WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–36 of 36 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Golo Framework Plugin golo-framework Local File Inclusion No login needed < 1.7.5 Fixed in 1.7.5 CVE-2026-28150 Patchstack
8.5 High CubeWP Plugin cubewp-framework SQL Injection ≤ 1.1.30 Fixed in 1.1.31 CVE-2026-28168 Patchstack
8.1 High CubeWP Framework Plugin cubewp-framework SQL Injection Subscriber+ SQL Injection via cubewp_remove_relation < 1.1.31 Fixed in 1.1.31 CVE-2026-17017 WPScan
7.5 High CubeWP Framework Plugin cubewp-framework Path Traversal Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter No login needed ≤ 1.1.30 CVE-2026-13339 Wordfence
8.8 High Redux Framework Plugin redux-framework Privilege Escalation Subscriber+ Privilege Escalation to Administrator < 4.5.13 Fixed in 4.5.13 CVE-2026-12525 WPScan
7.5 High Golo Framework Plugin golo-framework Local File Inclusion ≤ 1.7.3 CVE-2026-57794 Patchstack
7.1 High Felan Framework Plugin felan-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-22741 Patchstack
7.1 High Darna Framework Plugin darna-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9 CVE-2026-27088 Patchstack
7.1 High Wolverine Framework Plugin wolverine-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2026-27087 Patchstack
7.1 High Handmade Framework Plugin handmade-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9 CVE-2026-22520 Patchstack
7.5 High ModelTheme Framework Plugin modeltheme-framework Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.0 CVE-2025-69303 Patchstack
7.5 High Spirit Framework Plugin spirit-framework Local File Inclusion ≤ 1.2.13 CVE-2024-54263 Patchstack
7.5 High Handmade Framework Plugin handmade-framework Local File Inclusion ≤ 3.9 CVE-2026-22521 Patchstack
7.5 High REHub Framework Plugin rehub-framework Broken Access Control No login needed ≤ 19.9.5 Fixed in 19.9.9.6 CVE-2025-14358 Patchstack
7.5 High CubeWP Plugin cubewp-framework Broken Access Control No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2025-68036 Patchstack
8.1 High Frame Theme frame Local File Inclusion No login needed ≤ 2.4.0 CVE-2025-58899 Patchstack
7.5 High Spirit Framework Plugin spirit-framework Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 1.2.13 CVE-2025-10269 Wordfence
8.5 High Exertio Framework Plugin exertio-framework SQL Injection ≤ 1.3.3 CVE-2025-49402 Patchstack
7.1 High iFrame Block Plugin iframe-block Cross-Site Scripting No login needed ≤ 0.1.1 CVE-2025-49411 Patchstack
8.8 High CubeWP Plugin cubewp-framework Privilege Escalation ≤ 1.1.24 Fixed in 1.1.25 CVE-2025-54735 Patchstack
8.5 High iFrame Images Gallery Plugin wp-iframe-images-gallery SQL Injection ≤ 9.0 CVE-2025-30969 Patchstack
8.8 High CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Privilege Escalation All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation ≤ 1.1.23 CVE-2025-4315 Wordfence
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
8.8 High Smart Framework <= Multiple Plugins Theme Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.0.0, ≤ 5.1, ≤ 6.0.6, … CVE-2024-13418 Wordfence
8.6 High Fresh Framework Plugin fresh-framework Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.70.0 CVE-2025-26961 Patchstack
7.2 High AppPresser – Mobile App Framework Plugin apppresser Cross-Site Scripting Mobile App Framework <= 4.4.10 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.10 CVE-2025-1561 Wordfence
7.5 High CS Framework Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read No login needed ≤ 7.1 CVE-2024-12036 Wordfence
8.8 High CS Framework Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 7.0 CVE-2024-12035 Wordfence
8.1 High Exertio Framework Plugin Privilege Escalation Unauthenticated Arbitrary User Password Update No login needed ≤ 1.3.1 CVE-2024-13373 Wordfence
8.8 High Apus Framework Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in import_page_options ≤ 2.4 CVE-2024-12296 Wordfence
7.1 High LGPD Framework Plugin lgpd-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2024-52465 Patchstack
7.1 High Meta Box – WordPress Custom Fields Framework Plugin meta-box Broken Access Control ≤ 5.9.10 Fixed in 5.9.11 CVE-2024-43235 Patchstack
8.1 High AppPresser – Mobile App Framework Plugin apppresser Privilege Escalation Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 4.4.4 CVE-2024-9305 Wordfence
7.2 High Redux Framework Plugin redux-framework Arbitrary File Upload Unauthenticated JSON File Upload to Stored Cross-Site Scripting No login needed 4.4.12 – 4.4.17 CVE-2024-6828 Wordfence
8.8 High XootiX Framework <= Various Plugin Versions Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Update ≤ 2.6, ≤ 2.6.1, 2.5, … CVE-2024-5324 Wordfence
8.5 High REHub Framework Plugin SQL Injection < 19.6.2 Fixed in 19.6.2 CVE-2024-31234 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only