WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,251–4,300 of 16,970 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 86 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Reservation Plugin dt-reservation-plugin Broken Access Control Settings Change No login needed ≤ 1.7 CVE-2025-69095 Patchstack
9.8 Critical Sound | Musical Instruments Online Store Theme musicplace PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.6.9 CVE-2025-69079 Patchstack
8.1 High Malta Theme malta Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69078 Patchstack
8.1 High Hobo Theme hobo Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-69077 Patchstack
8.1 High Modern Housewife Theme modernhousewife Local File Inclusion No login needed ≤ 1.0.12 CVE-2025-69076 Patchstack
8.1 High Yolox Theme yolox Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-69075 Patchstack
8.1 High Pearson Specter Theme pearsonspecter Local File Inclusion No login needed ≤ 1.11.3 CVE-2025-69074 Patchstack
8.1 High Piqes Theme piqes Local File Inclusion No login needed ≤ 1.0.11 CVE-2025-69073 Patchstack
8.1 High Prider Theme prider Local File Inclusion No login needed ≤ 1.1.3.1 CVE-2025-69072 Patchstack
8.1 High TanTum Theme tantum Local File Inclusion No login needed ≤ 1.1.13 CVE-2025-69071 Patchstack
8.1 High Tornados Theme tornados Local File Inclusion No login needed ≤ 2.1 CVE-2025-69070 Patchstack
8.1 High Muji Theme muji Local File Inclusion No login needed ≤ 1.2.0 CVE-2025-69068 Patchstack
8.1 High Tails Theme tails Local File Inclusion No login needed ≤ 1.4.12 CVE-2025-69067 Patchstack
8.1 High Indoor Plants Theme indoor-plants Local File Inclusion No login needed ≤ 1.2.7 CVE-2025-69066 Patchstack
8.1 High Snow Mountain Theme snowmountain Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69065 Patchstack
8.1 High Pets Land Theme petsland Local File Inclusion No login needed ≤ 1.2.8 CVE-2025-69064 Patchstack
8.1 High Weedles Theme weedles Local File Inclusion No login needed ≤ 1.1.12 CVE-2025-69062 Patchstack
8.1 High MoveMe Theme moveme Local File Inclusion No login needed ≤ 1.2.15 CVE-2025-69061 Patchstack
8.1 High uReach Theme ureach Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69060 Patchstack
8.1 High DiveIt Theme diveit Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-69059 Patchstack
8.1 High PartyMaker Theme partymaker Local File Inclusion No login needed ≤ 1.1.15 CVE-2025-69058 Patchstack
8.1 High Eldon Plugin eldon Local File Inclusion No login needed ≤ 1.0 CVE-2025-69057 Patchstack
7.1 High Hotel Listing Plugin hotel-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-69056 Patchstack
6.5 Medium BM Content Builder Plugin bm-builder Path Traversal Arbitrary File Download ≤ 3.16.3.3 Fixed in 3.16.3.3 CVE-2025-69055 Patchstack
7.1 High Super Logos Showcase Plugin superlogoshowcase-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 CVE-2025-69054 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69053 Patchstack
9.8 Critical Registration & Login with Mobile Phone Number for WooCommerce Plugin registration-login-with-mobile-phone-number Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-69052 Patchstack
7.1 High ListingPro Reviews Plugin listingpro-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.11 Fixed in 2.9.11 CVE-2025-69051 Patchstack
8.1 High Overworld Plugin overworld Local File Inclusion No login needed ≤ 1.3 CVE-2025-69050 Patchstack
8.1 High Töbel Plugin tobel Local File Inclusion No login needed ≤ 1.6 CVE-2025-69049 Patchstack
7.1 High Universal Video Player Plugin universal-video-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.4 CVE-2025-69048 Patchstack
8.1 High MaxShop Plugin sw_maxshop Local File Inclusion No login needed ≤ 3.6.20 CVE-2025-69047 Patchstack
8.1 High iRecco Core Plugin irecco-core Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69046 Patchstack
8.5 High FooEvents for WooCommerce Plugin fooevents SQL Injection ≤ 1.20.4 Fixed in 1.20.5 CVE-2025-69045 Patchstack
8.1 High Vango Plugin vango Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69044 Patchstack
8.1 High Rashy Plugin rashy Local File Inclusion No login needed ≤ 1.1.3 CVE-2025-69043 Patchstack
8.1 High Lindo Plugin lindo Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69042 Patchstack
8.1 High Dekoro Plugin dekoro Local File Inclusion No login needed ≤ 1.0.7 CVE-2025-69041 Patchstack
8.1 High Bfres Plugin bfres Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-69040 Patchstack
8.1 High Bailly Plugin bailly Local File Inclusion No login needed ≤ 1.3.4 CVE-2025-69039 Patchstack
8.1 High Hyori Plugin hyori Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69038 Patchstack
8.1 High Pippo Plugin pippo Local File Inclusion No login needed ≤ 1.2.3 CVE-2025-69037 Patchstack
8.8 High Tech Life CPT Plugin techlife-cpt PHP Object Injection ≤ 16.4 CVE-2025-69036 Patchstack
8.8 High Dental Care CPT Plugin dentalcare-cpt PHP Object Injection ≤ 20.2 CVE-2025-69035 Patchstack
8.1 High Search & Go Plugin search-and-go Local File Inclusion No login needed ≤ 2.8 CVE-2025-69005 Patchstack
8.1 High Bajaar - Highly Customizable WooCommerce Theme bajaar Local File Inclusion Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-69004 Patchstack
7.1 High KenthaRadio Plugin qt-kentharadio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2025-69003 Patchstack
8.8 High OneLife Plugin onelife PHP Object Injection ≤ 3.9 CVE-2025-69002 Patchstack
5.3 Medium FluentForm Plugin fluentform Arbitrary Shortcode Execution No login needed ≤ 6.1.11 Fixed in 6.1.12 CVE-2025-69001 Patchstack
8.5 High Happy Addons for Elementor Plugin happy-elementor-addons SQL Injection ≤ 3.20.4 Fixed in 3.20.6 CVE-2025-68999 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only