WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,451–4,500 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 90 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP-jScrollPane Plugin wp-jscrollpane Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2025-49062 Patchstack
7.1 High Visit Counter Plugin visit-counter Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49065 Patchstack
7.1 High User Language Switch Plugin user-language-switch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.10 CVE-2025-49064 Patchstack
8.5 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element SQL Injection ≤ 3.28.3 Fixed in 3.28.5 CVE-2025-49267 Patchstack
7.5 High Cloud SAML SSO - Single Sign On Login Plugin cloud-sso-single-sign-on Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-49264 Patchstack
7.5 High GravityWP - Merge Tags Plugin gravitywp-merge-tags Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-49271 Patchstack
8.8 High Eventin Plugin wp-event-solution PHP Object Injection ≤ 4.0.31 Fixed in 4.0.32 CVE-2025-49869 Patchstack
7.5 High WP REST Cache Plugin wp-rest-cache Local File Inclusion No login needed ≤ 2025.1.0 Fixed in 2025.1.1 CVE-2025-52716 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.0 Fixed in 15.1 CVE-2025-52728 Patchstack
7.5 High Event Manager, Event Calendar and Booking Plugin eventin-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52731 Patchstack
7.1 High Project Cost Calculator Plugin project-cost-calculator Broken Access Control ≤ 1.0.0 CVE-2025-52775 Patchstack
8.8 High GMap Targeting Plugin gmap-targeting Local File Inclusion ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-52732 Patchstack
7.1 High SMM API Plugin smm-api Broken Access Control ≤ 6.0.31 CVE-2025-52785 Patchstack
7.3 High The E-Commerce ERP Plugin profitori Broken Access Control No login needed ≤ 2.1.1.3 CVE-2025-52800 Patchstack
7.1 High CaptionPix Plugin captionpix Cross-Site Scripting No login needed ≤ 1.8 CVE-2025-52788 Patchstack
7.5 High JobSearch Plugin wp-jobsearch Local File Inclusion ≤ 3.0.8 Fixed in 3.0.8 CVE-2025-52806 Patchstack
7.3 High TheBooking Plugin thebooking Broken Access Control No login needed ≤ 1.4.4 CVE-2025-52801 Patchstack
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
8.5 High Cube Portfolio Plugin cubeportfolio SQL Injection ≤ 1.16.8 CVE-2025-52823 Patchstack
8.8 High Tutor LMS Pro – eLearning and online course solution Plugin tutor SQL Injection eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection ≤ 3.7.0 CVE-2025-6184 Wordfence
8.8 High B Slider- Gutenberg Slider Block for WP Plugin b-slider Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation ≤ 1.1.30 CVE-2025-8418 Wordfence
7.5 High UiCore Elements Plugin uicore-elements Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed ≤ 1.3.0 CVE-2025-6253 Wordfence
8.1 High WooCommerce Purchase Orders Plugin wc-purchase-orders Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.0.2 CVE-2025-5391 Wordfence
8.8 High Eventin Plugin wp-event-solution Privilege Escalation Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover ≤ 4.0.34 CVE-2025-4796 Wordfence
8.8 High Post SMTP Plugin post-smtp Privilege Escalation Account Takeover ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-24000 Patchstack
8.1 High Multiple Plugins by emarket-design <= Multiple Versions Plugin Remote Code Execution Unauthenticated Limited Remote Code Execution No login needed ≤ 1.9.2, ≤ 2.5.2, ≤ 3.5.2, … CVE-2025-8420 Wordfence
7.5 High CleverReach WP Plugin cleverreach-wp SQL Injection Unauthenticated SQL Injection via title Parameter No login needed ≤ 1.5.20 CVE-2025-7036 Wordfence
7.5 High WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 3.9.29 CVE-2025-5061 Wordfence
7.5 High WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 3.9.28 CVE-2025-6207 Wordfence
7.2 High Use-your-Drive | Google Drive Plugin Cross-Site Scripting Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata No login needed ≤ 3.3.1 CVE-2025-7050 Wordfence
8.8 High SEO Metrics Plugin seo-metrics-helper Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.15 CVE-2025-6754 Wordfence
8.1 High BerqWP Plugin searchpro Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.42 CVE-2025-7443 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.1.0 CVE-2025-7725 Wordfence
7.2 High NinjaScanner – Virus & Malware scan Plugin ninjascanner Arbitrary File Deletion Virus & Malware scan <= 3.2.5 - Authenticated (Administrator+) Arbitrary File Deletion ≤ 3.2.5 CVE-2025-8213 Wordfence
8.8 High AI Engine Plugin ai-engine Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload 2.9.3 – 2.9.4 CVE-2025-7847 Wordfence
8.8 High Hydra Booking Plugin hydra-booking Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function 1.1.0 – 1.1.18 CVE-2025-7689 Wordfence
7.5 High Bricks Builder Theme SQL Injection Unauthenticated SQL Injection via `p` Parameter No login needed ≤ 1.12.4 CVE-2025-6495 Wordfence
7.5 High Kallyas Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 4.21.0 CVE-2025-6991 Wordfence
8.1 High Kallyas Theme Arbitrary File Deletion Authenticated (Contributor+) Arbitrary Folder Deletion ≤ 4.21.0 CVE-2025-6989 Wordfence
7.5 High MinimogWP – The High Converting eCommerce Theme Price Manipulation The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation No login needed ≤ 3.9.0 CVE-2025-8198 Wordfence
7.5 High GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory SQL Injection WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection No login needed ≤ 2.8.97 CVE-2024-13507 Wordfence
7.5 High Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 21.5 CVE-2023-7306 Wordfence
8.8 High Droip Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Many Actions ≤ 2.2.6 CVE-2025-5835 Wordfence
8.8 High Droip Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload < 2.5.2 Fixed in 2.5.2 CVE-2025-5831 Wordfence
8.8 High Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload < 1.0.1 Fixed in 1.0.1 CVE-2015-10144 Wordfence
8.8 High Dataverse Integration Plugin integration-cds Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via reset_password_link REST Route 2.77 – 2.81 CVE-2025-7695 Wordfence
8.1 High hiWeb Export Posts Plugin hiweb-export-posts Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 0.9.0.0 CVE-2025-7640 Wordfence
8.8 High Social Streams Plugin social-streams Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.1 CVE-2025-7722 Wordfence
8.8 High Realty Portal – Agent Plugin realty-portal-agent Broken Access Control Agent <= 0.3.9 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via rp_user_profile() Function ≤ 0.3.9 CVE-2025-6190 Wordfence
7.2 High Nginx Cache Purge Preload Plugin fastcgi-cache-purge-and-preload-nginx Remote Code Execution Authenticated (Administrator+) Remote Code Execution ≤ 2.1.1 CVE-2025-6213 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only