WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,601–4,650 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 93 of 342
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Felan Framework Plugin felan-framework Privilege Escalation Account Takeover No login needed ≤ 1.1.3 CVE-2025-23504 Patchstack
8.5 High Workreap (theme's plugin) Plugin workreap SQL Injection ≤ 3.3.6 CVE-2025-22728 Patchstack
6.4 Medium nK Themes Helper Plugin nk-themes-helper Server-Side Request Forgery ≤ 1.7.9 CVE-2025-22726 Patchstack
7.1 High WP Virtual Assistant Plugin virtualassistant Cross-Site Scripting No login needed ≤ 3.1 CVE-2025-22725 Patchstack
7.5 High WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Broken Access Control Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion No login needed ≤ 1.25 CVE-2025-22715 Patchstack
8.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei SQL Injection ≤ 5.4 CVE-2025-22713 Patchstack
8.1 High Typify Plugin typify Local File Inclusion No login needed ≤ 3.0.2 CVE-2025-22712 Patchstack
8.1 High Mitech Plugin mitech Local File Inclusion No login needed ≤ 2.3.4 CVE-2025-22708 Patchstack
8.1 High Moody Plugin tm-moody Local File Inclusion No login needed ≤ 2.7.3 CVE-2025-22707 Patchstack
8.1 High Atlas Plugin atlas Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-22509 Patchstack
8.1 High Navian Theme navian Local File Inclusion No login needed ≤ 1.5.4 CVE-2025-14431 Patchstack
8.1 High Brook Plugin brook Local File Inclusion Agency Business Creative theme <= 2.9.0 - Local File Inclusion No login needed ≤ 2.9.0 CVE-2025-14430 Patchstack
8.1 High AeroLand Plugin aeroland Local File Inclusion No login needed ≤ 1.6.6 CVE-2025-14429 Patchstack
7.5 High Blockons Plugin blockons Broken Access Control No login needed ≤ 1.2.19 CVE-2025-14360 Patchstack
8.1 High Oshine Theme oshin Local File Inclusion No login needed < 7.3.0 Fixed in 7.3.0 CVE-2025-14359 Patchstack
7.5 High REHub Framework Plugin rehub-framework Broken Access Control No login needed ≤ 19.9.5 Fixed in 19.9.9.6 CVE-2025-14358 Patchstack
7.1 High Real Estate Pro Plugin real-estate-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 CVE-2025-13504 Patchstack
7.1 High ListingHub Plugin listinghub Cross-Site Scripting No login needed ≤ 1.2.6 CVE-2025-12551 Patchstack
8.1 High OchaHouse Theme ochahouse Local File Inclusion No login needed ≤ 2.2.8 CVE-2025-12550 Patchstack
8.1 High Rozy - Flower Shop Theme rozy Local File Inclusion Flower Shop theme <= 1.2.25 - Local File Inclusion No login needed ≤ 1.2.25 CVE-2025-12549 Patchstack
4.9 Medium External Media Plugin external-media Server-Side Request Forgery ≤ 1.0.36 CVE-2025-49335 Patchstack
9.8 Critical DZS Video Gallery Plugin dzs-videogallery PHP Object Injection No login needed ≤ 12.37 CVE-2025-47552 Patchstack
7.1 High WidgetKit Pro Plugin widgetkit-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.1 CVE-2025-46494 Patchstack
6.5 Medium The Plus Addons for Elementor Pro Plugin theplus_elementor_addon Broken Access Control ≤ 6.3.7 Fixed in 6.3.7 CVE-2025-46434 Patchstack
6.4 Medium Advanced Database Cleaner PRO Plugin advanced-database-cleaner-pro Path Traversal Limited .txt Path Traversal ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-46256 Patchstack
9.3 Critical WPCHURCH Plugin church-management SQL Injection No login needed ≤ 2.7.0 CVE-2025-32303 Patchstack
7.1 High DZS Video Gallery Plugin dzs-videogallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.25 CVE-2025-32300 Patchstack
8.8 High WPCHURCH Plugin church-management Privilege Escalation ≤ 2.7.0 CVE-2025-31643 Patchstack
8.1 High Gecko Theme gecko Local File Inclusion No login needed ≤ 1.9.8 CVE-2025-69080 Patchstack
8.1 High Hope Theme charity-is-hope Local File Inclusion No login needed ≤ 3.0.0 CVE-2025-69081 Patchstack
7.1 High Arlo Plugin arlo Cross-Site Scripting No login needed ≤ 6.0.3 CVE-2025-69082 Patchstack
4.3 Medium JetEngine Plugin jet-engine Broken Access Control ≤ 3.8.1.1 Fixed in 3.8.1.2 CVE-2025-69333 Patchstack
4.3 Medium Oneline Lite Plugin oneline-lite Broken Access Control ≤ 6.6 Fixed in 6.7 CVE-2025-69344 Patchstack
6.1 Medium Stumble! Plugin stumble-for-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 1.1.1 CVE-2025-14128 Wordfence
6.4 Medium Recras Plugin recras Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'recrasname' Shortcode Attribute ≤ 6.4.1 CVE-2025-13497 Wordfence
4.3 Medium MTCaptcha Plugin mtcaptcha Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.7.2 CVE-2025-13520 Wordfence
5.4 Medium aBlocks – WordPress Gutenberg Blocks Plugin ablocks Broken Access Control WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification ≤ 2.4.0 CVE-2025-12449 Wordfence
5.4 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion ≤ 4.3.2.1 CVE-2025-14802 Wordfence
6.5 Medium Flashcard Plugin flashcard Path Traversal Authenticated (Contributor+) Arbitrary File Read via Path Traversal ≤ 0.9 CVE-2025-14867 Wordfence
4.4 Medium twinklesmtp – Email Service Provider Plugin twinklesmtp Cross-Site Scripting Email Service Provider For WordPress <= 1.03 - Authenticated (Administrator+) Stored Cross-Site Scripting via Sender Settings ≤ 1.03 CVE-2025-14887 Wordfence
7.1 High WPCHURCH Plugin church-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.0 CVE-2025-31642 Patchstack
5.3 Medium Plant - Gardening & Houseplants Theme plant Information Disclosure Gardening & Houseplants WordPress Theme <= 1.0.0 - Sensitive Data Exposure No login needed ≤ 1.0.0 CVE-2025-31051 Patchstack
9.9 Critical Themify Sidepane Theme sidepane Arbitrary File Upload Arbitrary File Upload Vulnerability in WordPress themes by Themify ≤ 1.9.8, ≤ 1.9.9, ≤ 1.9.6, … CVE-2025-30996 Patchstack
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
8.8 High Premium Age Verification / Restriction Plugin age-restriction Privilege Escalation Privilege Escalation Vulnerability in AA-Team WordPress plugins ≤ 3.0.2, ≤ 3.0 CVE-2025-29004 Patchstack
8.1 High WPCHURCH Plugin church-management Local File Inclusion No login needed ≤ 2.7.0 CVE-2025-32304 Patchstack
9.8 Critical InWave Jobs Plugin iwjob Broken Access Control No login needed ≤ 3.5.8 CVE-2025-39477 Patchstack
6.5 Medium AdsPlace'r – Ad Manager, Inserter, AdSense Ads Plugin adsplacer Cross-Site Scripting Ad Manager, Inserter, AdSense Ads plugin <= 1.1.5 - Cross Site Scripting (XSS) ≤ 1.1.5 CVE-2024-31088 Patchstack
7.1 High Header Image Slider Plugin header-image-slider Cross-Site Scripting No login needed ≤ 0.3 CVE-2024-30547 Patchstack
8.8 High DZS Video Gallery Plugin dzs-videogallery PHP Object Injection ≤ 12.25 CVE-2025-47553 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only