WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,451–4,500 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 90 of 342
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical g-FFL Checkout Plugin g-ffl-checkout Arbitrary File Upload No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-68001 Patchstack
9.9 Critical Real Homes CRM Plugin realhomes-crm Arbitrary File Upload ≤ 1.0.0 Fixed in 1.0.1 CVE-2025-67968 Patchstack
7.6 High Lawyer Directory Plugin lawyer-directory Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67967 Patchstack
8.8 High Lawyer Directory Plugin lawyer-directory Privilege Escalation ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67966 Patchstack
7.1 High Homey Core Plugin homey-core Cross-Site Scripting No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67964 Patchstack
8.6 High Movie Booking Plugin movie-booking Arbitrary File Deletion No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-67963 Patchstack
6.4 Medium WPO365 Plugin wpo365-login Server-Side Request Forgery ≤ 40.0 Fixed in 40.1 CVE-2025-67961 Patchstack
7.1 High WorkScout-Core Plugin workscout-core Cross-Site Scripting No login needed ≤ 1.7.06 Fixed in 1.7.07 CVE-2025-67960 Patchstack
7.1 High WorkScout Plugin workscout Cross-Site Scripting No login needed ≤ 4.1.07 Fixed in 4.1.08 CVE-2025-67959 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
8.1 High Listivo Core Plugin listivo-core Local File Inclusion No login needed ≤ 2.3.77 Fixed in 2.3.78 CVE-2025-67957 Patchstack
8.2 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 4.4.6 Fixed in 4.4.7 CVE-2025-67956 Patchstack
7.5 High MyHome Core Plugin myhome-core Local File Inclusion ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-67955 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
8.1 High Booking Activities Plugin booking-activities Privilege Escalation No login needed ≤ 1.16.44 Fixed in 1.16.45 CVE-2025-67953 Patchstack
7.1 High Grand Tour Plugin grandtour Cross-Site Scripting No login needed ≤ 5.6.2 Fixed in 5.6.2 CVE-2025-67952 Patchstack
7.1 High Hostiko Plugin hostiko Cross-Site Scripting No login needed ≤ 94.3.6 Fixed in 94.3.6 CVE-2025-67949 Patchstack
7.1 High AdForest Elementor Plugin adforest-elementor Cross-Site Scripting No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2025-67947 Patchstack
8.1 High AdForest Theme adforest Local File Inclusion No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2025-67946 Patchstack
9.3 Critical MailerLite – WooCommerce integration Plugin woo-mailerlite SQL Injection WooCommerce integration plugin <= 3.1.2 - SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-67945 Patchstack
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution Arbitrary Code Execution ≤ 8.1.8 Fixed in 8.2.0 CVE-2025-67944 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.32 Fixed in 3.6.33 CVE-2025-67943 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2025-67942 Patchstack
8.1 High The Aisle Theme theaisle Local File Inclusion No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2025-67941 Patchstack
8.1 High Powerlift Theme powerlift Local File Inclusion No login needed ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-67940 Patchstack
6.5 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.2 Fixed in 3.5.6.3 CVE-2025-67939 Patchstack
8.1 High Biagiotti Theme biagiotti Local File Inclusion No login needed ≤ 3.5.2 Fixed in 3.5.2 CVE-2025-67938 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2025-67923 Patchstack
4.3 Medium WP SEO Search Plugin wp-seo-search Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-67626 Patchstack
7.1 High Anon Plugin anon2x Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.10 CVE-2025-67620 Patchstack
8.8 High Kids Heaven Plugin kids-world PHP Object Injection ≤ 3.2 CVE-2025-67619 Patchstack
9.8 Critical Consult Aid Plugin consultaid PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-67617 Patchstack
8.1 High Mella Plugin mella Local File Inclusion No login needed ≤ 1.2.29 CVE-2025-67616 Patchstack
8.1 High Myour Plugin myour Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-67615 Patchstack
7.1 High TheNa Plugin thena Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.5 CVE-2025-67614 Patchstack
5.4 Medium Crumber Plugin crumber-elementor Broken Access Control ≤ 1.0.10 CVE-2025-66143 Patchstack
5.4 Medium Comparimager for Elementor Plugin comparimager-elementor Broken Access Control ≤ 1.0.1 CVE-2025-66142 Patchstack
5.4 Medium Scroller Plugin scroller Broken Access Control ≤ 2.0.2 CVE-2025-66141 Patchstack
5.4 Medium Uper for Elementor Plugin uper-elementor Broken Access Control ≤ 1.0.5 CVE-2025-66140 Patchstack
5.4 Medium Audier For Elementor Plugin audier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66139 Patchstack
5.4 Medium Motionger for Elementor Plugin motionger-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66138 Patchstack
5.4 Medium Searcher for Elementor Plugin searcher-elementor Broken Access Control ≤ 1.0.3 CVE-2025-66137 Patchstack
5.4 Medium Carter for Elementor Plugin carter-elementor Broken Access Control ≤ 1.0.2 CVE-2025-66136 Patchstack
5.4 Medium Imager for Elementor Plugin imager-elementor Broken Access Control ≤ 2.0.4 CVE-2025-66135 Patchstack
4.9 Medium ANAC XML Viewer Plugin anac-xml-viewer Server-Side Request Forgery ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-64252 Patchstack
4.3 Medium REHub Framework Plugin rehub-framework Information Disclosure Sensitive Data Exposure ≤ 19.9.9.4 Fixed in 19.9.9.4 CVE-2025-63051 Patchstack
6.5 Medium Grand Restaurant Theme Elements for Elementor Plugin grandrestaurant-elementor Cross-Site Scripting ≤ 2.1.1 CVE-2025-63026 Patchstack
5.3 Medium Cookies and Content Security Policy Plugin cookies-and-content-security-policy Information Disclosure Sensitive Data Exposure No login needed ≤ 2.34 Fixed in 2.35 CVE-2025-63019 Patchstack
4.3 Medium Bard Plugin bard Broken Access Control ≤ 2.229 CVE-2025-63018 Patchstack
7.5 High WerkStatt Plugin werkstatt-plugin Local File Inclusion ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-63017 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only