WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 286 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Gutenberg Blocks by Kadence Blocks | Cross-Site Scripting No login needed |
≤ 3.7.11.1 Fixed in 3.7.12 |
CVE-2026-103354 |
Patchstack | |
| 6.4 Medium | Gutenberg Essential Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute |
≤ 6.4.5 |
CVE-2026-96256 |
Wordfence | |
| 4.3 Medium | Spectra Legacy – Gutenberg Blocks | Information Disclosure Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure |
≤ 2.20.0 |
CVE-2026-16302 |
Wordfence | |
| 6.5 Medium | Premium Blocks – Gutenberg Blocks | Cross-Site Scripting Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) |
≤ 2.3.17 Fixed in 2.3.18 |
CVE-2026-94118 |
Patchstack | |
| 4.3 Medium | BlockSpare - Gutenberg Site Builder Blocks & Starter Sites | Broken Access Control Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation |
≤ 4.2.6 |
CVE-2026-1242 |
Wordfence | |
| 8.8 High | Master Blocks | Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed |
1.4.1 – < 1.5.0 Fixed in 1.5.0 |
CVE-2026-88824 |
WPScan | |
| 9.8 Critical | Post Grid and Gutenberg Blocks – ComboBlocks | Remote Code Execution ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection No login needed |
2.2.85 – 2.3.32 |
CVE-2024-11080 |
Wordfence | |
| 6.8 Medium | VikWidgetsLoader | Cross-Site Scripting Contributor+ Stored XSS via Gutenberg Block class_suffix |
1.11.0 – < 1.12.0 Fixed in 1.12.0 |
CVE-2026-84899 |
WPScan | |
| 7.1 High | Recipe Card Blocks for Gutenberg & Elementor | Cross-Site Scripting No login needed |
≤ 3.4.18 Fixed in 3.4.19 |
CVE-2026-73361 |
Patchstack | |
| 6.5 Medium | WPZOOM Forms – Contact Form Plugin for Gutenberg | Cross-Site Scripting Contact Form plugin for Gutenberg plugin <= 2.0.4 - Cross Site Scripting (XSS) |
≤ 2.0.4 |
CVE-2026-66639 |
Patchstack | |
| 8.8 High | Templately | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch |
≤ 3.7.1 |
CVE-2026-18438 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks by Kadence Blocks | Information Disclosure Sensitive Data Exposure |
≤ 3.7.8 Fixed in 3.7.8.1 |
CVE-2026-66696 |
Patchstack | |
| 3.5 Low | Spectra (Ultimate Addons for Gutenberg) | Content Injection Contributor+ Stored CSS Injection via Block Attributes |
< 2.20.0 Fixed in 2.20.0 |
CVE-2026-10827 |
WPScan | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-65433 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-59559 |
Patchstack | |
| 6.4 Medium | Post Grid Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute |
≤ 5.0.32 |
CVE-2026-15100 |
Wordfence | |
| 6.5 Medium | Ninja Forms | Broken Access Control Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors |
< 3.14.9 Fixed in 3.14.9 |
CVE-2026-65050 |
VulnCheck | |
| 6.4 Medium | Spectra Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block |
≤ 2.19.28 |
CVE-2026-12900 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP – Page Builder Features | Broken Access Control Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication |
≤ 3.5.32 |
CVE-2026-15286 |
Wordfence | |
| 6.4 Medium | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute |
≤ 5.0.31 |
CVE-2026-13253 |
Wordfence | |
| 6.4 Medium | Advanced iFrame | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute |
≤ 2026.1 |
CVE-2026-6742 |
Wordfence | |
| 6.4 Medium | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns | Cross-Site Scripting Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute |
≤ 6.1.4 |
CVE-2026-10833 |
Wordfence | |
| 9.3 Critical | WP Travel Gutenberg Blocks | SQL Injection No login needed |
≤ 3.9.4 Fixed in 3.9.5 |
CVE-2026-54808 |
Patchstack | |
| 7.2 High | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed |
≤ 6.1.3 |
CVE-2026-10586 |
Wordfence | |
| 8.8 High | Spectra Gutenberg Blocks | Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes |
≤ 2.19.25 |
CVE-2026-7465 |
Wordfence | |
| 5.4 Medium | ShopLentor - WooCommerce Builder for Elementor & Gutenberg | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute |
≤ 3.3.8 |
CVE-2026-6287 |
Wordfence | |
| 6.4 Medium | Gutenberg Essential Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes |
≤ 6.0.4 |
CVE-2026-4658 |
Wordfence | |
| 4.3 Medium | Spectra | Broken Access Control |
≤ 2.19.22 Fixed in 2.19.23 |
CVE-2026-42648 |
Patchstack | |
| 6.4 Medium | Timeline Blocks for Gutenberg | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute |
≤ 1.1.10 |
CVE-2026-6551 |
Wordfence | |
| 5.4 Medium | Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor | Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML |
≤ 3.5.5 |
CVE-2026-2951 |
Wordfence | |
| 6.4 Medium | Page Builder Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data |
≤ 3.1.16 |
CVE-2026-4801 |
Wordfence | |
| 5.3 Medium | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | Broken Access Control PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification No login needed |
≤ 5.0.5 |
CVE-2026-0718 |
Wordfence | |
| 4.3 Medium | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload |
≤ 3.6.3 |
CVE-2026-2826 |
Wordfence | |
| 6.4 Medium | WPFAQBlock– FAQ & Accordion Plugin For Gutenberg | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute |
≤ 1.1 |
CVE-2026-1093 |
Wordfence | |
| 7.1 High | Gutenberg Blocks | Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.8 |
CVE-2026-25438 |
Patchstack | |
| 6.4 Medium | Rise Blocks – A Complete Gutenberg Page Builder | Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes |
≤ 3.7 |
CVE-2026-1614 |
Wordfence | |
| 6.5 Medium | Cartify - WooCommerce Gutenberg | Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion |
≤ 1.3 |
CVE-2025-69385 |
Patchstack | |
| 6.4 Medium | Dealia | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block Attributes |
≤ 1.0.8 |
CVE-2026-2718 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Broken Access Control Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload |
≤ 3.6.1 |
CVE-2026-2633 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter |
≤ 3.6.1 |
CVE-2026-1857 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks by Kadence Blocks | Broken Access Control Missing Authorization |
≤ 3.5.32 |
CVE-2026-2608 |
Wordfence | |
| 5.3 Medium | Spectra | Broken Access Control No login needed |
≤ 2.19.17 Fixed in 2.19.18 |
CVE-2026-24982 |
Patchstack | |
| 5.3 Medium | Spectra Gutenberg Blocks | Information Disclosure Unauthenticated Information Disclosure in Sensitive Data No login needed |
≤ 2.19.17 |
CVE-2026-0950 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.14 |
CVE-2025-14283 |
Wordfence | |
| 5.9 Medium | Stackable | Cross-Site Scripting |
≤ 3.19.5 Fixed in 3.19.6 |
CVE-2025-47500 |
Patchstack | |
| 6.5 Medium | Gutenberg Thim Blocks | Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter |
≤ 1.0.1 |
CVE-2025-13725 |
Wordfence | |
| 5.3 Medium | LottieFiles – Lottie block for Gutenberg | Information Disclosure Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information Exposure No login needed |
≤ 3.0.0 |
CVE-2026-0717 |
Wordfence | |
| 5.4 Medium | aBlocks – WordPress Gutenberg Blocks | Broken Access Control WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification |
≤ 2.4.0 |
CVE-2025-12449 |
Wordfence | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.3.23 |
CVE-2025-68605 |
Patchstack | |
| 7.5 High | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | Broken Access Control PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 5.0.3 |
CVE-2025-12980 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.