WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 79 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.29 Fixed in 1.4.30 CVE-2026-57712 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details ≤ 13.4.1 CVE-2025-14042 Wordfence
6.4 Medium Filterable Portfolio Gallery Plugin fg-gallery Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS 1.0 CVE-2021-47929 VulnCheck
5.4 Medium Grand Portfolio Theme grandportfolio Cross-Site Request Forgery No login needed ≤ 3.3 CVE-2026-39634 Patchstack
7.5 High Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Local File Inclusion ≤ <= 3.5.1 Fixed in 3.5.2 CVE-2026-32537 Patchstack
5.3 Medium VW Portfolio Plugin vw-portfolio Broken Access Control No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-32437 Patchstack
5.3 Medium Perfect Portfolio Plugin perfect-portfolio Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32345 Patchstack
7.1 High DesignThemes Portfolio Plugin designthemes-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2026-27385 Patchstack
8.1 High Portfolio Builder Plugin swp-portfolio Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69375 Patchstack
8.5 High Ultra Portfolio Plugin ultra-portfolio SQL Injection ≤ 6.7 CVE-2025-69180 Patchstack
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
5.9 Medium Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Scripting ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-59135 Patchstack
5.3 Medium GS Portfolio for Envato Plugin gs-envato-portfolio Broken Access Control No login needed ≤ 1.4.2 CVE-2025-62755 Patchstack
5.4 Medium Portfolio Gallery Plugin gallery-portfolio Broken Access Control ≤ 1.4.8 CVE-2025-62098 Patchstack
7.1 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Request Forgery No login needed ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-59137 Patchstack
5.3 Medium HomeFix Elementor Portfolio Plugin homefix-ele-portfolio Broken Access Control No login needed ≤ 1.0.1 CVE-2025-68981 Patchstack
5.3 Medium WeDesignTech Portfolio Plugin wedesigntech-portfolio Broken Access Control No login needed ≤ 1.0.2 CVE-2025-68980 Patchstack
6.5 Medium DesignThemes Portfolio Addon Plugin designthemes-portfolio-addon Cross-Site Scripting ≤ 1.5 CVE-2025-68977 Patchstack
6.5 Medium Salient Portfolio Theme salient-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-68078 Patchstack
7.1 High Themify Portfolio Post Plugin themify-portfolio-post Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-67533 Patchstack
4.3 Medium Portfolio and Projects Plugin portfolio-and-projects Information Disclosure Sensitive Data Exposure ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-67470 Patchstack
6.4 Medium Social Feed Gallery Portfolio Plugin social-feed-gallery-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.3 CVE-2025-13896 Wordfence
8.1 High Premium Portfolio Features for Phlox Plugin auxin-portfolio Local File Inclusion Unauthenticated Local File Inclusion via args[extra_template_path] No login needed ≤ 2.3.10 CVE-2025-12497 Wordfence
4.4 Medium Multi-language Responsive Portfolio Plugin bootstrap-multi-language-responsive-portfolio Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11753 Wordfence
6.5 Medium Penci Portfolio Plugin penci-portfolio Cross-Site Scripting ≤ 3.5 Fixed in 3.6 CVE-2025-59586 Patchstack
6.5 Medium Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Scripting ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-57913 Patchstack
6.5 Medium PowerFolio Plugin portfolio-elementor Cross-Site Scripting ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-57932 Patchstack
5.9 Medium Advance Portfolio Grid Plugin advance-portfolio-grid Cross-Site Scripting ≤ 1.07.6 Fixed in 1.07.7 CVE-2025-57982 Patchstack
5.9 Medium Portfolio Plugin portfolio Cross-Site Scripting ≤ 2.58 CVE-2025-58245 Patchstack
7.2 High Responsive Filterable Portfolio Plugin Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.24 CVE-2025-10049 Wordfence
7.1 High Ultra Portfolio Plugin ultra-portfolio Cross-Site Scripting WordPress Plugin <= 6.7 - Cross Site Scripting (XSS) No login needed ≤ 6.7 CVE-2025-49420 Patchstack
8.5 High Cube Portfolio Plugin cubeportfolio SQL Injection ≤ 1.16.8 CVE-2025-52823 Patchstack
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
6.4 Medium Portfolio for Elementor & Image Gallery | PowerFolio Plugin portfolio-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.2.0 CVE-2025-7046 Wordfence
4.3 Medium Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Broken Access Control ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-29010 Patchstack
7.5 High CWW Portfolio Plugin cww-portfolio Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-39359 Patchstack
7.6 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-32124 Patchstack
6.5 Medium Opal Portfolio Plugin opal-portfolios Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-31748 Patchstack
8.5 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-31526 Patchstack
5.5 Medium Modal Portfolio Plugin modal-portfolio Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.7.4.2 CVE-2024-13851 Wordfence
6.4 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-1757 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 3.0 CVE-2024-13115 WPScan
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.0 CVE-2024-13114 WPScan
7.1 High DPortfolio Plugin dportfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-24534 Patchstack
7.1 High HM Portfolio Plugin hm-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-23522 Patchstack
6.5 Medium Winning Portfolio Plugin winning-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23865 Patchstack
6.5 Medium Easy Portfolio Plugin easy-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-23796 Patchstack
4.3 Medium GS Insever Portfolio Plugin gs-instagram-portfolio Broken Access Control Missing Authorization to Authenticated (Subscriber+) CSS Injection ≤ 1.4.5 CVE-2024-12249 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only