WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,501–4,550 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 91 of 342
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Payment Gateway bKash for WC Plugin woo-payment-bkash Broken Access Control No login needed ≤ 3.1.0 CVE-2025-62754 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack
5.4 Medium WP-CRM System Plugin wp-crm-system Broken Access Control ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-62106 Patchstack
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
9.9 Critical News Event Plugin news-event Arbitrary File Upload ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-62056 Patchstack
9.9 Critical Blogmatic Plugin blogmatic Arbitrary File Upload ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-62050 Patchstack
6.5 Medium Electron Plugin electron Broken Access Control ≤ 1.8.2 CVE-2025-5805 Patchstack
8.1 High Depot Plugin depot Local File Inclusion No login needed ≤ 1.16 CVE-2025-54003 Patchstack
6.5 Medium xSmart Plugin xsmart Broken Access Control ≤ 1.2.9.4 CVE-2025-54002 Patchstack
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
7.1 High flexo-posts-manager Plugin flexo-posts-manager Cross-Site Scripting No login needed ≤ 1.0001 CVE-2025-52762 Patchstack
7.1 High Restaurante Plugin restaurante Cross-Site Scripting No login needed ≤ 3.0.7 Fixed in 3.1.1 CVE-2025-52746 Patchstack
8.8 High xSmart Plugin xsmart Privilege Escalation ≤ 1.2.9.4 CVE-2025-50007 Patchstack
7.1 High xSmart Plugin xsmart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9.4 CVE-2025-50006 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50005 Patchstack
8.8 High JupiterX Core Plugin jupiterx-core PHP Object Injection ≤ 4.10.1 Fixed in 4.11.0 CVE-2025-50004 Patchstack
8.1 High Amuli Plugin amuli Local File Inclusion No login needed ≤ 2.3.0 CVE-2025-50003 Patchstack
10.0 Critical Energia Plugin energia Arbitrary File Upload No login needed ≤ 1.1.2 CVE-2025-50002 Patchstack
8.1 High Athens Plugin athens Local File Inclusion No login needed ≤ 1.1.6 CVE-2025-49994 Patchstack
5.4 Medium HomeLancer Plugin homelancer Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-49375 Patchstack
5.9 Medium Pondol BBS Plugin pondol-bbs Cross-Site Scripting ≤ 1.1.8.4 CVE-2025-49336 Patchstack
7.1 High Drone Plugin drone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.40 CVE-2025-49249 Patchstack
7.1 High Accordion Slider PRO Plugin accordion_slider_pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-49066 Patchstack
9.3 Critical WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection No login needed ≤ 2.5 CVE-2025-49055 Patchstack
8.5 High WP Lead Capturing Pages Plugin wp-lead-capture SQL Injection ≤ 2.5 CVE-2025-49050 Patchstack
8.5 High DZS Video Gallery Plugin dzs-videogallery SQL Injection ≤ 12.39 Fixed in 12.40 CVE-2025-49049 Patchstack
7.1 High xPromoter Plugin top_bar_promoter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 CVE-2025-49046 Patchstack
7.1 High Super Interactive Maps Plugin super-interactive-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-49045 Patchstack
7.1 High Magic Responsive Slider and Carousel Plugin magic_carousel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-49043 Patchstack
7.1 High Magic Slider Plugin magic_slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-48094 Patchstack
7.1 High Image&Video FullScreen Background Plugin lbg_fullscreen_fullwidth_slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 CVE-2025-47666 Patchstack
5.3 Medium WoodMart Theme woodmart Arbitrary Shortcode Execution No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2025-47600 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
5.9 Medium Stackable Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting ≤ 3.19.5 Fixed in 3.19.6 CVE-2025-47500 Patchstack
8.1 High Anarkali Plugin anarkali Local File Inclusion No login needed ≤ 1.0.9 CVE-2025-47474 Patchstack
7.1 High HTML5 Video Player with Playlist & Multiple Skins Plugin lbg-vp2-html5-rightside Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.5 CVE-2025-32123 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Request Forgery No login needed ≤ 8.3.13 Fixed in 8.3.14 CVE-2025-31413 Patchstack
7.1 High HTML5 Video Player Plugin lbg-vp2-html5-bottom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.5 CVE-2025-27005 Patchstack
9.8 Critical Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy Privilege Escalation WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.5.0 CVE-2025-15521 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API No login needed ≤ 4.3.2.4 CVE-2025-14798 Wordfence
4.3 Medium Newsletter – Send awesome emails from Plugin newsletter Cross-Site Request Forgery Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription No login needed ≤ 9.1.0 CVE-2026-1051 Wordfence
4.3 Medium Phrase TMS Integration Plugin memsource-connector Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 4.7.5 CVE-2025-12168 Wordfence
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed 2.5.2 – < 2.6.0 Fixed in 2.6.0 CVE-2026-23800 Patchstack
5.0 Medium DK PDF – WordPress PDF Generator Plugin dk-pdf Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery ≤ 2.3.0 CVE-2025-14793 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
6.5 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed ≤ 6.3.6 CVE-2025-12641 Wordfence
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-23550 Patchstack
4.3 Medium SocialChamp with Plugin auto-post-to-social-media-wp-to-social-champ Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.3.5 CVE-2025-14846 Wordfence
6.4 Medium Woodpecker Plugin woodpecker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_name' Shortcode Attribute ≤ 3.0.4 CVE-2025-13967 Wordfence
5.3 Medium Re Gallery Plugin regallery Broken Access Control No login needed ≤ 1.18.9 Fixed in 1.18.10 CVE-2026-22486 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only