WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 4,601–4,650 of 9,038 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | Download | Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload |
≤ 2.2.8 |
CVE-2025-6586 |
Wordfence | |
| 8.8 High | WP Human Resource Management | Broken Access Control Missing Authorization to Authenticated (Employee+) Privilege Escalation via wp_ajax_hrm_insert_employee AJAX Action |
2.0.0 – 2.2.17 |
CVE-2025-5953 |
Wordfence | |
| 8.0 High | AI Engine | Open Redirect Insecure OAuth Implementation |
2.8.4 |
CVE-2025-6238 |
Wordfence | |
| 7.2 High | VikRentCar Car Rental Management System | Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload |
≤ 1.4.3 |
CVE-2025-5322 |
Wordfence | |
| 7.2 High | Migration, Backup, Staging – WPvivid Backup & Migration | Arbitrary File Upload WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload |
≤ 0.9.116 |
CVE-2025-5961 |
Wordfence | |
| 8.8 High | JKDEVKIT | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 1.9.4 |
CVE-2025-2932 |
Wordfence | |
| 8.1 High | Vikinger | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax Function |
≤ 1.9.32 |
CVE-2025-4946 |
Wordfence | |
| 7.5 High | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | PHP Object Injection Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion No login needed |
≤ 1.44.2 |
CVE-2025-6464 |
Wordfence | |
| 8.8 High | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Arbitrary File Deletion Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion No login needed |
≤ 1.44.2 |
CVE-2025-6463 |
Wordfence | |
| 7.5 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Time-Based SQL Injection via ‘bsa_pro_id' No login needed |
≤ 4.89 |
CVE-2025-5339 |
Wordfence | |
| 7.5 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection via oid No login needed |
≤ 4.89 |
CVE-2025-6437 |
Wordfence | |
| 8.8 High | Home Villas | Real Estate | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 2.8 |
CVE-2025-5014 |
Wordfence | |
| 7.2 High | Amazon Products to WooCommerce | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
≤ 1.2.7 |
CVE-2025-5817 |
Wordfence | |
| 8.1 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | Local File Inclusion Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion No login needed |
≤ 4.89 |
CVE-2025-4380 |
Wordfence | |
| 8.8 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | Cross-Site Request Forgery Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery to PHP Code Injection in bsaCreateAdTemplate No login needed |
≤ 4.89 |
CVE-2025-6459 |
Wordfence | |
| 7.5 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection No login needed |
≤ 4.89 |
CVE-2025-4381 |
Wordfence | |
| 8.8 High | Game Users Share Buttons | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via themeNameId Parameter |
≤ 1.3.0 |
CVE-2025-6755 |
Wordfence | |
| 8.8 High | BeeTeam368 Extensions | Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion |
≤ 2.3.4 |
CVE-2025-6381 |
Wordfence | |
| 8.8 High | BeeTeam368 Extensions Pro | Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion |
≤ 2.3.4 |
CVE-2025-6379 |
Wordfence | |
| 7.5 High | Devnex Addons For Elementor | Local File Inclusion |
≤ 1.0.9 |
CVE-2025-53339 |
Patchstack | |
| 7.1 High | re.place | Cross-Site Request Forgery No login needed |
≤ 0.2.1 |
CVE-2025-53338 |
Patchstack | |
| 7.1 High | Track Everything | Cross-Site Request Forgery No login needed |
≤ 2.0.1 |
CVE-2025-53332 |
Patchstack | |
| 7.1 High | RSS Digest | Cross-Site Request Forgery No login needed |
≤ 1.5 |
CVE-2025-53331 |
Patchstack | |
| 7.1 High | Społecznościowa 6 PL 2013 | Cross-Site Request Forgery No login needed |
≤ 2.0.6 |
CVE-2025-53329 |
Patchstack | |
| 7.1 High | WPShapere - WordPress admin | Cross-Site Request Forgery No login needed |
≤ 1.4.1 |
CVE-2025-53317 |
Patchstack | |
| 7.1 High | Relocate Upload | Cross-Site Request Forgery No login needed |
≤ 0.24.1 |
CVE-2025-53315 |
Patchstack | |
| 7.1 High | Twitch TV Embed Suite | Cross-Site Request Forgery No login needed |
≤ 2.1.0 |
CVE-2025-53313 |
Patchstack | |
| 7.1 High | OnionBuzz | Cross-Site Request Forgery No login needed |
≤ 1.0.7 |
CVE-2025-53312 |
Patchstack | |
| 7.1 High | Navayan Subscribe | Cross-Site Request Forgery No login needed |
≤ 1.13 |
CVE-2025-53311 |
Patchstack | |
| 7.1 High | HidePost | Cross-Site Request Forgery No login needed |
≤ 2.3.8 |
CVE-2025-53310 |
Patchstack | |
| 7.1 High | Image Slider With Description | Cross-Site Request Forgery No login needed |
≤ 9.2 |
CVE-2025-53308 |
Patchstack | |
| 7.6 High | WP Forum Server | SQL Injection |
≤ 1.8.2 |
CVE-2025-53306 |
Patchstack | |
| 7.1 High | WP Forum Server | Cross-Site Request Forgery No login needed |
≤ 1.8.2 |
CVE-2025-53305 |
Patchstack | |
| 7.5 High | WPB Category Slider for WooCommerce | Local File Inclusion |
≤ 1.71 |
CVE-2025-53281 |
Patchstack | |
| 8.8 High | IS-theme-companion | Cross-Site Request Forgery No login needed |
≤ 1.59 |
CVE-2025-53277 |
Patchstack | |
| 7.1 High | WP Permalink Translator | Cross-Site Request Forgery No login needed |
≤ 1.7.6 |
CVE-2025-53274 |
Patchstack | |
| 7.1 High | Additional Order Filters for WooCommerce | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.22 Fixed in 1.23 |
CVE-2025-53271 |
Patchstack | |
| 7.5 High | Hotel Booking | Local File Inclusion |
≤ 3.7 Fixed in 3.8 |
CVE-2025-53259 |
Patchstack | |
| 7.6 High | Hover Effects | SQL Injection |
≤ 2.1.2 Fixed in 2.1.3 |
CVE-2025-53258 |
Patchstack | |
| 7.5 High | Gmedia Photo Gallery | Local File Inclusion |
≤ 1.23.0 Fixed in 1.24.0 |
CVE-2025-53257 |
Patchstack | |
| 7.6 High | YaySMTP | SQL Injection |
≤ 2.6.6 Fixed in 2.6.7 |
CVE-2025-53256 |
Patchstack | |
| 7.7 High | Image Shadow | Arbitrary File Deletion |
≤ 1.1.0 |
CVE-2025-24765 |
Patchstack | |
| 7.1 High | WPCRM - CRM for Contact form CF7 & WooCommerce | Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.0 |
CVE-2025-24774 |
Patchstack | |
| 8.1 High | Zenny | Local File Inclusion No login needed |
≤ 1.7.5 |
CVE-2025-24769 |
Patchstack | |
| 7.1 High | FastBook | Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-25173 |
Patchstack | |
| 8.8 High | WP SmartPay | Privilege Escalation Account Takeover |
≤ 2.7.13 Fixed in 2.8.0 |
CVE-2025-25171 |
Patchstack | |
| 7.1 High | Photo Express for Google | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.3.2 |
CVE-2025-27361 |
Patchstack | |
| 8.1 High | MBStore - Digital WooCommerce | Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed |
≤ 2.3 |
CVE-2025-28947 |
Patchstack | |
| 8.1 High | PrintXtore | Local File Inclusion No login needed |
≤ 1.7.8 Fixed in 1.7.8 |
CVE-2025-28946 |
Patchstack | |
| 7.1 High | Evangelische Termine | Cross-Site Scripting No login needed |
≤ 3.3 |
CVE-2025-28960 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.