WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,551–4,600 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 92 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Restrict File Access Plugin restrict-file-access Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.1.2 CVE-2025-7667 Wordfence
7.5 High Total Upkeep by BoldGrid Plugin boldgrid-backup Information Disclosure Unauthenticated Backup Download No login needed ≤ 1.14.9 CVE-2020-36848 Wordfence
7.5 High Friends Plugin friends PHP Object Injection Authenticated (Subscriber+) PHP Object Injection 3.5.1 CVE-2025-7504 Wordfence
8.8 High BeeTeam368 Extensions Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.3.5 CVE-2025-6423 Wordfence
8.8 High Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.3 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 1.6.3 CVE-2025-1313 Wordfence
8.8 High WPBookit Plugin wpbookit Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.0.4 CVE-2025-6057 Wordfence
7.2 High Broken Link Notifier Plugin broken-link-notifier Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 1.3.0 CVE-2025-6851 Wordfence
7.5 High WPGYM - Wordpress Gym Management System Plugin SQL Injection Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection No login needed < 67.8.0 Fixed in 67.8.0 CVE-2025-7442 Wordfence
7.5 High Events Manager Plugin events-manager SQL Injection Unauthenticated SQL Injection via `orderby` Parameter No login needed ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6970 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms PHP Object Injection Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6742 Wordfence
8.1 High SureForms – Drag and Drop Form Builder Plugin sureforms Arbitrary File Deletion Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion No login needed 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, … CVE-2025-6691 Wordfence
7.3 High Woodmart Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.2.3 CVE-2025-6744 Wordfence
8.8 High WoodMart Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 8.2.3 CVE-2025-6746 Wordfence
8.8 High Widget for Google Reviews Plugin Path Traversal Authenticated (Subscriber+) Directory Traversal to Local File Inclusion ≤ 1.0.15 CVE-2025-7327 Wordfence
7.1 High Zilom Plugin zilom Cross-Site Scripting No login needed ≤ 1.4.5 Fixed in 1.4.5 CVE-2024-43334 Patchstack
7.1 High Content Manager Light Plugin content-manager-light Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2 CVE-2025-24771 Patchstack
7.1 High WP Wall Plugin wp-wall Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-28968 Patchstack
8.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24780 Patchstack
7.1 High SB Breadcrumbs Plugin sb-breadcrumbs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-28978 Patchstack
7.7 High Aviation Weather from NOAA Plugin aviation-weather-from-noaa Arbitrary File Deletion ≤ 0.7.2 CVE-2025-28980 Patchstack
7.1 High Homey Plugin homey Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2025-31037 Patchstack
7.1 High Pressroom Theme pressroom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0 Fixed in 7.1 CVE-2025-32311 Patchstack
8.5 High Simple Link Directory Plugin qc-simple-link-directory SQL Injection ≤ 14.8.1 Fixed in 14.8.1 CVE-2025-32297 Patchstack
7.1 High Rankie Plugin valvepress-rankie Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-39487 Patchstack
7.5 High PrivateContent - Mail Actions Plugin private-content-mail-actions Local File Inclusion Mail Actions plugin <= 2.3.2 - Local File Inclusion No login needed ≤ 2.3.2 CVE-2025-47627 Patchstack
7.1 High Testimonials Showcase Plugin testimonials-showcase Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49245 Patchstack
7.1 High Neom Blog Plugin neom-blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.9 Fixed in 0.1.0 CVE-2025-49274 Patchstack
7.1 High Team Showcase Plugin team-showcase-cm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49247 Patchstack
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions SQL Injection No login needed ≤ 2.15.1 Fixed in 2.15.2 CVE-2025-49870 Patchstack
7.1 High Video List Manager Plugin video-list-manager Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-52776 Patchstack
7.2 High Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.2 Fixed in 7.8.5 CVE-2025-52718 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.6 CVE-2025-52798 Patchstack
7.1 High WP-Recall Plugin wp-recall Cross-Site Scripting No login needed ≤ 16.26.14 CVE-2025-52796 Patchstack
8.1 High Kossy - Minimalist eCommerce Plugin kossy Local File Inclusion Minimalist eCommerce WordPress Theme <= 1.45 - Local File Inclusion No login needed ≤ 1.45 CVE-2025-52807 Patchstack
7.5 High Leyka Plugin leyka Local File Inclusion No login needed ≤ 3.32.1 CVE-2025-52805 Patchstack
8.8 High Red Art Plugin redart PHP Object Injection ≤ 3.8 Fixed in 3.9 CVE-2025-52828 Patchstack
8.1 High MobiLoud Plugin mobiloud-mobile-app-plugin Broken Access Control ≤ 4.6.5 CVE-2025-52813 Patchstack
7.5 High Elessi Plugin elessi-theme Local File Inclusion ≤ 6.4.1 Fixed in 6.4.1 CVE-2025-49070 Patchstack
8.1 High CMSMasters Content Composer Plugin cmsmasters-content-composer Local File Inclusion No login needed ≤ 2.5.7 Fixed in 2.5.7 CVE-2025-4414 Patchstack
7.2 High Allmart Plugin allmart-core Server-Side Request Forgery No login needed ≤ 1.0.0 CVE-2025-49418 Patchstack
8.5 High Pixelating image slideshow gallery Plugin pixelating-image-slideshow-gallery SQL Injection ≤ 8.0 CVE-2025-30979 Patchstack
8.5 High iFrame Images Gallery Plugin wp-iframe-images-gallery SQL Injection ≤ 9.0 CVE-2025-30969 Patchstack
8.5 High Cool fade popup Plugin cool-fade-popup SQL Injection ≤ 10.1 CVE-2025-30947 Patchstack
8.5 High Gallery Widget Plugin gallery-widget SQL Injection ≤ 1.2.1 CVE-2025-28969 Patchstack
8.5 High Contact Us page - Contact people LITE Plugin contact-us-page-contact-people SQL Injection Contact people LITE plugin <= 3.7.4 - SQL Injection ≤ 3.7.4 CVE-2025-28967 Patchstack
7.7 High Chatra Live Chat + ChatBot + Cart Saver Plugin chatra-live-chat Cross-Site Scripting ≤ 1.0.11 CVE-2025-24735 Patchstack
7.5 High GoZen Forms Plugin gozen-forms SQL Injection Unauthenticated SQL Injection via dirGZActiveForm() No login needed ≤ 1.1.5 CVE-2025-6782 Wordfence
7.5 High Booking X Plugin booking-x Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via export_now() Function No login needed 1.0 – 1.1.2 CVE-2025-6814 Wordfence
7.5 High GoZen Forms Plugin gozen-forms SQL Injection Unauthenticated SQL Injection via emdedSc() No login needed ≤ 1.1.5 CVE-2025-6783 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only