WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 1–37 of 37 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Branda Plugin branda-white-labeling Cross-Site Scripting No login needed ≤ 3.4.32 Fixed in 3.4.33 CVE-2026-102376 Patchstack
7.2 High Frontend Post Submission Manager Lite Plugin frontend-post-submission-manager-lite Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) No login needed ≤ 1.3.4 CVE-2026-96649 Wordfence
8.8 High Master Blocks Plugin ultimate-blocks-for-gutenberg Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed 1.4.1 – < 1.5.0 Fixed in 1.5.0 CVE-2026-88824 WPScan
7.2 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed ≤ 6.86 CVE-2026-77830 Wordfence
8.1 High Atarim Plugin atarim-visual-collaboration Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta ≤ 5.1.1 CVE-2026-19942 Wordfence
7.1 High SpaLab | Beauty Salon Theme spalab Cross-Site Scripting No login needed ≤ 6.7 CVE-2025-69154 Patchstack
8.1 High Atomlab Theme atomlab Local File Inclusion No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2026-39590 Patchstack
8.1 High Softlab Core Plugin softlab-core Local File Inclusion No login needed < 1.2.11 Fixed in 1.2.11 CVE-2026-34895 Patchstack
7.5 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2026-49056 Patchstack
7.5 High LabtechCO Theme labtechco Local File Inclusion ≤ 8.3 Fixed in 8.4 CVE-2026-39544 Patchstack
7.3 High Automated FedEx live/manual rates with shipping labels Plugin a2z-fedex-shipping Broken Access Control No login needed ≤ 5.1.9 CVE-2026-25456 Patchstack
7.2 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution ≤ 2.36 Fixed in 2.37 CVE-2026-32414 Patchstack
8.8 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter ≤ 2.36 CVE-2026-1929 Wordfence
8.1 High Blabber Theme blabber Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-22378 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60188 Patchstack
8.1 High Lab Plugin lab Local File Inclusion No login needed ≤ 1.0.0 CVE-2025-26592 Patchstack
8.1 High La Boom Theme laboom Local File Inclusion No login needed ≤ 2.7 CVE-2025-31632 Patchstack
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High CRUDLab Scroll to Top Plugin crudlab-scroll-to-top Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-22774 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
7.1 High LeadLab by wiredminds Plugin wiredminds-leadlab Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-31568 Patchstack
7.1 High Local Shipping Labels for WooCommerce Plugin local-shipping-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23903 Patchstack
7.1 High CRUDLab Like Box Plugin crudlab-facebook-like-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.9 CVE-2025-23814 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-26993 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.9 Fixed in 4.1.0 CVE-2025-22657 Patchstack
7.1 High DK White Label Plugin dk-white-label Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-24541 Patchstack
7.1 High Atarim Plugin atarim-visual-collaboration Cross-Site Scripting No login needed ≤ 4.0.8 Fixed in 4.0.9 CVE-2025-24570 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
7.1 High CRUDLab Google Plus Button Plugin crudlab-google-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2024-54399 Patchstack
7.1 High LabelGrid Tools Plugin label-grid-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.58 Fixed in 1.3.59 CVE-2024-54341 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
7.1 High FraudLabs Pro SMS Verification Plugin fraudlabs-pro-sms-verification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2024-51688 Patchstack
7.1 High White Label CMS Plugin white-label-cms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2024-43303 Patchstack
7.2 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.30 CVE-2024-2793 Wordfence
7.5 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Broken Access Control Atarim <= 3.22.6 - Hardcoded Credentials No login needed ≤ 3.22.6 CVE-2024-2038 Wordfence
7.2 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Privilege Escalation ≤ 4.2.1 Fixed in 4.3.0 CVE-2023-51546 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only