WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 4,401–4,450 of 9,038 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Al Pack | Broken Access Control Missing Authorization to Unauthenticated Premium Feature Activation via check_activate_permission Function No login needed |
≤ 1.1.1 |
CVE-2025-7664 |
Wordfence | |
| 8.8 High | WPGYM | Broken Access Control Missing Authorization to Admin Account Creation |
≤ 67.7.0 |
CVE-2025-6080 |
Wordfence | |
| 8.8 High | WPGYM - Wordpress Gym Management System | Local File Inclusion Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update |
≤ 67.7.0 |
CVE-2025-3671 |
Wordfence | |
| 7.5 High | School Management System | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 93.2.0 |
CVE-2024-12612 |
Wordfence | |
| 7.6 High | Dropshix | Cross-Site Scripting |
≤ 4.0.14 |
CVE-2025-49898 |
Patchstack | |
| 8.8 High | Vertical scroll slideshow gallery v2 | SQL Injection |
≤ 9.1 |
CVE-2025-49897 |
Patchstack | |
| 7.5 High | Assistant for NextGEN Gallery | Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed |
≤ 1.0.9 |
CVE-2025-7641 |
Wordfence | |
| 7.5 High | BizCalendar Web | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.1.0.53 |
CVE-2025-7650 |
Wordfence | |
| 8.1 High | WooCommerce OTP Login With Phone Number, OTP Verification | Authentication Bypass No login needed |
≤ 1.8.47 |
CVE-2025-8342 |
Wordfence | |
| 7.5 High | Order Tip for WooCommerce | Broken Access Control Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts No login needed |
≤ 1.5.4 |
CVE-2025-6025 |
Wordfence | |
| 7.1 High | NetInsight Analytics Implementation | Cross-Site Request Forgery No login needed |
≤ 1.0.3 |
CVE-2025-52765 |
Patchstack | |
| 8.2 High | StoryMap | Cross-Site Request Forgery No login needed |
≤ 2.1 |
CVE-2025-52797 |
Patchstack | |
| 7.1 High | Primer MyData for Woocommerce | Cross-Site Request Forgery No login needed |
≤ 4.2.5 Fixed in 4.2.6 |
CVE-2025-53575 |
Patchstack | |
| 8.8 High | Findgo | Cross-Site Request Forgery No login needed |
≤ 1.3.57 Fixed in 1.3.58 |
CVE-2025-53587 |
Patchstack | |
| 8.5 High | Quiz And Survey Master | SQL Injection |
≤ 10.2.4 Fixed in 10.2.5 |
CVE-2025-55708 |
Patchstack | |
| 8.1 High | Unicamp | Local File Inclusion No login needed |
≤ 2.6.3 Fixed in 2.6.4 |
CVE-2025-54701 |
Patchstack | |
| 8.1 High | Makeaholic | Local File Inclusion No login needed |
≤ 1.8.4 Fixed in 1.8.5 |
CVE-2025-54700 |
Patchstack | |
| 7.2 High | Kadence WooCommerce Email Designer | Privilege Escalation |
≤ 1.5.16 Fixed in 1.5.17 |
CVE-2025-54697 |
Patchstack | |
| 7.5 High | Membership For WooCommerce | Broken Access Control No login needed |
≤ 2.9.0 Fixed in 3.0.0 |
CVE-2025-54692 |
Patchstack | |
| 8.1 High | Xinterio | Local File Inclusion No login needed |
≤ 4.2 Fixed in 4.3 |
CVE-2025-54690 |
Patchstack | |
| 8.1 High | Urna | Local File Inclusion No login needed |
≤ 2.5.7 Fixed in 2.5.8 |
CVE-2025-54689 |
Patchstack | |
| 7.5 High | Neon Channel Product Customizer Free | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2025-54679 |
Patchstack | |
| 7.5 High | CSS & JavaScript Toolbox | Local File Inclusion |
≤ 12.0.3 Fixed in 12.0.3 |
CVE-2025-3703 |
Patchstack | |
| 7.5 High | News Magazine X | Local File Inclusion No login needed |
≤ 1.2.37 Fixed in 1.2.38 |
CVE-2025-24766 |
Patchstack | |
| 8.1 High | VidMov | Local File Inclusion No login needed |
≤ 1.9.4 |
CVE-2025-25172 |
Patchstack | |
| 7.1 High | Alike - WordPress Custom Post Comparison | Cross-Site Scripting WordPress Custom Post Comparison <= 3.0.1 - Cross Site Scripting (XSS) No login needed |
≤ 3.0.1 |
CVE-2025-28975 |
Patchstack | |
| 8.1 High | WP Pipes | Local File Inclusion No login needed |
≤ 1.4.3 |
CVE-2025-28979 |
Patchstack | |
| 7.1 High | WooCommerce Shop Page Builder | Cross-Site Scripting No login needed |
≤ 2.27.7 |
CVE-2025-28999 |
Patchstack | |
| 7.1 High | FoodMenu | Cross-Site Scripting No login needed |
≤ 1.20 |
CVE-2025-29014 |
Patchstack | |
| 8.1 High | IDonatePro | Local File Inclusion No login needed |
≤ 2.1.9 |
CVE-2025-30635 |
Patchstack | |
| 7.1 High | Multimedia Playlist Slider Addon for WPBakery Page Builder | Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2025-30626 |
Patchstack | |
| 7.5 High | IDonatePro | Broken Access Control No login needed |
≤ 2.1.9 |
CVE-2025-30639 |
Patchstack | |
| 7.1 High | Billplz Addon for Contact Form 7 | Cross-Site Scripting No login needed |
≤ 1.2.0 Fixed in 1.2.1 |
CVE-2025-31007 |
Patchstack | |
| 8.5 High | WP Links Page | SQL Injection |
≤ 4.9.6 Fixed in 5.0 |
CVE-2025-30998 |
Patchstack | |
| 7.5 High | RT-Theme 18 | Extensions | Local File Inclusion No login needed |
≤ 2.4 Fixed in 2.5 |
CVE-2025-32288 |
Patchstack | |
| 7.5 High | WP Lead Capturing Pages | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 2.6 Fixed in 2.6 |
CVE-2025-31425 |
Patchstack | |
| 8.5 High | Pinterest Automatic Pin | SQL Injection |
≤ 4.19.0 Fixed in 4.19.0 |
CVE-2025-39510 |
Patchstack | |
| 7.2 High | Content Egg | PHP Object Injection |
≤ 7.0.0 Fixed in 8.0.0 |
CVE-2025-47536 |
Patchstack | |
| 7.1 High | Video Blogster Lite | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-47689 |
Patchstack | |
| 7.5 High | Gutenberg Blocks | Local File Inclusion No login needed |
≤ 3.3.1 Fixed in 3.3.2 |
CVE-2025-48332 |
Patchstack | |
| 8.1 High | Premium Addons for KingComposer | Local File Inclusion No login needed |
≤ 1.1.1 |
CVE-2025-49036 |
Patchstack | |
| 8.5 High | ProfileGrid | SQL Injection |
≤ 5.9.5.3 Fixed in 5.9.5.4 |
CVE-2025-49033 |
Patchstack | |
| 7.1 High | WP Dynamic Links | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2025-49038 |
Patchstack | |
| 7.1 High | Authentication and xmlrpc log writer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.2 |
CVE-2025-49037 |
Patchstack | |
| 7.1 High | Simple Poll | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.1.1 |
CVE-2025-49044 |
Patchstack | |
| 7.1 High | Time Sheets | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.3 |
CVE-2025-49054 |
Patchstack | |
| 7.1 High | 多说社会化评论框 | Cross-Site Scripting No login needed |
≤ 1.2 |
CVE-2025-49056 |
Patchstack | |
| 7.1 High | SoundSt SEO Search | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.3 |
CVE-2025-49058 |
Patchstack | |
| 7.1 High | WP Voting | Cross-Site Scripting No login needed |
≤ 1.8 |
CVE-2025-49057 |
Patchstack | |
| 7.1 High | BaiduXZH Submit(百度熊掌号) | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.6 |
CVE-2025-49063 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.