WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–31 of 31 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WP Directory Kit Plugin wpdirectorykit Cross-Site Scripting Listing Admin+ Stored XSS via Category and Location Title and Icon Fields < 1.5.8 Fixed in 1.5.8 CVE-2026-16591 WPScan
7.1 High Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Reflected XSS via Pin It Share Handler No login needed < 3.0.1 Fixed in 3.0.1 CVE-2026-19723 WPScan
7.1 High Social Media & Share Icons Plugin ultimate-social-media-icons Cross-Site Scripting No login needed ≤ 2.9.9 Fixed in 3.0.0 CVE-2026-66623 Patchstack
7.5 High CubeWP Framework Plugin cubewp-framework Path Traversal Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter No login needed ≤ 1.1.30 CVE-2026-13339 Wordfence
8.5 High CWS SVGicons Plugin cws-svgicons SQL Injection ≤ 1.5.5 CVE-2026-57787 Patchstack
7.1 High Favicon Rotator Plugin favicon-rotator Cross-Site Scripting No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2026-42649 Patchstack
7.1 High Favicon Plugin favicon-by-realfavicongenerator Cross-Site Scripting No login needed ≤ 1.3.46 Fixed in 1.3.47 CVE-2026-42754 Patchstack
8.8 High Betheme Theme Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload ≤ 28.4 CVE-2026-6261 Wordfence
8.8 High Apicona Theme apicona PHP Object Injection ≤ 24.1.0 CVE-2026-25400 Patchstack
8.3 High MimeTypes Link Icons Plugin mimetypes-link-icons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Crafted Links in Post Content No login needed ≤ 3.2.20 CVE-2026-1313 Wordfence
8.1 High Muzicon Theme muzicon Local File Inclusion No login needed ≤ 1.9.0 CVE-2026-28107 Patchstack
7.1 High iContact for Gravity Forms Plugin gravity-forms-icontact Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-68863 Patchstack
7.1 High Doliconnect Plugin doliconnect Cross-Site Scripting No login needed ≤ 9.3.2 Fixed in 9.4.2 CVE-2025-53574 Patchstack
7.1 High Doliconnect Plugin doliconnect Cross-Site Request Forgery No login needed ≤ 9.5.7 Fixed in 9.6.2 CVE-2025-58690 Patchstack
7.1 High Personal Favicon Plugin personal-favicon Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28964 Patchstack
8.1 High eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Upload Unauthenticated Arbitrary File Upload via set_file() No login needed ≤ 1.2.5 CVE-2025-4336 Wordfence
7.1 High File Icons Plugin file-icons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-27288 Patchstack
7.1 High Hamburger Icon Menu Lite Plugin hamburger-icon-menu-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-32548 Patchstack
7.1 High WP_Identicon Plugin wp-identicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31468 Patchstack
7.1 High Extra Options – Favicons Plugin extra-options-favicons Cross-Site Request Forgery Favicons plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-23508 Patchstack
7.1 High Favicon My Blog Plugin favicon-my-blog Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53722 Patchstack
7.1 High Encyclopedia / Glossary / Wiki Plugin encyclopedia-lexicon-glossary-wiki-dictionary Cross-Site Scripting No login needed ≤ 1.7.60 Fixed in 1.7.61 CVE-2024-49320 Patchstack
8.1 High Favicon Generator Plugin Arbitrary File Upload Arbitrary File Upload via CSRF < 2.1 Fixed in 2.1 CVE-2024-7863 WPScan
7.2 High Adicon Server Plugin adicon-server-16x16 SQL Injection Admin+ SQL Injection ≤ 1.2 CVE-2024-7766 WPScan
8.1 High MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles Plugin maxi-blocks Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.9.2 CVE-2024-6885 Wordfence
8.8 High Attachment File Icons (AF Icons) Plugin attachment-file-icons Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.3 CVE-2024-6309 Wordfence
7.1 High Easy Set Favicon Plugin easy-set-favicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-33645 Patchstack
7.7 High JVM rich text icons Plugin jvm-rich-text-icons Arbitrary File Deletion ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-51418 Patchstack
7.1 High Favicon Rotator Plugin favicon-rotator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-28001 Patchstack
7.1 High WooThumbs for WooCommerce by Iconic Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-29116 Patchstack
7.2 High Icons Font Loader Plugin icons-font-loader Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-24714 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only