WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 4,451–4,500 of 9,038 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | WP-jScrollPane | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.3 |
CVE-2025-49062 |
Patchstack | |
| 7.1 High | Visit Counter | Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-49065 |
Patchstack | |
| 7.1 High | User Language Switch | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.10 |
CVE-2025-49064 |
Patchstack | |
| 8.5 High | Frontend Admin by DynamiApps | SQL Injection |
≤ 3.28.3 Fixed in 3.28.5 |
CVE-2025-49267 |
Patchstack | |
| 7.5 High | Cloud SAML SSO - Single Sign On Login | Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed |
≤ 1.0.18 Fixed in 1.0.19 |
CVE-2025-49264 |
Patchstack | |
| 7.5 High | GravityWP - Merge Tags | Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed |
≤ 1.4.4 Fixed in 1.4.5 |
CVE-2025-49271 |
Patchstack | |
| 8.8 High | Eventin | PHP Object Injection |
≤ 4.0.31 Fixed in 4.0.32 |
CVE-2025-49869 |
Patchstack | |
| 7.5 High | WP REST Cache | Local File Inclusion No login needed |
≤ 2025.1.0 Fixed in 2025.1.1 |
CVE-2025-52716 |
Patchstack | |
| 7.5 High | Responsive Posts Carousel Pro | Local File Inclusion |
≤ 15.0 Fixed in 15.1 |
CVE-2025-52728 |
Patchstack | |
| 7.5 High | Event Manager, Event Calendar and Booking | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 4.0.24 Fixed in 4.0.25 |
CVE-2025-52731 |
Patchstack | |
| 7.1 High | Project Cost Calculator | Broken Access Control |
≤ 1.0.0 |
CVE-2025-52775 |
Patchstack | |
| 8.8 High | GMap Targeting | Local File Inclusion |
≤ 1.1.6 Fixed in 1.1.7 |
CVE-2025-52732 |
Patchstack | |
| 7.1 High | SMM API | Broken Access Control |
≤ 6.0.31 |
CVE-2025-52785 |
Patchstack | |
| 7.3 High | The E-Commerce ERP | Broken Access Control No login needed |
≤ 2.1.1.3 |
CVE-2025-52800 |
Patchstack | |
| 7.1 High | CaptionPix | Cross-Site Scripting No login needed |
≤ 1.8 |
CVE-2025-52788 |
Patchstack | |
| 7.5 High | JobSearch | Local File Inclusion |
≤ 3.0.8 Fixed in 3.0.8 |
CVE-2025-52806 |
Patchstack | |
| 7.3 High | TheBooking | Broken Access Control No login needed |
≤ 1.4.4 |
CVE-2025-52801 |
Patchstack | |
| 8.5 High | WooCommerce Point Of Sale (POS) | SQL Injection |
≤ 1.4 |
CVE-2025-52820 |
Patchstack | |
| 8.5 High | Cube Portfolio | SQL Injection |
≤ 1.16.8 |
CVE-2025-52823 |
Patchstack | |
| 8.8 High | Tutor LMS Pro – eLearning and online course solution | SQL Injection eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection |
≤ 3.7.0 |
CVE-2025-6184 |
Wordfence | |
| 8.8 High | B Slider- Gutenberg Slider Block for WP | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation |
≤ 1.1.30 |
CVE-2025-8418 |
Wordfence | |
| 7.5 High | UiCore Elements | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed |
≤ 1.3.0 |
CVE-2025-6253 |
Wordfence | |
| 8.1 High | WooCommerce Purchase Orders | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 1.0.2 |
CVE-2025-5391 |
Wordfence | |
| 8.8 High | Eventin | Privilege Escalation Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover |
≤ 4.0.34 |
CVE-2025-4796 |
Wordfence | |
| 8.8 High | Post SMTP | Privilege Escalation Account Takeover |
≤ 3.2.0 Fixed in 3.3.0 |
CVE-2025-24000 |
Patchstack | |
| 8.1 High | Multiple Plugins by emarket-design <= Multiple Versions | Remote Code Execution Unauthenticated Limited Remote Code Execution No login needed |
≤ 1.9.2, ≤ 2.5.2, ≤ 3.5.2, … |
CVE-2025-8420 |
Wordfence | |
| 7.5 High | CleverReach WP | SQL Injection Unauthenticated SQL Injection via title Parameter No login needed |
≤ 1.5.20 |
CVE-2025-7036 |
Wordfence | |
| 7.5 High | WP Import Export Lite | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 3.9.29 |
CVE-2025-5061 |
Wordfence | |
| 7.5 High | WP Import Export Lite | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 3.9.28 |
CVE-2025-6207 |
Wordfence | |
| 7.2 High | Use-your-Drive | Google Drive | Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed |
≤ 3.3.1 |
CVE-2025-7050 |
Wordfence | |
| 8.8 High | SEO Metrics | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation |
≤ 1.0.15 |
CVE-2025-6754 |
Wordfence | |
| 8.1 High | BerqWP | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.2.42 |
CVE-2025-7443 |
Wordfence | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.1.0 |
CVE-2025-7725 |
Wordfence | |
| 7.2 High | NinjaScanner – Virus & Malware scan | Arbitrary File Deletion Virus & Malware scan <= 3.2.5 - Authenticated (Administrator+) Arbitrary File Deletion |
≤ 3.2.5 |
CVE-2025-8213 |
Wordfence | |
| 8.8 High | AI Engine | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
2.9.3 – 2.9.4 |
CVE-2025-7847 |
Wordfence | |
| 8.8 High | Hydra Booking | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function |
1.1.0 – 1.1.18 |
CVE-2025-7689 |
Wordfence | |
| 7.5 High | Bricks Builder | SQL Injection Unauthenticated SQL Injection via `p` Parameter No login needed |
≤ 1.12.4 |
CVE-2025-6495 |
Wordfence | |
| 7.5 High | Kallyas | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 4.21.0 |
CVE-2025-6991 |
Wordfence | |
| 8.1 High | Kallyas | Arbitrary File Deletion Authenticated (Contributor+) Arbitrary Folder Deletion |
≤ 4.21.0 |
CVE-2025-6989 |
Wordfence | |
| 7.5 High | MinimogWP – The High Converting eCommerce | Price Manipulation The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation No login needed |
≤ 3.9.0 |
CVE-2025-8198 |
Wordfence | |
| 7.5 High | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | SQL Injection WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection No login needed |
≤ 2.8.97 |
CVE-2024-13507 |
Wordfence | |
| 7.5 High | Frontend File Manager | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 21.5 |
CVE-2023-7306 |
Wordfence | |
| 8.8 High | Droip | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Many Actions |
≤ 2.2.6 |
CVE-2025-5835 |
Wordfence | |
| 8.8 High | Droip | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
< 2.5.2 Fixed in 2.5.2 |
CVE-2025-5831 |
Wordfence | |
| 8.8 High | Responsive Thumbnail Slider | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
< 1.0.1 Fixed in 1.0.1 |
CVE-2015-10144 |
Wordfence | |
| 8.8 High | Dataverse Integration | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via reset_password_link REST Route |
2.77 – 2.81 |
CVE-2025-7695 |
Wordfence | |
| 8.1 High | hiWeb Export Posts | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed |
≤ 0.9.0.0 |
CVE-2025-7640 |
Wordfence | |
| 8.8 High | Social Streams | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
≤ 1.0.1 |
CVE-2025-7722 |
Wordfence | |
| 8.8 High | Realty Portal – Agent | Broken Access Control Agent <= 0.3.9 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via rp_user_profile() Function |
≤ 0.3.9 |
CVE-2025-6190 |
Wordfence | |
| 7.2 High | Nginx Cache Purge Preload | Remote Code Execution Authenticated (Administrator+) Remote Code Execution |
≤ 2.1.1 |
CVE-2025-6213 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.