WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,651–4,700 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 94 of 342
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Frappé Plugin frappe Local File Inclusion No login needed ≤ 1.8 CVE-2025-69083 Patchstack
5.3 Medium Breeze Plugin breeze Broken Access Control No login needed ≤ 2.2.21 Fixed in 2.2.22 CVE-2025-69364 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-69363 Patchstack
5.9 Medium UiChemy Plugin uichemy Cross-Site Scripting ≤ 4.4.2 Fixed in 4.4.3 CVE-2025-69362 Patchstack
4.3 Medium Post Expirator Plugin post-expirator Broken Access Control ≤ 4.9.3 Fixed in 4.9.4 CVE-2025-69361 Patchstack
6.5 Medium TheGem Theme Elements (for WPBakery) Plugin thegem-elements Cross-Site Scripting ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69360 Patchstack
5.3 Medium Creator LMS Plugin creatorlms Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2025-69359 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69357 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69356 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control ≤ 3.5.6.4 Fixed in 3.5.6.5 CVE-2025-69355 Patchstack
4.3 Medium Better Business Reviews Plugin better-business-reviews Broken Access Control ≤ 0.1.1 Fixed in 0.1.2 CVE-2025-69354 Patchstack
4.3 Medium Proxy & VPN Blocker Plugin proxy-vpn-blocker Broken Access Control ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-69353 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.15.12.2 Fixed in 6.15.13 CVE-2025-69352 Patchstack
8.5 High Ninja Tables Plugin ninja-tables SQL Injection ≤ 5.2.4 Fixed in 5.2.5 CVE-2025-69351 Patchstack
5.9 Medium Accordion Plugin accordions-wp Cross-Site Scripting ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-69350 Patchstack
5.4 Medium RSS Feed Widget Plugin rss-feed-widget Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-69349 Patchstack
4.3 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2025-69348 Patchstack
4.3 Medium AffiliateX Plugin affiliatex Broken Access Control ≤ 1.3.9.3 Fixed in 1.4.0 CVE-2025-69346 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Broken Access Control ≤ 1.27.9 Fixed in 1.27.10 CVE-2025-69345 Patchstack
7.5 High Calafate Theme calafate Local File Inclusion ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-69342 Patchstack
5.4 Medium WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69341 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.9.4 Fixed in 2.9.5 CVE-2025-69336 Patchstack
6.5 Medium Team Showcase Plugin team-showcase Cross-Site Scripting ≤ 2.9 Fixed in 3.0.0 CVE-2025-69335 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-69334 Patchstack
4.3 Medium Theater Plugin theatre Broken Access Control ≤ 0.19 Fixed in 0.19.1 CVE-2025-69331 Patchstack
4.3 Medium Car Rental Manager Plugin car-rental-manager Broken Access Control ≤ 1.0.9 Fixed in 1.2.0 CVE-2025-69327 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.26 Fixed in 2.7.7.27 CVE-2025-69084 Patchstack
7.1 High JobBank Plugin jobbank Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 CVE-2025-69085 Patchstack
8.1 High Issabella Theme issabella Local File Inclusion No login needed ≤ 1.1.2 CVE-2025-69086 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification No login needed ≤ 4.3.2 CVE-2025-13964 Wordfence
5.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion ≤ 3.7.6 CVE-2025-13766 Wordfence
4.3 Medium GamiPress – Gamification plugin to reward points, achievements, badges & ranks in Plugin Broken Access Control Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 7.6.1 CVE-2025-13812 Wordfence
6.5 Medium Page Expire Popup/Redirection Plugin page-expire-popup SQL Injection Authenticated (Author+) SQL Injection via 'id' Shortcode Attribute ≤ 1.0 CVE-2025-14153 Wordfence
9.3 Critical Entrada Theme entrada SQL Injection No login needed ≤ 5.7.7 CVE-2025-39484 Patchstack
6.5 Medium Dokan Pro Plugin dokan-pro Cross-Site Scripting ≤ 3.14.5 CVE-2025-39497 Patchstack
6.5 Medium LoginWP - Pro Plugin loginwp-pro Broken Access Control Pro Plugin <= 4.0.8.5 - Broken Access Control No login needed ≤ 4.0.8.5 Fixed in 4.0.8.6 CVE-2025-39561 Patchstack
7.5 High LoginWP - Pro Plugin loginwp-pro Broken Access Control Pro Plugin <= 4.0.8.5 - Settings Change No login needed ≤ 4.0.8.5 Fixed in 4.0.8.6 CVE-2025-46255 Patchstack
4.3 Medium Thim Core Plugin thim-core Cross-Site Request Forgery No login needed ≤ 2.3.3 CVE-2025-53344 Patchstack
7.1 High iPhone Webclip Manager Plugin iphone-webclip-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5 CVE-2024-53735 Patchstack
7.5 High Booking Package Plugin booking-package Price Manipulation No login needed ≤ 1.6.27 Fixed in 1.6.29 CVE-2024-30516 Patchstack
7.1 High Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30461 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.3.3 Fixed in 5.3.4 CVE-2024-23511 Patchstack
5.4 Medium WP Job Manager Plugin wp-job-manager Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 2.1.0 CVE-2023-52212 Patchstack
6.5 Medium Geo Controller Plugin cf-geoplugin Cross-Site Scripting ≤ 8.5.2 Fixed in 8.5.3 CVE-2023-51513 Patchstack
9.1 Critical Media File Renamer Plugin media-file-renamer Remote Code Execution Arbitrary File Rename lead to RCE ≤ 5.7.7 Fixed in 5.7.8 CVE-2023-50897 Patchstack
7.1 High Machic Core Plugin machic-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6 CVE-2023-49186 Patchstack
9.3 Critical Infility Global Plugin infility-global SQL Injection No login needed ≤ 2.15.06 CVE-2025-68865 Patchstack
7.5 High Sell Downloads Plugin sell-downloads Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.2.0 CVE-2025-68850 Patchstack
7.5 High Follow My Blog Post Plugin follow-my-blog-post Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-68547 Patchstack
8.6 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68044 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only