WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,301–4,350 of 16,970 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 87 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Miion Plugin miion Arbitrary File Upload ≤ 1.2.7 CVE-2025-68986 Patchstack
7.5 High Miion Plugin miion Local File Inclusion ≤ 1.2.7 CVE-2025-68913 Patchstack
8.6 High HDForms Plugin hdforms Arbitrary File Deletion No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-68912 Patchstack
6.5 Medium Solace Plugin solace Broken Access Control ≤ 2.1.16 CVE-2025-68911 Patchstack
9.9 Critical Blogzee Plugin blogzee Arbitrary File Upload ≤ 1.0.5 CVE-2025-68910 Patchstack
9.9 Critical Blogistic Plugin blogistic Arbitrary File Upload ≤ 1.0.5 CVE-2025-68909 Patchstack
8.1 High Barberry Plugin barberry Local File Inclusion No login needed ≤ 2.9.9.87 CVE-2025-68908 Patchstack
7.5 High Hostme v2 Plugin hostmev2 Arbitrary File Deletion No login needed ≤ 7.0 CVE-2025-68907 Patchstack
7.1 High JNews - Video Plugin jnews-video Cross-Site Scripting Video plugin <= 11.0.2 - Reflected Cross Site Scripting (XSS) No login needed ≤ 11.0.2 CVE-2025-68906 Patchstack
7.5 High JNews - Pay Writer Plugin jnews-pay-writer Local File Inclusion Pay Writer plugin <= 11.0.0 - Local File Inclusion ≤ 11.0.0 CVE-2025-68905 Patchstack
7.1 High JNews - Frontend Submit Plugin jnews-frontend-submit Cross-Site Scripting Frontend Submit plugin <= 11.0.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 11.0.0 CVE-2025-68904 Patchstack
8.8 High Anona Plugin anona PHP Object Injection ≤ 8.0 CVE-2025-68903 Patchstack
7.5 High Anona Plugin anona Path Traversal Arbitrary File Download No login needed ≤ 8.0 CVE-2025-68902 Patchstack
8.6 High Anona Plugin anona Arbitrary File Deletion No login needed ≤ 8.0 CVE-2025-68901 Patchstack
6.5 Medium Enfold Theme enfold Cross-Site Scripting ≤ 7.1.3 Fixed in 7.1.4 CVE-2025-68900 Patchstack
8.8 High Vivagh Plugin vivagh PHP Object Injection ≤ 2.4 CVE-2025-68899 Patchstack
5.8 Medium Synergy Project Manager Plugin synergy-project-manager Cross-Site Scripting No login needed ≤ 1.5 CVE-2025-68898 Patchstack
6.5 Medium WDV One Page Docs Plugin wdv-one-page-docs Broken Access Control No login needed ≤ 1.2.4 CVE-2025-68896 Patchstack
7.1 High ShoutOut Plugin shoutout Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.2 CVE-2025-68894 Patchstack
7.1 High WP Simple Redirect Plugin wp-simple-redirect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-68884 Patchstack
7.1 High bidorbuy Store Integrator Plugin bidorbuystoreintegrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.0 CVE-2025-68883 Patchstack
7.5 High Scalenut Plugin scalenut Broken Access Control No login needed ≤ 1.1.5 CVE-2025-68882 Patchstack
8.5 High AppExperts Plugin appexperts SQL Injection ≤ 1.4.5 CVE-2025-68881 Patchstack
7.1 High Dooodl Plugin dooodl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.0 CVE-2025-68871 Patchstack
9.8 Critical LazyTasks Plugin lazytasks-project-task-management Privilege Escalation No login needed ≤ 1.2.37 Fixed in 1.3.01 CVE-2025-68869 Patchstack
7.1 High Dinatur Plugin dinatur Cross-Site Scripting No login needed ≤ 1.18 CVE-2025-68866 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting No login needed ≤ 2.15.11 CVE-2025-68864 Patchstack
7.1 High Syntax Highlighter Compress Plugin syntax-highlighter-compress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.83.3 CVE-2025-68859 Patchstack
7.1 High wpCAS Plugin wpcas Cross-Site Scripting No login needed ≤ 1.07 CVE-2025-68858 Patchstack
9.3 Critical Paid Downloads Plugin paid-downloads SQL Injection No login needed ≤ 3.15 CVE-2025-68857 Patchstack
7.1 High Quote Master Plugin quote-master Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.1 CVE-2025-68849 Patchstack
7.1 High Easy Theme Options Plugin easy-theme-options Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-68839 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-68838 Patchstack
7.1 High Ravpage Plugin ravpage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.33 CVE-2025-68835 Patchstack
6.5 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 4.0.4 Fixed in 4.0.5 CVE-2025-68558 Patchstack
7.1 High Craft Theme craftcoffee Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68538 Patchstack
7.1 High DotLife Theme dotlife Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.5 Fixed in 4.9.5 CVE-2025-68520 Patchstack
7.1 High Hoteller Theme hoteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.8.9 Fixed in 6.8.9 CVE-2025-68518 Patchstack
8.1 High Photography Plugin photography Local File Inclusion No login needed ≤ 7.7.5 Fixed in 7.7.5 CVE-2025-68510 Patchstack
6.5 Medium Icegram Plugin icegram Broken Access Control No login needed ≤ 3.1.35 Fixed in 3.1.36 CVE-2025-68507 Patchstack
6.5 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68073 Patchstack
6.5 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.20 Fixed in 3.5.21 CVE-2025-68072 Patchstack
7.6 High Hotel Listing Plugin hotel-listing Broken Access Control ≤ 1.4.2 CVE-2025-68059 Patchstack
7.6 High Institutions Directory Plugin institutions-directory Broken Access Control ≤ 1.3..4 CVE-2025-68058 Patchstack
7.6 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control ≤ 1.3.9 CVE-2025-68057 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-68047 Patchstack
6.5 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-68046 Patchstack
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
6.5 Medium WP BackItUp Plugin wp-backitup Broken Access Control No login needed ≤ 2.1.0 CVE-2025-68039 Patchstack
7.5 High Tabby Checkout Plugin tabby-checkout Information Disclosure Sensitive Data Exposure No login needed ≤ 5.8.4 Fixed in 5.9.1 CVE-2025-68035 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only