WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 73 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
7.2 High Responsive Slider Gallery Plugin responsive-slider-gallery PHP Object Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-94122 Patchstack
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool SQL Injection Unauthenticated SQL Injection No login needed ≤ 27.5 CVE-2026-14516 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
8.6 High WP Support Plus Responsive Ticket System Plugin SQL Injection Unauthenticated SQL Injection via filter[elements] Array Keys No login needed ≤ 9.1.2 CVE-2026-11590 WPScan
8.8 High WP Support Plus Responsive Ticket System Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Upload No login needed ≤ 9.1.2 CVE-2026-11589 WPScan
7.1 High Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-56041 Patchstack
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Information Disclosure Sensitive Data Exposure No login needed ≤ 27.4 Fixed in 27.5 CVE-2026-42667 Patchstack
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
7.5 High WP Responsive Images Plugin wp-responsive-images Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via src No login needed ≤ 1.0 CVE-2026-1557 Wordfence
8.8 High Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored XSS No login needed 1.7.0 – < 2.6.1 Fixed in 2.6.1 CVE-2025-15386 WPScan
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin slider-responsive-slideshow PHP Object Injection Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Object Injection ≤ 1.5.4 CVE-2026-22346 Patchstack
8.8 High Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery Plugin new-image-gallery PHP Object Injection Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin <= 1.6.0 - PHP Object Injection ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-22345 Patchstack
7.1 High eDS Responsive Menu Plugin eds-responsive-menu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-68845 Patchstack
7.1 High Magic Responsive Slider and Carousel Plugin magic_carousel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-49043 Patchstack
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.1 CVE-2025-68996 Patchstack
7.5 High Responsive Sidebar Plugin responsive-sidebar Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-60073 Patchstack
7.1 High Toast Mobile Menu Plugin toast-responsive-menu Cross-Site Scripting No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-53238 Patchstack
7.2 High Responsive Filterable Portfolio Plugin Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.24 CVE-2025-10049 Wordfence
7.2 High eDS Responsive Menu Plugin eds-responsive-menu PHP Object Injection ≤ 1.2 CVE-2025-58839 Patchstack
7.1 High Responsive HTML5 Audio Player PRO With Playlist Plugin lbg-audio2-html5 Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2025-54056 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.0 Fixed in 15.1 CVE-2025-52728 Patchstack
8.8 High Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload < 1.0.1 Fixed in 1.0.1 CVE-2015-10144 Wordfence
7.5 High Multi-language Responsive Contact Form Plugin responsive-contact-form Broken Access Control No login needed ≤ 2.8 CVE-2025-29000 Patchstack
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
8.8 High Owl carousel responsive Plugin responsive-owl-carousel SQL Injection Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.9 CVE-2025-5590 Wordfence
7.1 High Recent Posts Slider Responsive Plugin recent-posts-slider-responsive Cross-Site Request Forgery No login needed ≤ 1.0.1 CVE-2025-28966 Patchstack
8.1 High Enzio - Responsive Business Plugin enzio Local File Inclusion Responsive Business WordPress Theme theme < 1.2.6 - Local File Inclusion No login needed ≤ 1.2.6 Fixed in 1.2.6 CVE-2025-31912 Patchstack
8.1 High Kiamo - Responsive Business Service Theme kiamo Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-31633 Patchstack
8.5 High Magic Responsive Slider and Carousel Plugin magic-carousel SQL Injection ≤ 1.6 Fixed in 1.6 CVE-2025-31640 Patchstack
8.5 High Multimedia Responsive Carousel with Image Video Audio Support Plugin multimedia-carousel SQL Injection ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-31928 Patchstack
8.5 High Responsive HTML5 Audio Player PRO With Playlist Plugin lbg-audio2-html5 SQL Injection ≤ 3.5.7 CVE-2025-32287 Patchstack
7.1 High SUPER RESPONSIVE SLIDER Plugin super-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22575 Patchstack
8.8 High JobCareer | Job Board Responsive Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions ≤ 7.1 CVE-2024-12810 Wordfence
8.1 High Flex Mag - Responsive WordPress News Theme Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 3.5.2 CVE-2024-13655 Wordfence
8.8 High Car Dealer Automotive WordPress Theme – Responsive Theme Arbitrary File Deletion Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read ≤ 1.6.3 CVE-2025-1282 Wordfence
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
7.1 High Responsive Modal Builder for High Conversion – Easy Popups Plugin easy-popups Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-26774 Patchstack
8.8 High Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Local File Inclusion Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.4 CVE-2024-13353 Wordfence
7.1 High Simple Responsive Menu Plugin simple-responsive-menu Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26543 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49333 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49303 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only