WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 4,851–4,900 of 9,029 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | Ultimate WP Mail | Privilege Escalation Account Takeover via Email Log Leak |
≤ 1.3.5 Fixed in 1.3.6 |
CVE-2025-49288 |
Patchstack | |
| 7.6 High | WC Vendors Marketplace | SQL Injection |
≤ 2.5.6 Fixed in 2.5.7 |
CVE-2025-49263 |
Patchstack | |
| 7.6 High | Sina Extension for Elementor | Cross-Site Scripting |
≤ 3.6.1 Fixed in 3.7.0 |
CVE-2025-49262 |
Patchstack | |
| 7.4 High | POEditor | Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed |
≤ 0.9.10 Fixed in 0.9.11 |
CVE-2025-49237 |
Patchstack | |
| 7.1 High | Real Time Validation for Gravity Forms | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.7.0 |
CVE-2025-48329 |
Patchstack | |
| 8.8 High | WP Posts Carousel | PHP Object Injection |
≤ 1.3.12 Fixed in 1.3.13 |
CVE-2025-39358 |
Patchstack | |
| 8.5 High | Photography | PHP Object Injection |
≤ 7.5.2 |
CVE-2025-47584 |
Patchstack | |
| 7.1 High | Hive Support | Broken Access Control Authenticated (Subscriber+) Missing Authorization via hs_update_ai_chat_settings and hive_lite_support_get_all_binbox |
≤ 1.2.5 |
CVE-2025-5018 |
Wordfence | |
| 8.8 High | Short URL | SQL Injection Subscriber+ SQLi |
≤ 1.6.8 |
CVE-2023-2921 |
WPScan | |
| 8.8 High | HyperComments | Broken Access Control Unauthenticated (Subscriber+) Arbitrary Options Update |
≤ 1.2.2 |
CVE-2025-5701 |
Wordfence | |
| 8.1 High | WP User Frontend Pro | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 4.1.3 |
CVE-2025-3055 |
Wordfence | |
| 8.8 High | WP User Frontend Pro | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 4.1.3 |
CVE-2025-3054 |
Wordfence | |
| 8.8 High | Sunshine Photo Cart | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
≤ 3.4.11 |
CVE-2025-5482 |
Wordfence | |
| 7.2 High | Shared Files | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via sanitize_file Function No login needed |
≤ 1.7.48 |
CVE-2025-4392 |
Wordfence | |
| 7.2 High | wpForo + wpForo Advanced Attachments | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 3.1.3 |
CVE-2025-4224 |
Wordfence | |
| 7.2 High | Newsletters | Local File Inclusion Authenticated (Administrator+) Local File Inclusion |
≤ 4.9.9.9 |
CVE-2025-4857 |
Wordfence | |
| 8.8 High | Offsprout Page Builder | Privilege Escalation Authenticated (Contributor+) Privilege Escalation via permission_callback Function |
2.2.1 – 2.15.2 |
CVE-2025-4672 |
Wordfence | |
| 8.8 High | WP-GeoMeta | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via wp_ajax_wpgm_start_geojson_import Function |
0.3.4 – 0.3.5 |
CVE-2025-4103 |
Wordfence | |
| 7.5 High | WooCommerce Orders & Customers Exporter | Information Disclosure Sensitive Data Exposure No login needed |
≤ 5.0 |
CVE-2025-48331 |
Patchstack | |
| 8.8 High | Browse As | Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Cookie |
≤ 0.2 |
CVE-2025-5190 |
Wordfence | |
| 7.5 High | Likes and Dislikes | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.0.0 |
CVE-2025-5287 |
Wordfence | |
| 8.8 High | MasterStudy LMS Pro | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 4.7.0 |
CVE-2025-4800 |
Wordfence | |
| 8.8 High | Property | Broken Access Control Missing Authorization to Authenticated (Author+) Privilege Escalation via property_package_user_role Metadata in PayPal Registration |
1.0.5 – 1.0.6 |
CVE-2025-5117 |
Wordfence | |
| 8.1 High | eMagicOne Store Manager for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload via set_file() No login needed |
≤ 1.2.5 |
CVE-2025-4336 |
Wordfence | |
| 7.7 High | KBx Pro Ultimate | Arbitrary File Deletion |
≤ 8.0.5 Fixed in 8.0.5 |
CVE-2025-31053 |
Patchstack | |
| 8.1 High | Vizeon - Business Consulting | Local File Inclusion No login needed |
≤ 1.2.1 Fixed in 1.2.1 |
CVE-2025-31064 |
Patchstack | |
| 8.1 High | Capie | Local File Inclusion No login needed |
≤ 1.0.40 Fixed in 1.0.53.1 |
CVE-2025-31060 |
Patchstack | |
| 8.1 High | La Boom | Local File Inclusion No login needed |
≤ 2.7 |
CVE-2025-31632 |
Patchstack | |
| 8.1 High | Enzio - Responsive Business | Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed |
≤ 1.2.6 Fixed in 1.2.6 |
CVE-2025-31912 |
Patchstack | |
| 7.1 High | WP Post Modules for Elementor | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.0 |
CVE-2025-31636 |
Patchstack | |
| 8.1 High | Kiamo - Responsive Business Service | Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed |
≤ 1.3.3 |
CVE-2025-31633 |
Patchstack | |
| 8.1 High | Ogami | Local File Inclusion No login needed |
≤ 1.53 Fixed in 1.61.1 |
CVE-2025-31913 |
Patchstack | |
| 8.8 High | Crafts & Arts | PHP Object Injection |
≤ 2.5 |
CVE-2025-31924 |
Patchstack | |
| 8.8 High | Pet World | PHP Object Injection |
≤ 2.8 |
CVE-2025-32284 |
Patchstack | |
| 8.1 High | Butcher | Local File Inclusion No login needed |
≤ 2.40 |
CVE-2025-32286 |
Patchstack | |
| 7.1 High | Butcher | Cross-Site Scripting No login needed |
≤ 2.54 Fixed in 2.54 |
CVE-2025-32285 |
Patchstack | |
| 8.1 High | Yozi | Local File Inclusion No login needed |
≤ 2.0.63 Fixed in 2.0.66.1 |
CVE-2025-32289 |
Patchstack | |
| 8.1 High | Oxpitan | Local File Inclusion No login needed |
≤ 1.3.5 Fixed in 1.3.6 |
CVE-2025-32294 |
Patchstack | |
| 8.8 High | Finance Consultant | PHP Object Injection |
≤ 2.8 |
CVE-2025-32293 |
Patchstack | |
| 8.1 High | Healsoul | Local File Inclusion No login needed |
≤ 2.2.3 Fixed in 2.2.4 |
CVE-2025-32309 |
Patchstack | |
| 8.1 High | Winnex | Local File Inclusion No login needed |
≤ 1.3.2 |
CVE-2025-32302 |
Patchstack | |
| 8.1 High | Wilmër | Local File Inclusion No login needed |
≤ 3.4.2 Fixed in 3.4.2 |
CVE-2025-39494 |
Patchstack | |
| 8.1 High | Backpack Traveler | Local File Inclusion No login needed |
≤ 2.10.2 Fixed in 2.10.3 |
CVE-2025-39490 |
Patchstack | |
| 7.1 High | Goodlayers Hostel | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.1.2 |
CVE-2025-39502 |
Patchstack | |
| 7.1 High | Goodlayers Hotel | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.1.4 |
CVE-2025-39505 |
Patchstack | |
| 8.2 High | JobHunt Job Alerts | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 3.6 |
CVE-2025-39536 |
Patchstack | |
| 8.1 High | Nasa Core | Local File Inclusion No login needed |
≤ 6.3.2 |
CVE-2025-39506 |
Patchstack | |
| 7.1 High | kStats Reloaded | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.7.4 |
CVE-2025-46440 |
Patchstack | |
| 7.1 High | Tayori Form | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.9 |
CVE-2025-46437 |
Patchstack | |
| 7.1 High | Libro de Reclamaciones | Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-46446 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.