WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 251 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.5.3 CVE-2026-15795 Wordfence
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
6.5 Medium Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object References (IDOR) ≤ 28.2 Fixed in 28.3 CVE-2026-96347 Patchstack
7.2 High Responsive Slider Gallery Plugin responsive-slider-gallery PHP Object Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-94122 Patchstack
9.1 Critical Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter No login needed ≤ 28.2 CVE-2026-93399 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data No login needed ≤ 28.2 CVE-2026-92799 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
4.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter ≤ 27.7 CVE-2026-12905 Wordfence
6.1 Medium Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Cross-Site Scripting Reflected Cross-Site Scripting via 'id' Parameter No login needed < 1.1.53 Fixed in 1.1.53 CVE-2026-18344 Wordfence
9.8 Critical Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … Plugin advanced-responsive-video-embedder Authentication Bypass Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter No login needed 10.8.7 CVE-2026-18072 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool SQL Injection Unauthenticated SQL Injection No login needed ≤ 27.5 CVE-2026-14516 Wordfence
5.9 Medium Tabs Plugin tabs-responsive Cross-Site Scripting ≤ 2.5 CVE-2026-65550 Patchstack
9.3 Critical Bookly Plugin bookly-responsive-appointment-booking-tool SQL Injection No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61949 Patchstack
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
5.3 Medium WP Support Plus Responsive Ticket System Plugin Broken Access Control Unauthenticated Support Ticket Access via Session Cookie Forgery No login needed ≤ 9.1.2 CVE-2026-11875 WPScan
8.6 High WP Support Plus Responsive Ticket System Plugin SQL Injection Unauthenticated SQL Injection via filter[elements] Array Keys No login needed ≤ 9.1.2 CVE-2026-11590 WPScan
8.8 High WP Support Plus Responsive Ticket System Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Upload No login needed ≤ 9.1.2 CVE-2026-11589 WPScan
7.1 High Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-56041 Patchstack
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Information Disclosure Sensitive Data Exposure No login needed ≤ 27.4 Fixed in 27.5 CVE-2026-42667 Patchstack
9.1 Critical Responsive Slider by MetaSlider Plugin ml-slider Remote Code Execution ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39465 Patchstack
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
6.4 Medium Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter ≤ 3.1.31 CVE-2026-9134 Wordfence
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack
6.4 Medium Responsive Check Plugin responsive-checker-real-time Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.0.3 CVE-2026-8844 Wordfence
6.4 Medium Responsive Video Embedder Plugin responsive-video-embedder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.1 CVE-2026-8877 Wordfence
6.1 Medium WP Responsive Popup + Optin Plugin wp-popup-optin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter No login needed ≤ 1.4 CVE-2026-4131 Wordfence
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
4.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions 2.0.9 – 2.2.1 CVE-2026-6703 Wordfence
5.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Other Unauthenticated Open Email Relay via REST API 'email_to' Parameter No login needed ≤ 2.2.0 CVE-2026-6675 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
6.5 Medium Responsive Plus Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed < 3.4.3 Fixed in 3.4.3 CVE-2025-15488 WPScan
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
5.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Broken Access Control No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-32543 Patchstack
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
7.5 High WP Responsive Images Plugin wp-responsive-images Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via src No login needed ≤ 1.0 CVE-2026-1557 Wordfence
5.0 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload ≤ 2.7.1 CVE-2026-2479 Wordfence
8.8 High Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored XSS No login needed 1.7.0 – < 2.6.1 Fixed in 2.6.1 CVE-2025-15386 WPScan
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin slider-responsive-slideshow PHP Object Injection Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Object Injection ≤ 1.5.4 CVE-2026-22346 Patchstack
8.8 High Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery Plugin new-image-gallery PHP Object Injection Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin <= 1.6.0 - PHP Object Injection ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-22345 Patchstack
7.1 High eDS Responsive Menu Plugin eds-responsive-menu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-68845 Patchstack
6.4 Medium WDES Responsive Popup Plugin wdes-responsive-popup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute ≤ 1.3.6 CVE-2026-1804 Wordfence
4.4 Medium Responsive Header Plugin responsive-header Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 1.0 CVE-2026-1300 Wordfence
7.1 High Magic Responsive Slider and Carousel Plugin magic_carousel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-49043 Patchstack
4.3 Medium Responsive Accordion Slider Plugin responsive-accordion-slider Broken Access Control Missing Authorization to Authenticated (Contributor+) Slider Update via 'resp_accordion_silder_save_images' ≤ 1.2.2 CVE-2026-0635 Wordfence
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
6.4 Medium Responsive Pricing Table Plugin dk-pricr-responsive-pricing-table Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency' ≤ 5.1.12 CVE-2025-15058 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only