WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,751–4,800 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 96 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks No login needed ≤ 1.3.8.9 CVE-2025-3515 Wordfence
7.2 High Wise Chat Plugin wise-chat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header No login needed ≤ 3.3.4 CVE-2025-3774 Wordfence
8.1 High Zagg - Electronics & Accessories WooCommerce Theme Local File Inclusion Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.1 CVE-2025-4200 Wordfence
7.2 High AutomatorWP Plugin automatorwp SQL Injection Authenticated (Administrator+) SQL Injection via field_conditions ≤ 5.2.5 CVE-2025-5487 Wordfence
7.2 High File Manager Pro – Filester Plugin filester Arbitrary File Upload Filester <= 1.8.8 - Authenticated (Administrator+) Arbitrary File Upload ≤ 1.8.8 CVE-2025-3234 Wordfence
7.5 High WP Travel Engine Plugin wp-travel-engine Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 6.5.1 CVE-2025-5282 Wordfence
8.8 High Workreap Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media' ≤ 3.3.2 CVE-2025-5012 Wordfence
7.2 High Xagio SEO Plugin xagio-seo Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'HTTP_REFERER' No login needed ≤ 7.1.0.16 CVE-2025-3302 Wordfence
8.8 High CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Privilege Escalation All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation ≤ 1.1.23 CVE-2025-4315 Wordfence
8.8 High Automatic Plugin - AI content generator and auto poster Plugin Arbitrary File Upload AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File Upload ≤ 3.115.0 CVE-2025-5395 Wordfence
7.2 High WP-DownloadManager Plugin wp-downloadmanager Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion ≤ 1.68.10 CVE-2025-4799 Wordfence
8.1 High TinySalt Theme tinysalt Local File Inclusion No login needed ≤ 3.10.0 Fixed in 3.10.0 CVE-2025-49454 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
8.8 High Axle Demo Importer Plugin Arbitrary File Upload Author+ Arbitrary File Upload ≤ 1.0.3 CVE-2025-4954 WPScan
7.5 High Likes and Dislikes Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.0 CVE-2025-4840 WPScan
8.8 High RH - Real Estate Theme Privilege Escalation Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 4.4.0 CVE-2025-4601 Wordfence
8.1 High Fitrush Theme bw-fitrush Local File Inclusion No login needed ≤ 1.3.4 CVE-2023-26005 Patchstack
8.1 High BodyCenter - Gym, Fitness WooCommerce Theme bodycenter Local File Inclusion Gym, Fitness WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2023-25999 Patchstack
8.1 High One-Login Plugin one-login Privilege Escalation No login needed ≤ 1.4 CVE-2025-23974 Patchstack
8.1 High CraftXtore Plugin bw-craftxtore Local File Inclusion No login needed ≤ 1.7 CVE-2025-24770 Patchstack
8.1 High Nitan Plugin snsnitan Local File Inclusion No login needed ≤ 2.9 CVE-2025-24768 Patchstack
8.1 High Lab Plugin lab Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-26592 Patchstack
8.1 High Petito Plugin bw-petito Local File Inclusion No login needed ≤ 1.6.6 Fixed in 1.6.6 CVE-2025-27362 Patchstack
8.1 High Avaz Plugin snsavaz Local File Inclusion No login needed ≤ 2.8 CVE-2025-28944 Patchstack
8.1 High GiftXtore Plugin bw-giftxtore Local File Inclusion No login needed ≤ 1.7.7 Fixed in 1.7.7 CVE-2025-28888 Patchstack
8.1 High Valen - Sport, Fashion WooCommerce Plugin valen Local File Inclusion Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2025-28945 Patchstack
8.8 High Password Policy Manager Plugin password-policy-manager Privilege Escalation Account Takeover ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-31019 Patchstack
8.1 High SNS Anton Plugin snsanton Local File Inclusion No login needed ≤ 4.1 CVE-2025-28992 Patchstack
7.5 High elfsight Contact Form widget Plugin elfsight-contact-form Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.1 CVE-2025-31045 Patchstack
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
7.1 High Universal Video Player Plugin elementor_widget_universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-31057 Patchstack
7.1 High Revolution Video Player Plugin revolution_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.2 CVE-2025-31058 Patchstack
7.1 High Wishlist Plugin wishlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-31061 Patchstack
7.1 High Sticky Radio Player Plugin lbg-audio5-html5-shoutcast_sticky Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4 CVE-2025-31426 Patchstack
7.5 High CLEVER Plugin lbg-audio11-html5-shoutcast_history Path Traversal Arbitrary File Download No login needed ≤ 2.6 CVE-2025-31635 Patchstack
7.1 High Spare Theme spare Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-31638 Patchstack
7.1 High Universal Video Player Plugin universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.3 CVE-2025-31917 Patchstack
8.5 High WP Guppy Plugin wp-guppy SQL Injection ≤ 4.3.3 CVE-2025-31920 Patchstack
7.1 High SHOUT Plugin lbg-audio8-html5-radio_ads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.3 CVE-2025-31925 Patchstack
7.1 High FlatNews Theme flatnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 6.2 CVE-2025-32305 Patchstack
7.6 High Team Builder Plugin a-team-showcase Broken Access Control ≤ 1.5.7 CVE-2025-32308 Patchstack
8.1 High Seofy Core Plugin seofy-core Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.11 CVE-2025-39473 Patchstack
8.1 High Krowd Theme krowd Local File Inclusion No login needed ≤ 1.5.0 Fixed in 1.5.0 CVE-2025-32595 Patchstack
8.1 High Arlo Plugin arlo Local File Inclusion No login needed ≤ 6.0.3 CVE-2025-39475 Patchstack
7.5 High Revo Plugin revo Local File Inclusion No login needed ≤ 4.0.26 CVE-2025-39476 Patchstack
7.1 High WP Email Delivery Plugin wp-email-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.20.11.23 CVE-2025-39539 Patchstack
7.1 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.23 Fixed in 1.22.24 CVE-2025-47477 Patchstack
7.1 High Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-47463 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47487 Patchstack
8.8 High MapSVG Plugin mapsvg Privilege Escalation ≤ 8.6.13 Fixed in 8.6.13 CVE-2025-47561 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only