28911 Patchstack
7.1 High Driving Directions Plugin ddirections Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2025-28903 Patchstack
7.1 High WP Event Ticketing Plugin wpeventticketing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 CVE-2025-28899 Patchstack
7.1 High Lightview Plus Plugin lightview-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.3 CVE-2025-28890 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only