WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.5.3 CVE-2026-15795 Wordfence
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
6.5 Medium Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object References (IDOR) ≤ 28.2 Fixed in 28.3 CVE-2026-96347 Patchstack
5.3 Medium Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data No login needed ≤ 28.2 CVE-2026-92799 Wordfence
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
4.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter ≤ 27.7 CVE-2026-12905 Wordfence
6.1 Medium Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Cross-Site Scripting Reflected Cross-Site Scripting via 'id' Parameter No login needed < 1.1.53 Fixed in 1.1.53 CVE-2026-18344 Wordfence
5.9 Medium Tabs Plugin tabs-responsive Cross-Site Scripting ≤ 2.5 CVE-2026-65550 Patchstack
5.3 Medium WP Support Plus Responsive Ticket System Plugin Broken Access Control Unauthenticated Support Ticket Access via Session Cookie Forgery No login needed ≤ 9.1.2 CVE-2026-11875 WPScan
6.4 Medium Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter ≤ 3.1.31 CVE-2026-9134 Wordfence
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack
6.4 Medium Responsive Check Plugin responsive-checker-real-time Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.0.3 CVE-2026-8844 Wordfence
6.4 Medium Responsive Video Embedder Plugin responsive-video-embedder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.1 CVE-2026-8877 Wordfence
6.1 Medium WP Responsive Popup + Optin Plugin wp-popup-optin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter No login needed ≤ 1.4 CVE-2026-4131 Wordfence
4.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions 2.0.9 – 2.2.1 CVE-2026-6703 Wordfence
5.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Other Unauthenticated Open Email Relay via REST API 'email_to' Parameter No login needed ≤ 2.2.0 CVE-2026-6675 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
6.5 Medium Responsive Plus Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed < 3.4.3 Fixed in 3.4.3 CVE-2025-15488 WPScan
5.3 Medium Responsive Blocks Plugin responsive-block-editor-addons Broken Access Control No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-32543 Patchstack
5.0 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload ≤ 2.7.1 CVE-2026-2479 Wordfence
6.4 Medium WDES Responsive Popup Plugin wdes-responsive-popup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute ≤ 1.3.6 CVE-2026-1804 Wordfence
4.4 Medium Responsive Header Plugin responsive-header Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 1.0 CVE-2026-1300 Wordfence
4.3 Medium Responsive Accordion Slider Plugin responsive-accordion-slider Broken Access Control Missing Authorization to Authenticated (Contributor+) Slider Update via 'resp_accordion_silder_save_images' ≤ 1.2.2 CVE-2026-0635 Wordfence
6.4 Medium Responsive Pricing Table Plugin dk-pricr-responsive-pricing-table Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency' ≤ 5.1.12 CVE-2025-15058 Wordfence
6.4 Medium Responsive Pricing Table Plugin dk-pricr-responsive-pricing-table Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 5.1.12 CVE-2025-13418 Wordfence
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-69363 Patchstack
6.5 Medium Responsive Block Control Plugin responsive-block-control Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-62135 Patchstack
5.9 Medium Google AdSense for Responsive Design – GARD Plugin google-adsense-for-responsive-design-gard Cross-Site Scripting GARD plugin <= 2.23 - Cross Site Scripting (XSS) ≤ 2.23 CVE-2025-67632 Patchstack
6.5 Medium Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Cross-Site Scripting ≤ 15.2 Fixed in 15.3 CVE-2025-68548 Patchstack
5.5 Medium Responsive and Swipe slider Plugin responsive-and-swipe-slider Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.2 CVE-2025-14721 Wordfence
6.5 Medium Molla Plugin molla Remote Code Execution Multipurpose Responsive Shopify theme <= 1.5.13 - Arbitrary Code Execution No login needed ≤ 1.5.13 CVE-2025-60070 Patchstack
4.3 Medium Image Slider by Ays- Responsive Slider and Carousel Plugin ays-slider Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed ≤ 2.7.0 CVE-2025-14454 Wordfence
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 2.5.3 CVE-2025-12359 Wordfence
5.4 Medium Slippy Slider – Responsive Touch Navigation Slider Plugin slippy-slider-responsive-touch-navigation-slider Cross-Site Scripting Responsive Touch Navigation Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-11874 Wordfence
6.4 Medium B Carousel Block – Responsive Image and Content Carousel Plugin b-carousel-block Broken Access Control Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.1.5 CVE-2025-12388 Wordfence
4.4 Medium Multi-language Responsive Portfolio Plugin bootstrap-multi-language-responsive-portfolio Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11753 Wordfence
4.9 Medium Thumbnail Slider With Lightbox Plugin wp-responsive-slider-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2015-10146 Wordfence
5.9 Medium Photospace Responsive Plugin photospace-responsive Cross-Site Scripting ≤ 2.2.0 CVE-2025-62899 Patchstack
6.1 Medium Multi Item Responsive Slider Plugin mislider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-11992 Wordfence
6.4 Medium Responsive Progress Bar Plugin responsive-progress-bar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11883 Wordfence
6.4 Medium Responsive iframe GoogleMap Plugin responsive-iframe-googlemap Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.2 CVE-2025-11813 Wordfence
6.4 Medium WP Responsive Meet The Team Plugin wp-responsive-meet-the-team Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2025-11818 Wordfence
6.3 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-9710 WPScan
6.1 Medium Side Slide Responsive Menu Plugin side-slide-responsive-menu Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9880 Wordfence
6.4 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.0.1 CVE-2025-8215 Wordfence
6.5 Medium Responsive Mobile-Friendly Tooltip Plugin responsive-mobile-friendly-tooltip Cross-Site Scripting ≤ 1.6.6 CVE-2025-48316 Patchstack
6.4 Medium Simple Responsive Slider Plugin addi-simple-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-8690 Wordfence
6.4 Medium Useful Tab Block – Responsive & AMP-Compatible Plugin useful-tab-block-responsive-amp-compatible Cross-Site Scripting Responsive & AMP-Compatible <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter ≤ 1.3.2 CVE-2025-5754 Wordfence
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54050 Patchstack
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 CVE-2025-6068 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only