WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,601–4,650 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 93 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Download Plugin download-plugin Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.2.8 CVE-2025-6586 Wordfence
8.8 High WP Human Resource Management Plugin hrm Broken Access Control Missing Authorization to Authenticated (Employee+) Privilege Escalation via wp_ajax_hrm_insert_employee AJAX Action 2.0.0 – 2.2.17 CVE-2025-5953 Wordfence
8.0 High AI Engine Plugin ai-engine Open Redirect Insecure OAuth Implementation 2.8.4 CVE-2025-6238 Wordfence
7.2 High VikRentCar Car Rental Management System Plugin vikrentcar Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 1.4.3 CVE-2025-5322 Wordfence
7.2 High Migration, Backup, Staging – WPvivid Backup & Migration Plugin wpvivid-backuprestore Arbitrary File Upload WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload ≤ 0.9.116 CVE-2025-5961 Wordfence
8.8 High JKDEVKIT Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.9.4 CVE-2025-2932 Wordfence
8.1 High Vikinger Theme Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax Function ≤ 1.9.32 CVE-2025-4946 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator PHP Object Injection Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6464 Wordfence
8.8 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Arbitrary File Deletion Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6463 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Time-Based SQL Injection via ‘bsa_pro_id' No login needed ≤ 4.89 CVE-2025-5339 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection via oid No login needed ≤ 4.89 CVE-2025-6437 Wordfence
8.8 High Home Villas | Real Estate Theme Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 2.8 CVE-2025-5014 Wordfence
7.2 High Amazon Products to WooCommerce Plugin import-products-to-wc Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 1.2.7 CVE-2025-5817 Wordfence
8.1 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin Local File Inclusion Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion No login needed ≤ 4.89 CVE-2025-4380 Wordfence
8.8 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin Cross-Site Request Forgery Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery to PHP Code Injection in bsaCreateAdTemplate No login needed ≤ 4.89 CVE-2025-6459 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection No login needed ≤ 4.89 CVE-2025-4381 Wordfence
8.8 High Game Users Share Buttons Plugin game-users-share-buttons Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via themeNameId Parameter ≤ 1.3.0 CVE-2025-6755 Wordfence
8.8 High BeeTeam368 Extensions Plugin Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion ≤ 2.3.4 CVE-2025-6381 Wordfence
8.8 High BeeTeam368 Extensions Pro Plugin Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion ≤ 2.3.4 CVE-2025-6379 Wordfence
7.5 High Devnex Addons For Elementor Plugin devnex-addons-for-elementor Local File Inclusion ≤ 1.0.9 CVE-2025-53339 Patchstack
7.1 High re.place Plugin replace Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-53338 Patchstack
7.1 High Track Everything Plugin track-everything Cross-Site Request Forgery No login needed ≤ 2.0.1 CVE-2025-53332 Patchstack
7.1 High RSS Digest Plugin rss-digest Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-53331 Patchstack
7.1 High Społecznościowa 6 PL 2013 Plugin spolecznosciowa-6-pl-2013 Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2025-53329 Patchstack
7.1 High WPShapere - WordPress admin Plugin wpshapere-lite Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-53317 Patchstack
7.1 High Relocate Upload Plugin relocate-upload Cross-Site Request Forgery No login needed ≤ 0.24.1 CVE-2025-53315 Patchstack
7.1 High Twitch TV Embed Suite Plugin twitch-tv-embed-suite Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-53313 Patchstack
7.1 High OnionBuzz Plugin onionbuzz-viral-quiz Cross-Site Request Forgery No login needed ≤ 1.0.7 CVE-2025-53312 Patchstack
7.1 High Navayan Subscribe Plugin navayan-subscribe Cross-Site Request Forgery No login needed ≤ 1.13 CVE-2025-53311 Patchstack
7.1 High HidePost Plugin hidepost Cross-Site Request Forgery No login needed ≤ 2.3.8 CVE-2025-53310 Patchstack
7.1 High Image Slider With Description Plugin image-slider-with-description Cross-Site Request Forgery No login needed ≤ 9.2 CVE-2025-53308 Patchstack
7.6 High WP Forum Server Plugin forum-server SQL Injection ≤ 1.8.2 CVE-2025-53306 Patchstack
7.1 High WP Forum Server Plugin forum-server Cross-Site Request Forgery No login needed ≤ 1.8.2 CVE-2025-53305 Patchstack
7.5 High WPB Category Slider for WooCommerce Plugin wpb-woocommerce-category-slider Local File Inclusion ≤ 1.71 CVE-2025-53281 Patchstack
8.8 High IS-theme-companion Plugin weblizar-companion Cross-Site Request Forgery No login needed ≤ 1.59 CVE-2025-53277 Patchstack
7.1 High WP Permalink Translator Plugin wp-permalink-translator Cross-Site Request Forgery No login needed ≤ 1.7.6 CVE-2025-53274 Patchstack
7.1 High Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.22 Fixed in 1.23 CVE-2025-53271 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.7 Fixed in 3.8 CVE-2025-53259 Patchstack
7.6 High Hover Effects Plugin hover-effects SQL Injection ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-53258 Patchstack
7.5 High Gmedia Photo Gallery Plugin grand-media Local File Inclusion ≤ 1.23.0 Fixed in 1.24.0 CVE-2025-53257 Patchstack
7.6 High YaySMTP Plugin yaysmtp SQL Injection ≤ 2.6.6 Fixed in 2.6.7 CVE-2025-53256 Patchstack
7.7 High Image Shadow Plugin image-shadow Arbitrary File Deletion ≤ 1.1.0 CVE-2025-24765 Patchstack
7.1 High WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 CVE-2025-24774 Patchstack
8.1 High Zenny Plugin bw-zenny Local File Inclusion No login needed ≤ 1.7.5 CVE-2025-24769 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
8.8 High WP SmartPay Plugin smartpay Privilege Escalation Account Takeover ≤ 2.7.13 Fixed in 2.8.0 CVE-2025-25171 Patchstack
7.1 High Photo Express for Google Plugin photo-express-for-google Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.2 CVE-2025-27361 Patchstack
8.1 High MBStore - Digital WooCommerce Plugin mbstore Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed ≤ 2.3 CVE-2025-28947 Patchstack
8.1 High PrintXtore Theme bw-printxtore Local File Inclusion No login needed ≤ 1.7.8 Fixed in 1.7.8 CVE-2025-28946 Patchstack
7.1 High Evangelische Termine Plugin evangtermine Cross-Site Scripting No login needed ≤ 3.3 CVE-2025-28960 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only