WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,651–4,700 of 9,038 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 94 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Backwp Plugin backwp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2025-28956 Patchstack
8.1 High SNS Vicky Theme snsvicky Local File Inclusion No login needed ≤ 3.7 CVE-2025-28990 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.3 Fixed in 4.9.4 CVE-2025-28988 Patchstack
8.6 High Content No Cache Plugin content-no-cache Remote Code Execution Arbitrary Function Call No login needed ≤ 0.1.4 Fixed in 0.1.5 CVE-2025-28993 Patchstack
7.1 High Woocommerce Line Notify Plugin woo-line-notify Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-30972 Patchstack
8.1 High SERPed.net Plugin serped-net Local File Inclusion No login needed ≤ 4.6 Fixed in 4.7 CVE-2025-28998 Patchstack
7.1 High Seven Stars Theme sevenstars Cross-Site Scripting No login needed ≤ 1.4.4 CVE-2025-31067 Patchstack
8.1 High Puca Plugin puca Local File Inclusion No login needed ≤ 2.6.33 Fixed in 2.6.34 CVE-2025-30992 Patchstack
7.1 High HYDRO Plugin hydro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 CVE-2025-31428 Patchstack
7.5 High CTUsers Plugin ctuser Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-32298 Patchstack
7.1 High Smart Notification Plugin smio-push-notification Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 10.3 CVE-2025-39478 Patchstack
7.1 High MagOne Theme magone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8 Fixed in 8.9 CVE-2025-39488 Patchstack
7.1 High FormLift for Infusionsoft Web Forms Plugin formlift Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.5.20 Fixed in 7.5.21 CVE-2025-47654 Patchstack
7.1 High School Management Plugin school-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 92.0.0 CVE-2025-47574 Patchstack
7.1 High Eventin Plugin wp-event-solution Cross-Site Scripting No login needed ≤ 4.0.28 Fixed in 4.0.29 CVE-2025-49321 Patchstack
7.1 High Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.8.4 Fixed in 0.5.8.5 CVE-2025-49290 Patchstack
8.1 High Greenmart Plugin greenmart Local File Inclusion No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-49883 Patchstack
8.1 High Zikzag Core Plugin zikzag-core Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-49886 Patchstack
7.1 High Flexo Counter Plugin flexo-countdown Cross-Site Scripting No login needed ≤ 1.0001 CVE-2025-50052 Patchstack
8.1 High Networker Theme networker Local File Inclusion No login needed ≤ 1.2.0 Fixed in 1.2.2 CVE-2025-52723 Patchstack
8.6 High CouponXxL Custom Post Types Plugin couponxxl-cpt Privilege Escalation No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-52726 Patchstack
8.1 High Diza Theme diza Local File Inclusion No login needed ≤ 1.3.9 Fixed in 1.3.11 CVE-2025-52729 Patchstack
7.1 High CSS3 Vertical Web Pricing Tables Plugin css3_vertical_web_pricing_tables Cross-Site Scripting No login needed ≤ 1.9 Fixed in 2.0 CVE-2025-52727 Patchstack
7.1 High xili-dictionary Plugin xili-dictionary Cross-Site Scripting No login needed ≤ 2.12.5.2 CVE-2025-52778 Patchstack
7.1 High Infility Global Plugin infility-global Cross-Site Scripting No login needed ≤ 2.15.06 CVE-2025-52774 Patchstack
8.1 High RealtyElite Plugin realtyelite Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-52808 Patchstack
7.1 High LMS Plugin lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52799 Patchstack
8.1 High National Weather Service Alerts Plugin national-weather-service-alerts Local File Inclusion No login needed ≤ 1.3.5 CVE-2025-52809 Patchstack
8.1 High Davenport - Versatile Blog and Magazine Plugin davenport Local File Inclusion Versatile Blog and Magazine WordPress Theme <= 1.3 - Local File Inclusion No login needed ≤ 1.3 CVE-2025-52811 Patchstack
8.1 High Katerio - Magazine Theme katerio Local File Inclusion Magazine theme <= 1.5.1 - Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-52810 Patchstack
8.1 High Domnoo Plugin domnoo Local File Inclusion No login needed ≤ 1.49 Fixed in 1.52.1 CVE-2025-52812 Patchstack
8.1 High CityGov Theme citygov Local File Inclusion No login needed ≤ 1.9 CVE-2025-52815 Patchstack
8.1 High BRW Plugin ova-brw Local File Inclusion No login needed ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-52814 Patchstack
8.2 High Abandoned Contact Form 7 Plugin abandoned-contact-form-7 Broken Access Control No login needed ≤ 2.2 CVE-2025-52817 Patchstack
8.1 High Zita Plugin zita Local File Inclusion No login needed ≤ 1.6.5 CVE-2025-52816 Patchstack
8.2 High Trusty Whistleblowing Plugin trusty-whistleblowing-solution Broken Access Control No login needed ≤ 2.0.1 CVE-2025-52818 Patchstack
8.8 High Sala Theme sala PHP Object Injection ≤ 1.1.3 CVE-2025-52826 Patchstack
8.8 High Mobile DJ Manager Plugin mobile-dj-manager Privilege Escalation ≤ 1.7.8.3 CVE-2025-52824 Patchstack
8.8 High Nuss Plugin nuss PHP Object Injection ≤ 1.3.3 CVE-2025-52827 Patchstack
8.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed ≤ 2.6 CVE-2023-25998 Patchstack
7.1 High SpecFit-Virtual Try On Woocommerce Plugin try-on-for-woocommerce Cross-Site Scripting No login needed ≤ 8.0.3 CVE-2025-23973 Patchstack
8.1 High FW Gallery Plugin fw-gallery Local File Inclusion No login needed ≤ 8.0.0 CVE-2025-49416 Patchstack
8.1 High Sofass Plugin sofass Local File Inclusion No login needed ≤ 1.3.4 CVE-2025-24760 Patchstack
7.1 High Bulk YouTube Post Creator Plugin bulk-youtube-post-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-49423 Patchstack
8.6 High FW Food Menu Plugin fw-food-menu Arbitrary File Deletion No login needed ≤ 6.0.0 CVE-2025-49448 Patchstack
7.2 High Ninja Tables – Easy Data Table Builder Plugin ninja-tables Server-Side Request Forgery Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery No login needed ≤ 5.0.18 CVE-2025-2940 Wordfence
7.2 High Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Database module No login needed 3.5.11 – 3.5.19 CVE-2025-6212 Wordfence
8.8 High Owl carousel responsive Plugin responsive-owl-carousel SQL Injection Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.9 CVE-2025-5590 Wordfence
7.5 High Everest Forms (Pro) Plugin everest-forms Path Traversal Unauthenticated Path Traversal to Arbitrary File Deletion No login needed ≤ 1.9.4 CVE-2025-5927 Wordfence
7.5 High Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Arbitrary File Upload AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.5.0 CVE-2025-6206 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only