WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 217 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2026-105876 Patchstack
6.5 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting ≤ 3.6.13 Fixed in 3.6.14 CVE-2026-104409 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute ≤ 5.7.2 CVE-2026-6170 Wordfence
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94680 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94671 Patchstack
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Magazine Grid Widget < 51.1.77 Fixed in 51.1.77 CVE-2026-84896 WPScan
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'delay' Shortcode Attribute ≤ 3.6.12 CVE-2026-4559 Wordfence
6.8 Medium Post Grid, Slider & Carousel Ultimate Plugin Cross-Site Scripting Contributor+ Stored XSS via Header Title Field < 1.8.1 Fixed in 1.8.1 CVE-2026-16260 WPScan
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group No login needed < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16290 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16289 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Arbitrary Notification Deletion via IDOR < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-16291 WPScan
6.1 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed < 51.1.76 Fixed in 51.1.76 CVE-2026-14841 WPScan
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12689 WPScan
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Price Manipulation Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery No login needed < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12688 WPScan
6.4 Medium Post Grid Gutenberg Blocks Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute ≤ 5.0.32 CVE-2026-15100 Wordfence
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting 2.14.25 – 2.14.30 Fixed in 2.14.31 CVE-2026-65475 Patchstack
6.4 Medium Grid/List View for WooCommerce Plugin gridlist-view-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute ≤ 3.0.9 CVE-2026-15794 Wordfence
4.3 Medium Memberships and User Profiles for WooCommerce Plugin ecommerce-user-profiles-by-profilegrid Broken Access Control Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation ≤ 3.4 CVE-2026-11359 Wordfence
6.4 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute ≤ 5.0.31 CVE-2026-13253 Wordfence
6.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content ≤ 5.9.9.2 CVE-2026-4610 Wordfence
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting ≤ 2.14.23 Fixed in 2.14.24 CVE-2026-42688 Patchstack
6.4 Medium Easy Image Collage Plugin easy-image-collage Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters ≤ 1.13.6 CVE-2026-9019 Wordfence
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.9.2 CVE-2026-49054 Patchstack
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
4.3 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-27424 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Group Settings Modification ≤ 5.9.8.4 CVE-2026-4607 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection Authenticated (Subscriber+) SQL Injection via 'rid' Parameter ≤ 5.9.8.4 CVE-2026-4608 Wordfence
6.4 Medium Netroics Blog Posts Grid Plugin netroics-blog-posts-grid Cross-Site Scripting WordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS 1.0 CVE-2022-50946 VulnCheck
5.3 Medium Total Upkeep Plugin boldgrid-backup Broken Access Control Missing Authorization to Unauthenticated Rollback Cancellation No login needed ≤ 1.17.1 CVE-2026-3143 Wordfence
5.3 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin Broken Access Control PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification No login needed ≤ 5.0.5 CVE-2026-0718 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting ≤ 5.9.8.1 Fixed in 5.9.8.2 CVE-2026-25417 Patchstack
6.5 Medium The Grid Plugin the-grid Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24370 Patchstack
5.3 Medium Filter & Grids Plugin ymc-smart-filter Broken Access Control No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-32397 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery Cross-Site Request Forgery to Group Membership Request Approval/Denial No login needed ≤ 5.9.8.2 CVE-2026-2494 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion ≤ 5.9.8.1 CVE-2026-2488 Wordfence
4.3 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control ≤ 3.6.10 Fixed in 3.6.11 CVE-2026-25375 Patchstack
4.3 Medium Modula Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing ≤ 2.13.6 CVE-2026-1254 Wordfence
6.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Cross-Site Scripting for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode ≤ 3.7.11 CVE-2026-0559 Wordfence
5.3 Medium WPZOOM Addons for Elementor – Starter Templates & Widgets Plugin wpzoom-elementor-addons Broken Access Control Starter Templates & Widgets <= 1.3.2 - Unauthenticated Protected Post Exposure via ajax_post_grid_load_more No login needed ≤ 1.3.2 CVE-2026-2295 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid ≤ 5.5.3 CVE-2025-13463 Wordfence
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification No login needed ≤ 5.9.7.2 CVE-2026-1271 Wordfence
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension ≤ 5.9.7.2 CVE-2025-13416 Wordfence
4.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control ≤ 2.13.6 Fixed in 2.13.7 CVE-2026-24939 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-24389 Patchstack
5.3 Medium The Grid Plugin the-grid Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24368 Patchstack
5.9 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting ≤ 2.13.4 Fixed in 2.13.5 CVE-2026-23976 Patchstack
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management ≤ 3.6.9 CVE-2025-15466 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only