CVE-2020-25213
WordPress Vulnerability Database
The most comprehensive open vulnerability database for WordPress plugins, themes, and server infrastructure.
16,106
plugins with known vulnerabilities
2,198
themes with known vulnerabilities
13,246
vulnerabilities without a fix
1,948
critical severity (score ≥ 9.0)

Official WordPress Plugin
WPVulnerability
Real-time vulnerability scanner for your WordPress dashboard. Monitors your core, plugins, themes, PHP, Apache, nginx, MariaDB, MySQL, ImageMagick, curl and more — all in one place.
Notable vulnerabilities — last 90 days
WordPress Huge-IT Video Gallery plugin <=2.0.4 - SQL Injection vulnerability
CVE-2017-9841
CVE-2017-9841
CVE-2020-11738
CVE-2019-9978
jQuery Manager for WordPress <= 1.10.4 & jQuery Migrate Helper <= 1.4.1- Running Vulnerable Dependency
CVE-2022-46839
CVE-2023-29384
CVE-2023-49815
WordPress Rencontre – Dating Site Plugin <= 3.10.1 is vulnerable to Arbitrary File Upload
WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to PHP Object Injection
Latest Plugin Vulnerabilities
View all →CVE-2026-5371
CVE-2026-1250
CVE-2025-15463
CVE-2026-42741
CVE-2026-45210
CVE-2026-45211
CVE-2026-42742
CVE-2026-45213
CVE-2026-45212
CVE-2026-45214
CVE-2026-45218
CVE-2026-45215
CVE-2026-25431
WordPress Essential Real Estate plugin <= 5.3.2 - Broken Access Control vulnerability
WordPress ConveyThis plugin <= 269.9 - Broken Access Control vulnerability
WordPress Essential Real Estate plugin <= 5.3.2 - Insecure Direct Object References (IDOR) vulnerability
WordPress Court Reservation plugin <= 1.10.13 - Cross Site Scripting (XSS) vulnerability
WordPress Directorist Booking plugin < 3.0.2 - SQL Injection vulnerability
CVE-2026-1934
CVE-2026-3604
Latest Theme Vulnerabilities
View all →CVE-2025-39485
CVE-2025-31912
CVE-2025-31633
WordPress Avante Theme < 3.0.5 is vulnerable to a medium priority Cross Site Scripting (XSS)
CVE-2025-47584
CVE-2025-32595
CVE-2025-27362
CVE-2025-28888
CVE-2025-32305
CVE-2025-24761
CVE-2025-28946
CVE-2025-39488
CVE-2025-52799
CVE-2025-52834
CVE-2025-52812
CVE-2025-52833
CVE-2025-52828
CVE-2025-32311
CVE-2024-43334
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion
Latest WordPress Core Vulnerabilities
View all →WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload