WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 82 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Scripting No login needed ≤ 1.27.14 Fixed in 1.27.15 CVE-2026-100510 Patchstack
7.5 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters No login needed ≤ 3.0.1 CVE-2026-89406 Wordfence
8.1 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter ≤ 3.0.2 CVE-2026-92713 Wordfence
8.8 High The Grid Plugin the-grid Privilege Escalation ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-28191 Patchstack
7.5 High Total Upkeep Plugin boldgrid-backup Information Disclosure Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret No login needed < 1.17.3 Fixed in 1.17.3 CVE-2026-16253 WPScan
8.2 High Total Upkeep Plugin boldgrid-backup Broken Access Control No login needed ≤ 1.17.2 Fixed in 1.17.3 CVE-2026-66708 Patchstack
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Privilege Escalation Unauthenticated Privilege Escalation via Unrestricted Group ID No login needed < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-12687 WPScan
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Authentication Bypass Broken Authentication No login needed ≤ 5.9.9.6 Fixed in 5.9.9.7 CVE-2026-57697 Patchstack
8.8 High WP Grid Builder Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter ≤ 2.3.3 CVE-2026-13756 Wordfence
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
7.5 High JetEngine Plugin jet-engine SQL Injection Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint No login needed ≤ 3.8.10.1 CVE-2026-12360 Wordfence
7.2 High Modula Image Gallery Plugin modula-best-grid-gallery PHP Object Injection ≤ 2.14.18 Fixed in 2.14.19 CVE-2026-39481 Patchstack
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining ≤ 5.9.8.4 CVE-2026-4609 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
7.5 High Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Local File Inclusion ≤ <= 3.5.1 Fixed in 3.5.2 CVE-2026-32537 Patchstack
7.1 High The Grid Plugin the-grid Broken Access Control ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24369 Patchstack
7.5 High JetEngine Plugin jet-engine SQL Injection Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter No login needed ≤ 3.8.6.1 CVE-2026-4662 Wordfence
8.1 High Gridiron Theme gridiron Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28012 Patchstack
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
7.1 High Content Grid Slider Plugin content-grid-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-68879 Patchstack
7.5 High Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin ultimate-post Broken Access Control PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 5.0.3 CVE-2025-12980 Wordfence
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence
7.2 High Modula Plugin modula-best-grid-gallery Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion 2.13.1 – 2.13.2 CVE-2025-13645 Wordfence
7.1 High Grid Plus Plugin grid-plus Cross-Site Scripting No login needed ≤ 3.3 CVE-2025-53352 Patchstack
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.9.5.7 Fixed in 5.9.5.8 CVE-2025-4957 Patchstack
7.1 High Grid Plugin grid Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-58657 Patchstack
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid PHP Object Injection ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-54007 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.3 Fixed in 5.9.5.4 CVE-2025-49033 Patchstack
7.1 High CSS3 Compare Pricing Tables Plugin css3_web_pricing_tables_grids Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.6 Fixed in 11.7 CVE-2025-47554 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49876 Patchstack
7.6 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid SQL Injection YaySMTP plugin <= 1.5 - SQL Injection ≤ 1.5 Fixed in 1.5.1 CVE-2025-48301 Patchstack
7.5 High Total Upkeep by BoldGrid Plugin boldgrid-backup Information Disclosure Unauthenticated Backup Download No login needed ≤ 1.14.9 CVE-2020-36848 Wordfence
7.5 High Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Plugin aeroscroll-gallery Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed ≤ 1.0.13 CVE-2025-49451 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.0 Fixed in 5.9.5.1 CVE-2025-47478 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.4.8 Fixed in 5.9.4.9 CVE-2025-39586 Patchstack
7.1 High wordpress related Posts with thumbnails Plugin related-posts-list-grid-and-slider-all-in-one Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0.1 CVE-2025-31569 Patchstack
7.5 High The Post Grid Plugin the-post-grid Local File Inclusion ≤ 7.7.17 Fixed in 7.7.18 CVE-2025-30814 Patchstack
7.2 High Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Remote Code Execution WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection ≤ 1.16.10 CVE-2025-2257 Wordfence
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities PHP Object Injection User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection ≤ 5.9.4.5 CVE-2025-0724 Wordfence
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities PHP Object Injection ≤ 5.9.4.3 Fixed in 5.9.4.4 CVE-2025-26999 Patchstack
7.2 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid Cross-Site Scripting YaySMTP <= 1.4 - Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed ≤ 1.4 CVE-2025-0918 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
7.1 High Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-23634 Patchstack
7.1 High CtyGrid Hyp3rL0cal Search Plugin hyp3rl0cal-city-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1.1 CVE-2025-23695 Patchstack
7.1 High LocalGrid Plugin localgrid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23678 Patchstack
8.8 High Modula Image Gallery Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.11.10 CVE-2024-12853 Wordfence
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only