WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,701–4,750 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 95 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Knowledge Base – Knowledge Base Maker Plugin knowledge-base-maker Cross-Site Request Forgery Knowledge Base Maker plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2025-52791 Patchstack
7.1 High WP-DownloadCounter Plugin wp-downloadcounter Cross-Site Request Forgery No login needed ≤ 1.01 CVE-2025-52790 Patchstack
7.1 High Esselink.nu Settings Plugin esselinknu-settings Cross-Site Request Forgery No login needed ≤ 4.5 CVE-2025-52793 Patchstack
7.1 High WP User Stylesheet Switcher Plugin wp-user-stylesheet-switcher Cross-Site Request Forgery No login needed ≤ v2.2.0 CVE-2025-52792 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Request Forgery No login needed ≤ 5.0.6 CVE-2025-52795 Patchstack
7.1 High Creative Contact Form Plugin sexy-contact-form Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-52794 Patchstack
8.5 High Video List Manager Plugin video-list-manager SQL Injection ≤ 1.7 CVE-2025-52821 Patchstack
7.5 High Import YouTube videos as WP Posts Plugin import-youtube-videos-as-wp-post Broken Access Control No login needed ≤ 2.1 CVE-2025-52802 Patchstack
8.8 High Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-52825 Patchstack
8.5 High WP Roadmap Plugin wp-roadmap SQL Injection ≤ 2.1.3 Fixed in 2.2.0 CVE-2025-52822 Patchstack
7.5 High Classified Listing Plugin classified-listing Local File Inclusion ≤ 4.2.0 Fixed in 4.2.1 CVE-2025-52715 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.7 Fixed in 1.3.7.1 CVE-2025-52708 Patchstack
7.2 High Beaver Builder Plugin (Starter Version) Plugin Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.9.1 CVE-2025-4102 Wordfence
8.8 High AI Engine Plugin ai-engine Privilege Escalation Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP 2.8.0 – 2.8.3 CVE-2025-5071 Wordfence
7.2 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'save_options' ≤ 3.5.12 CVE-2025-6220 Wordfence
7.2 High CSV Me Plugin csv-me Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.0 CVE-2025-6086 Wordfence
8.8 High Pixabay Images Plugin pixabay-images Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 3.4 CVE-2025-4413 Wordfence
7.1 High eForm - WordPress Form Builder Plugin wp-fsqm-pro Cross-Site Scripting WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) No login needed ≤ 4.19.1 Fixed in 4.19.1 CVE-2025-48333 Patchstack
7.5 High Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Plugin aeroscroll-gallery Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed ≤ 1.0.13 CVE-2025-49451 Patchstack
8.1 High CozyStay Theme cozystay Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2025-49508 Patchstack
7.6 High WP Employee Attendance System Plugin wp-employee-attendance-system SQL Injection ≤ 3.5 CVE-2025-28972 Patchstack
8.1 High DSK Plugin dsk Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-24761 Patchstack
8.1 High Simen Plugin snssimen Local File Inclusion No login needed ≤ 4.6 CVE-2025-29002 Patchstack
8.1 High Evon Plugin snsevon Local File Inclusion No login needed ≤ 3.4 CVE-2025-28991 Patchstack
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
7.1 High Elite Video Player Plugin elite-video-player Cross-Site Scripting No login needed ≤ 10.0.5 CVE-2025-30988 Patchstack
7.5 High WPGYM Plugin gym-management Local File Inclusion ≤ 65.0 CVE-2025-32549 Patchstack
8.5 High Rankie Plugin valvepress-rankie SQL Injection ≤ 1.8.2 Fixed in 1.8.2 CVE-2025-39486 Patchstack
7.1 High Nasa Core Plugin nasa-core Cross-Site Scripting No login needed ≤ 6.4.4 Fixed in 6.4.4 CVE-2025-39508 Patchstack
7.5 High School Management Plugin school-management Local File Inclusion ≤ 93.0.0 CVE-2025-47572 Patchstack
8.5 High Woocommerce Partial Shipment Plugin wc-partial-shipment SQL Injection ≤ 3.2 Fixed in 3.3 CVE-2025-48118 Patchstack
7.1 High Track, Analyze & Optimize by WP Tao Plugin wp-tao Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2025-48145 Patchstack
8.1 High Fana Plugin fana Local File Inclusion No login needed ≤ 1.1.28 Fixed in 1.1.29 CVE-2025-49251 Patchstack
8.1 High Lasa Plugin lasa Local File Inclusion No login needed ≤ 1.1 Fixed in 1.1.1 CVE-2025-49253 Patchstack
8.1 High Besa Plugin besa Local File Inclusion No login needed ≤ 2.3.8 Fixed in 2.3.10 CVE-2025-49252 Patchstack
8.1 High Ruza Plugin ruza Local File Inclusion No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49255 Patchstack
8.1 High Nika Plugin nika Local File Inclusion No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-49254 Patchstack
8.1 High Zota Plugin zota Local File Inclusion No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-49257 Patchstack
8.1 High Sapa Plugin sapa Local File Inclusion No login needed ≤ 1.1.14 Fixed in 1.1.15 CVE-2025-49256 Patchstack
8.1 High Hara Plugin hara Local File Inclusion No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-49259 Patchstack
8.1 High Maia Plugin maia Local File Inclusion No login needed ≤ 1.1.15 Fixed in 1.1.16 CVE-2025-49258 Patchstack
8.1 High Diza Theme diza Local File Inclusion No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-49261 Patchstack
8.1 High Aora Theme aora Local File Inclusion No login needed ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-49260 Patchstack
7.1 High Echo RSS Feed Post Generator Plugin rss-feed-post-generator-echo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8.1 Fixed in 5.4.9 CVE-2025-49312 Patchstack
7.1 High Ultimate Reviews Plugin ultimate-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.14 Fixed in 3.2.15 CVE-2025-49266 Patchstack
7.1 High WP2LEADS Plugin wp2leads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-49316 Patchstack
7.6 High Slim SEO Plugin slim-seo SQL Injection ≤ 4.5.4 Fixed in 4.5.5 CVE-2025-49854 Patchstack
7.2 High eCommerce Product Catalog Plugin ecommerce-product-catalog PHP Object Injection ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-49331 Patchstack
8.6 High Litho Plugin litho Arbitrary File Deletion No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-49879 Patchstack
8.6 High FW Gallery Plugin fw-gallery Arbitrary File Deletion No login needed ≤ 8.0.0 CVE-2025-49415 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only