WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,501–4,550 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 91 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Orion Login with SMS Plugin orion-login-with-sms Authentication Bypass Authentication Bypass via Weak OTP No login needed ≤ 1.0.5 CVE-2025-7692 Wordfence
8.1 High Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) Plugin extensions-for-cf7 Arbitrary File Deletion Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission Deletion No login needed ≤ 3.2.8 CVE-2025-7645 Wordfence
8.1 High WP JobHunt Plugin Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account Deletion ≤ 7.2 CVE-2025-6585 Wordfence
8.8 High WPLMS Learning Management System for WordPress, WordPress LMS Theme Privilege Escalation ≤ 1.8.4.1 CVE-2015-10139 Wordfence
7.5 High GI-Media Library Plugin gi-media-library Path Traversal Directory Traversal No login needed < 3.0 Fixed in 3.0 CVE-2015-10136 Wordfence
7.5 High Simple Backup Plugin Path Traversal Arbitrary File Download via Path Traversal No login needed < 2.7.11 Fixed in 2.7.11 CVE-2015-10134 Wordfence
7.5 High MasterStudy LMS – Online Courses, eLearning PRO Plus Plugin Arbitrary File Upload Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.7.9 CVE-2025-7438 Wordfence
8.8 High B1.lt for WooCommerce Plugin b1-accounting Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection ≤ 2.2.57 CVE-2025-6718 Wordfence
8.8 High aapanel WP Toolkit Plugin aapanel-wp-toolkit Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via auto_login() Function 1.0 – 1.1 CVE-2025-6813 Wordfence
8.8 High School Management System Plugin wpschoolpress Local File Inclusion Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update ≤ 93.1.0 CVE-2025-3740 Wordfence
7.5 High Easy Video Player Wordpress & WooCommerce Plugin fwdevp Path Traversal Arbitrary File Download No login needed ≤ 10.0 CVE-2025-28955 Patchstack
8.8 High Yogi Plugin yogi PHP Object Injection ≤ 2.9.3 Fixed in 2.9.3 CVE-2025-24779 Patchstack
8.8 High Hillter Theme hillter PHP Object Injection ≤ 3.0.7 CVE-2025-24777 Patchstack
8.6 High URL Shortener Plugin exact-links Broken Access Control No login needed ≤ 3.0.7 CVE-2025-28965 Patchstack
7.5 High Multi-language Responsive Contact Form Plugin responsive-contact-form Broken Access Control No login needed ≤ 2.8 CVE-2025-29000 Patchstack
7.1 High ListingEasy Plugin listingeasy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2025-30955 Patchstack
7.1 High Electrician - Electrical Service Plugin electrician Cross-Site Scripting Electrical Service WordPress theme <= 1.0 - Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-31055 Patchstack
7.1 High Ofiz - WordPress Business Consulting Plugin ofiz Cross-Site Scripting Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31072 Patchstack
7.5 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg-cleverbakery Path Traversal WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download No login needed ≤ 2.5 Fixed in 2.5.3 CVE-2025-31070 Patchstack
7.1 High Invico - WordPress Consulting Business Plugin invico Cross-Site Scripting WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-31427 Patchstack
8.8 High Visual Art | Gallery Plugin visual-arts PHP Object Injection ≤ 2.4 CVE-2025-31422 Patchstack
7.1 High Wordpress Auto Spinner Plugin wp-auto-spinner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.26.0 CVE-2025-46500 Patchstack
8.5 High WPGYM Plugin gym-management SQL Injection ≤ 65.0 CVE-2025-32574 Patchstack
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
7.1 High CSS3 Compare Pricing Tables Plugin css3_web_pricing_tables_grids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.6 Fixed in 11.7 CVE-2025-47554 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 26.0.6 Fixed in 26.0.7 CVE-2025-48291 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13.4 Fixed in 2.13.5 CVE-2025-47652 Patchstack
7.1 High SMu Manual DoFollow Plugin manuall-dofollow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 CVE-2025-49031 Patchstack
7.1 High Contact Form 7 Editor Button Plugin cf7-editor-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-48345 Patchstack
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.10.2 Fixed in 3.11.0 CVE-2025-49034 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49876 Patchstack
7.1 High PW WooCommerce On Sale! Plugin pw-woocommerce-on-sale Broken Access Control ≤ 1.39 Fixed in 1.40 CVE-2025-49888 Patchstack
7.1 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-52777 Patchstack
7.1 High Media Folder Plugin media-folder Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-52786 Patchstack
7.1 High Dot html,php,xml etc pages Plugin dot-htmlphpxml-etc-pages Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-52779 Patchstack
7.5 High Sala Theme sala Broken Access Control No login needed ≤ 1.1.3 CVE-2025-52803 Patchstack
7.1 High Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2025-52787 Patchstack
8.5 High Pakke Envíos Plugin pakke SQL Injection ≤ 1.0.2 CVE-2025-52819 Patchstack
7.5 High Nuss Plugin nuss Broken Access Control No login needed ≤ 1.3.7.1 CVE-2025-52804 Patchstack
7.1 High Import CDN-Remote Images Plugin import-cdn-remote-images Cross-Site Request Forgery No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-48153 Patchstack
7.6 High YaySMTP Plugin smtp-sendinblue SQL Injection ≤ 1.3 Fixed in 1.3.1 CVE-2025-48161 Patchstack
7.6 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid SQL Injection YaySMTP plugin <= 1.5 - SQL Injection ≤ 1.5 Fixed in 1.5.1 CVE-2025-48301 Patchstack
7.6 High YayExtra Plugin yayextra SQL Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48299 Patchstack
7.6 High SMTP for Amazon SES Plugin smtp-amazon-ses SQL Injection ≤ 1.9 Fixed in 1.9.1 CVE-2025-54043 Patchstack
8.5 High GymBase Theme Classes Plugin gymbase_classes SQL Injection ≤ 1.4 Fixed in 1.5 CVE-2025-54026 Patchstack
7.2 High JetFormBuilder Plugin jetformbuilder PHP Object Injection ≤ 3.5.1.2 Fixed in 3.5.2 CVE-2025-53990 Patchstack
7.5 High Ultimate WP Mail Plugin ultimate-wp-mail Broken Access Control Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function 1.0.17 – 1.3.6 CVE-2025-6993 Wordfence
8.1 High Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin wp-malware-removal Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.0 CVE-2025-6043 Wordfence
8.2 High Counter live visitors for WooCommerce Plugin counter-visitor-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion in wcvisitor_get_block No login needed ≤ 1.3.6 CVE-2025-7359 Wordfence
7.2 High WP Event Manager Plugin wp-event-manager Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'organizer_name' No login needed ≤ 3.1.50 CVE-2025-2800 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only