WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 69 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Simple Event Planner Plugin simple-event-planner PHP Object Injection ≤ 1.5.7 Fixed in 1.5.8 CVE-2026-97257 Patchstack
7.2 High Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 5.3.5 CVE-2026-92977 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter No login needed ≤ 4.4.1 CVE-2026-14989 Wordfence
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter No login needed ≤ 4.3.5 CVE-2026-13360 Wordfence
7.5 High Uncanny Automator Plugin uncanny-automator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints No login needed ≤ 7.3.2 CVE-2026-15025 Wordfence
7.6 High Uncanny Automator Plugin uncanny-automator SQL Injection ≤ 7.3.2 Fixed in 7.4.0 CVE-2026-65462 Patchstack
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token No login needed ≤ 7.3.1.4 CVE-2026-15008 Wordfence
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection No login needed ≤ 7.3.1.2 Fixed in 7.3.1.3 CVE-2026-56031 Patchstack
8.8 High AdRotate Banner Manager Plugin adrotate Remote Code Execution Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute ≤ 5.17.7 CVE-2026-12242 Wordfence
7.5 High easy-paypal-events-tickets Plugin easy-paypal-events-tickets Authentication Bypass Easy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code Scanning No login needed < 1.4.0 Fixed in 1.4.0 CVE-2026-32834 VulnCheck
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2026-25464 Patchstack
7.1 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator Cross-Site Scripting Banner Rotator plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28112 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist Cross-Site Scripting AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28110 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner Cross-Site Scripting AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28108 Patchstack
8.1 High Au Pair Agency - Babysitting & Nanny Theme au-pair-agency PHP Object Injection Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data No login needed ≤ 1.2.2 CVE-2026-27098 Patchstack
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
8.8 High Woocommerce Category Banner Management Plugin banner-management-for-woocommerce PHP Object Injection ≤ 2.5.1 CVE-2026-22354 Patchstack
7.5 High Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed ≤ 4.1.2 CVE-2025-11754 Wordfence
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
7.1 High Jannah Plugin jannah Cross-Site Scripting No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64207 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64205 Patchstack
7.2 High Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto Plugin codistoconnect Cross-Site Scripting Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-11727 Wordfence
7.2 High Telegram Bot & Channel Plugin telegram-bot Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Telegram Username No login needed ≤ 4.1 CVE-2025-13068 Wordfence
7.2 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Path Traversal ≤ 1.10.4 Fixed in 1.10.5 CVE-2025-58972 Patchstack
7.1 High Sello ChannelConnector Plugin sello-channelconnector Cross-Site Scripting No login needed ≤ 1.6.3 CVE-2025-52754 Patchstack
8.8 High Progress Planner Plugin progress-planner Privilege Escalation ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-48082 Patchstack
8.5 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator SQL Injection Banner Rotator Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60110 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner SQL Injection AllInOne - Banner with Thumbnails Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60108 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist SQL Injection AllInOne - Banner with Playlist Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60107 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Broken Access Control Broken Access Control to XSS No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-32589 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.5.1 Fixed in 7.5.1 CVE-2025-53334 Patchstack
7.5 High Neon Channel Product Customizer Free Plugin neon-channel-product-customizer-free Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-54679 Patchstack
7.2 High NinjaScanner – Virus & Malware scan Plugin ninjascanner Arbitrary File Deletion Virus & Malware scan <= 3.2.5 - Authenticated (Administrator+) Arbitrary File Deletion ≤ 3.2.5 CVE-2025-8213 Wordfence
8.1 High Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal Plugin wp-malware-removal Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.0 CVE-2025-6043 Wordfence
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
7.5 High Woo Product Feed For Marketing Channels Plugin woocommerce-to-google-merchant-center Broken Access Control No login needed ≤ 1.9.0 CVE-2025-31377 Patchstack
7.1 High WP-Planification Plugin wp-planification Cross-Site Request Forgery WP-Planning plugin <= 2.3.1 - CSRF to Stored XSS No login needed ≤ 2.3.1 CVE-2025-32484 Patchstack
7.1 High WP Map Route Planner Plugin wp-map-route-planner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-32621 Patchstack
8.8 High Uncanny Automator Plugin uncanny-automator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 6.3.0.2 CVE-2025-2075 Wordfence
7.1 High banner-manager Plugin banner-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 16.04.19 CVE-2025-30565 Patchstack
7.1 High Events Planner Plugin events-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.10 CVE-2025-26586 Patchstack
7.1 High CM Pop-Up banners Plugin cm-pop-up-banners Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-24694 Patchstack
7.1 High Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-23634 Patchstack
7.1 High Content Planner Plugin content-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23631 Patchstack
7.1 High WP-Announcements Plugin wp-announcements Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2025-23489 Patchstack
7.1 High Genki Announcement Plugin genki-announcement Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23900 Patchstack
7.1 High Annie Plugin annie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 CVE-2025-23884 Patchstack
7.5 High Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization to Authenticated (Contributor+) PHP Object Injection ≤ 1.3.5 CVE-2024-12627 Wordfence
7.1 High Upload Scanner Plugin upload-scanner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-56035 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only