CVE-2020-25213
WordPress Vulnerability Database
The most comprehensive open vulnerability database for WordPress plugins, themes, and server infrastructure.
16,259
plugins with known vulnerabilities
2,267
themes with known vulnerabilities
13,530
vulnerabilities without a fix
2,002
critical severity (score ≥ 9.0)

Official WordPress Plugin
WPVulnerability
Real-time vulnerability scanner for your WordPress dashboard. Monitors your core, plugins, themes, PHP, Apache, nginx, MariaDB, MySQL, ImageMagick, curl and more — all in one place.
Notable vulnerabilities — last 90 days
WordPress Huge-IT Video Gallery plugin <=2.0.4 - SQL Injection vulnerability
CVE-2017-9841
CVE-2017-9841
CVE-2020-11738
CVE-2019-9978
jQuery Manager for WordPress <= 1.10.4 & jQuery Migrate Helper <= 1.4.1- Running Vulnerable Dependency
CVE-2022-46839
CVE-2023-29384
CVE-2023-49815
WordPress Rencontre – Dating Site Plugin <= 3.10.1 is vulnerable to Arbitrary File Upload
CVE-2024-25100
Latest Plugin Vulnerabilities
View all →WordPress CoDesigner plugin <= 4.29 - Cross Site Scripting (XSS) vulnerability
WPFunnels Pro <= 2.9.4 - Unauthenticated Stored Cross-Site Scripting
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution <= 2.1.7 - Missing Authorization
Visual Link Preview <= 2.4.1 - Authenticated (Subscriber+) Information Exposure
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more <= 4.5.2 - Unauthenticated Information Exposure
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.4 - Unauthenticated Information Exposure
Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation
Simple Shopping Cart <= 5.2.9 - Unauthenticated Insecure Direct Object Reference
Booknetic <= 4.8.5 - Missing Authorization
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 - Missing Authorization
Easy Invoice – Invoice Generator, PDF Quotes & Payments <= 2.1.19 - Unauthenticated Remote Code Execution
CVE-2026-9125
Backup and Staging by WP Time Capsule <= 1.22.25 - Missing Authorization
SlimStat Analytics < 5.4.0 - Unauthenticated PHP Object Injection
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions <= 8.4.1 - Missing Authorization
Support Board < 3.8.9 - Unauthenticated Privilege Escalation
WordPress Speed Optimizer Plugin < 7.7.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2026-3220
CVE-2026-49060
CVE-2026-46698
Latest Theme Vulnerabilities
View all →CVE-2026-3326
CVE-2026-8365
Enfold - Responsive Multi-Purpose Theme <= 7.1.4 - Reflected Cross-Site Scripting
CVE-2023-54352
CVE-2024-58349
WordPress Moderno Theme < 1.43 is vulnerable to a high priority PHP Object Injection
CVE-2019-25742
Nexio <= 1.10.0 - Unauthenticated Local File Inclusion
CopyPress <= 1.4.5 - Unauthenticated Local File Inclusion
Kelly Young <= 1.1.0 - Unauthenticated Local File Inclusion
Ingenioso <= 1.14.0 - Unauthenticated Local File Inclusion
Rosaleen <= 2.8 - Unauthenticated Local File Inclusion
Abelle <= 1.22 - Unauthenticated Local File Inclusion
Plumbing <= 1.6 - Unauthenticated PHP Object Injection
Snow Club <= 1.1 - Unauthenticated Local File Inclusion
SeaFood Company <= 1.4 - Unauthenticated PHP Object Injection
Printo <= 1.11 - Unauthenticated Local File Inclusion
Granola <= 1.13 - Unauthenticated Local File Inclusion
JobCareer <= 7.3 - Authenticated (Subscriber+) Arbitrary File Deletion
Spike <= 1.2 - Unauthenticated Local File Inclusion
Latest WordPress Core Vulnerabilities
View all →WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload