WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,401–4,450 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 89 of 342
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP Simple Redirect Plugin wp-simple-redirect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-68884 Patchstack
7.1 High bidorbuy Store Integrator Plugin bidorbuystoreintegrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.0 CVE-2025-68883 Patchstack
7.5 High Scalenut Plugin scalenut Broken Access Control No login needed ≤ 1.1.5 CVE-2025-68882 Patchstack
8.5 High AppExperts Plugin appexperts SQL Injection ≤ 1.4.5 CVE-2025-68881 Patchstack
7.1 High Dooodl Plugin dooodl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.0 CVE-2025-68871 Patchstack
9.8 Critical LazyTasks Plugin lazytasks-project-task-management Privilege Escalation No login needed ≤ 1.2.37 Fixed in 1.3.01 CVE-2025-68869 Patchstack
7.1 High Dinatur Plugin dinatur Cross-Site Scripting No login needed ≤ 1.18 CVE-2025-68866 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting No login needed ≤ 2.15.11 CVE-2025-68864 Patchstack
7.1 High Syntax Highlighter Compress Plugin syntax-highlighter-compress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.83.3 CVE-2025-68859 Patchstack
7.1 High wpCAS Plugin wpcas Cross-Site Scripting No login needed ≤ 1.07 CVE-2025-68858 Patchstack
9.3 Critical Paid Downloads Plugin paid-downloads SQL Injection No login needed ≤ 3.15 CVE-2025-68857 Patchstack
7.1 High Quote Master Plugin quote-master Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.1 CVE-2025-68849 Patchstack
7.1 High Easy Theme Options Plugin easy-theme-options Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-68839 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-68838 Patchstack
7.1 High Ravpage Plugin ravpage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.33 CVE-2025-68835 Patchstack
6.5 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 4.0.4 Fixed in 4.0.5 CVE-2025-68558 Patchstack
7.1 High Craft Theme craftcoffee Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68538 Patchstack
7.1 High DotLife Theme dotlife Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.5 Fixed in 4.9.5 CVE-2025-68520 Patchstack
7.1 High Hoteller Theme hoteller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.8.9 Fixed in 6.8.9 CVE-2025-68518 Patchstack
8.1 High Photography Plugin photography Local File Inclusion No login needed ≤ 7.7.5 Fixed in 7.7.5 CVE-2025-68510 Patchstack
6.5 Medium Icegram Plugin icegram Broken Access Control No login needed ≤ 3.1.35 Fixed in 3.1.36 CVE-2025-68507 Patchstack
6.5 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68073 Patchstack
6.5 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.20 Fixed in 3.5.21 CVE-2025-68072 Patchstack
7.6 High Hotel Listing Plugin hotel-listing Broken Access Control ≤ 1.4.2 CVE-2025-68059 Patchstack
7.6 High Institutions Directory Plugin institutions-directory Broken Access Control ≤ 1.3..4 CVE-2025-68058 Patchstack
7.6 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control ≤ 1.3.9 CVE-2025-68057 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-68047 Patchstack
6.5 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-68046 Patchstack
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
6.5 Medium WP BackItUp Plugin wp-backitup Broken Access Control No login needed ≤ 2.1.0 CVE-2025-68039 Patchstack
7.5 High Tabby Checkout Plugin tabby-checkout Information Disclosure Sensitive Data Exposure No login needed ≤ 5.8.4 Fixed in 5.9.1 CVE-2025-68035 Patchstack
9.3 Critical CleverReach® WP Plugin cleverreach-wp SQL Injection No login needed ≤ 1.5.21 Fixed in 1.5.22 CVE-2025-68034 Patchstack
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-68030 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Privilege Escalation No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68027 Patchstack
6.5 Medium Notifier Plugin notifier Broken Access Control No login needed ≤ 2.7.13 Fixed in 3.0.0 CVE-2025-68020 Patchstack
6.5 Medium SEO Booster Plugin seo-booster Broken Access Control No login needed ≤ 6.1.8 CVE-2025-68019 Patchstack
9.4 Critical Order Listener for WooCommerce Plugin woc-order-alert Broken Access Control No login needed ≤ 3.6.1 Fixed in 3.6.2 CVE-2025-68018 Patchstack
7.5 High Antideo Email Validator Plugin antideo-email-validator SQL Injection No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2025-68017 Patchstack
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack
9.0 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2025-68015 Patchstack
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
7.1 High CodeColorer Plugin codecolorer Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 0.10.1 Fixed in 0.10.2 CVE-2025-68012 Patchstack
7.1 High GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-68011 Patchstack
7.1 High Netgsm Plugin netgsm Cross-Site Scripting No login needed ≤ 2.9.63 Fixed in 2.9.64 CVE-2025-68010 Patchstack
6.5 Medium Slider Templates Plugin slider-templates Broken Access Control No login needed ≤ 1.0.3 CVE-2025-68009 Patchstack
7.1 High WP Mail Plugin wp-mail Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-68008 Patchstack
6.5 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Settings Change No login needed ≤ 5.0.37.decaf Fixed in 5.0.53.decaf CVE-2025-68007 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
7.1 High My Post Order Plugin my-posts-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1.1 CVE-2025-68004 Patchstack
6.5 Medium Shown Connector Plugin shown-connector Broken Access Control Settings Change No login needed ≤ 1.2.10 CVE-2025-68003 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only