WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,401–4,450 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 89 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Al Pack Plugin alpack Broken Access Control Missing Authorization to Unauthenticated Premium Feature Activation via check_activate_permission Function No login needed ≤ 1.1.1 CVE-2025-7664 Wordfence
8.8 High WPGYM Plugin Broken Access Control Missing Authorization to Admin Account Creation ≤ 67.7.0 CVE-2025-6080 Wordfence
8.8 High WPGYM - Wordpress Gym Management System Plugin Local File Inclusion Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 67.7.0 CVE-2025-3671 Wordfence
7.5 High School Management System Plugin wpschoolpress SQL Injection Unauthenticated SQL Injection No login needed ≤ 93.2.0 CVE-2024-12612 Wordfence
7.6 High Dropshix Plugin dropshipping-xox Cross-Site Scripting ≤ 4.0.14 CVE-2025-49898 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
7.5 High Assistant for NextGEN Gallery Plugin assistant-for-nextgen-gallery Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.0.9 CVE-2025-7641 Wordfence
7.5 High BizCalendar Web Plugin bizcalendar-web Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.1.0.53 CVE-2025-7650 Wordfence
8.1 High WooCommerce OTP Login With Phone Number, OTP Verification Plugin login-with-phone-number Authentication Bypass No login needed ≤ 1.8.47 CVE-2025-8342 Wordfence
7.5 High Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts No login needed ≤ 1.5.4 CVE-2025-6025 Wordfence
7.1 High NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52765 Patchstack
8.2 High StoryMap Plugin wp-storymap Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-52797 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Request Forgery No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-53575 Patchstack
8.8 High Findgo Plugin findgo Cross-Site Request Forgery No login needed ≤ 1.3.57 Fixed in 1.3.58 CVE-2025-53587 Patchstack
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.2.4 Fixed in 10.2.5 CVE-2025-55708 Patchstack
8.1 High Unicamp Plugin unicamp Local File Inclusion No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2025-54701 Patchstack
8.1 High Makeaholic Plugin makeaholic Local File Inclusion No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54700 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-54697 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.9.0 Fixed in 3.0.0 CVE-2025-54692 Patchstack
8.1 High Xinterio Plugin xinterio Local File Inclusion No login needed ≤ 4.2 Fixed in 4.3 CVE-2025-54690 Patchstack
8.1 High Urna Plugin urna Local File Inclusion No login needed ≤ 2.5.7 Fixed in 2.5.8 CVE-2025-54689 Patchstack
7.5 High Neon Channel Product Customizer Free Plugin neon-channel-product-customizer-free Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-54679 Patchstack
7.5 High CSS & JavaScript Toolbox Plugin css-javascript-toolbox Local File Inclusion ≤ 12.0.3 Fixed in 12.0.3 CVE-2025-3703 Patchstack
7.5 High News Magazine X Plugin news-magazine-x Local File Inclusion No login needed ≤ 1.2.37 Fixed in 1.2.38 CVE-2025-24766 Patchstack
8.1 High VidMov Theme vidmov Local File Inclusion No login needed ≤ 1.9.4 CVE-2025-25172 Patchstack
7.1 High Alike - WordPress Custom Post Comparison Plugin alike Cross-Site Scripting WordPress Custom Post Comparison <= 3.0.1 - Cross Site Scripting (XSS) No login needed ≤ 3.0.1 CVE-2025-28975 Patchstack
8.1 High WP Pipes Plugin wp-pipes Local File Inclusion No login needed ≤ 1.4.3 CVE-2025-28979 Patchstack
7.1 High WooCommerce Shop Page Builder Plugin dzs-wootable Cross-Site Scripting No login needed ≤ 2.27.7 CVE-2025-28999 Patchstack
7.1 High FoodMenu Plugin dzs-restaurantmenu Cross-Site Scripting No login needed ≤ 1.20 CVE-2025-29014 Patchstack
8.1 High IDonatePro Plugin idonate-pro Local File Inclusion No login needed ≤ 2.1.9 CVE-2025-30635 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-30626 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-30639 Patchstack
7.1 High Billplz Addon for Contact Form 7 Plugin billplz-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-31007 Patchstack
8.5 High WP Links Page Plugin wp-links-page SQL Injection ≤ 4.9.6 Fixed in 5.0 CVE-2025-30998 Patchstack
7.5 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-32288 Patchstack
7.5 High WP Lead Capturing Pages Plugin leadcapture Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.6 Fixed in 2.6 CVE-2025-31425 Patchstack
8.5 High Pinterest Automatic Pin Plugin wp-pinterest-automatic SQL Injection ≤ 4.19.0 Fixed in 4.19.0 CVE-2025-39510 Patchstack
7.2 High Content Egg Plugin content-egg PHP Object Injection ≤ 7.0.0 Fixed in 8.0.0 CVE-2025-47536 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-47689 Patchstack
7.5 High Gutenberg Blocks Plugin advanced-gutenberg Local File Inclusion No login needed ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-48332 Patchstack
8.1 High Premium Addons for KingComposer Plugin premium-addons-for-kingcomposer Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-49036 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.3 Fixed in 5.9.5.4 CVE-2025-49033 Patchstack
7.1 High WP Dynamic Links Plugin wp-dynamic-links Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-49038 Patchstack
7.1 High Authentication and xmlrpc log writer Plugin authentication-and-xmlrpc-log-writer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-49037 Patchstack
7.1 High Simple Poll Plugin simple-poll Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-49044 Patchstack
7.1 High Time Sheets Plugin time-sheets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.3 CVE-2025-49054 Patchstack
7.1 High 多说社会化评论框 Plugin duoshuo Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-49056 Patchstack
7.1 High SoundSt SEO Search Plugin soundst-seo-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-49058 Patchstack
7.1 High WP Voting Plugin wp-voting Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-49057 Patchstack
7.1 High BaiduXZH Submit(百度熊掌号) Plugin i3geek-baiduxzh Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-49063 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only