WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–20 of 20 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.29 Fixed in 1.4.30 CVE-2026-57712 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
7.5 High Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Local File Inclusion ≤ <= 3.5.1 Fixed in 3.5.2 CVE-2026-32537 Patchstack
7.1 High DesignThemes Portfolio Plugin designthemes-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2026-27385 Patchstack
8.1 High Portfolio Builder Plugin swp-portfolio Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69375 Patchstack
8.5 High Ultra Portfolio Plugin ultra-portfolio SQL Injection ≤ 6.7 CVE-2025-69180 Patchstack
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
7.1 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance Cross-Site Request Forgery No login needed ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-59137 Patchstack
7.1 High Themify Portfolio Post Plugin themify-portfolio-post Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-67533 Patchstack
8.1 High Premium Portfolio Features for Phlox Plugin auxin-portfolio Local File Inclusion Unauthenticated Local File Inclusion via args[extra_template_path] No login needed ≤ 2.3.10 CVE-2025-12497 Wordfence
7.2 High Responsive Filterable Portfolio Plugin Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.24 CVE-2025-10049 Wordfence
7.1 High Ultra Portfolio Plugin ultra-portfolio Cross-Site Scripting WordPress Plugin <= 6.7 - Cross Site Scripting (XSS) No login needed ≤ 6.7 CVE-2025-49420 Patchstack
8.5 High Cube Portfolio Plugin cubeportfolio SQL Injection ≤ 1.16.8 CVE-2025-52823 Patchstack
7.5 High CWW Portfolio Plugin cww-portfolio Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-39359 Patchstack
7.6 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-32124 Patchstack
8.5 High Behance Portfolio Manager Plugin portfolio-manager-powered-by-behance SQL Injection ≤ 1.7.5 Fixed in 1.8.0 CVE-2025-31526 Patchstack
7.1 High DPortfolio Plugin dportfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-24534 Patchstack
7.1 High HM Portfolio Plugin hm-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-23522 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
8.6 High Phlox Portfolio Plugin auxin-portfolio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-38399 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only