WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 55 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.0 High Tabs Plugin tabs-responsive Remote Code Execution ≤ 2.5 CVE-2026-39776 Patchstack
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.3.3.1 Fixed in 2.3.3.2 CVE-2026-66573 Patchstack
5.9 Medium Tabs Plugin tabs-responsive Cross-Site Scripting ≤ 2.5 CVE-2026-65550 Patchstack
4.3 Medium Envo's Templates & Widgets for Elementor and WooCommerce Plugin envo-elementor-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting ≤ 1.4.26 CVE-2026-11600 Wordfence
6.4 Medium Bold Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode ≤ 5.5.1 CVE-2025-12803 Wordfence
4.3 Medium Latest Tabs Plugin kento-latest-tabs Cross-Site Request Forgery Cross-Site Request Forgery to Plugin's Settings Update No login needed ≤ 1.5 CVE-2025-14999 Wordfence
6.5 Medium JetTabs Plugin jet-tabs Broken Access Control ≤ 2.2.12 Fixed in 2.2.12.1 CVE-2025-68498 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.12 Fixed in 2.2.12.1 CVE-2025-68499 Patchstack
8.8 High Category and Product Woocommerce Tabs Plugin category-and-product-woocommerce-tabs Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2025-13088 Wordfence
6.4 Medium WP Bootstrap Tabs Plugin wp-bootstrap-tabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.4 CVE-2025-11822 Wordfence
6.5 Medium Tab Ultimate Plugin tabs-pro Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-62060 Patchstack
7.5 High AffiliateWP Plugin affiliatewp-affiliate-area-tabs SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.28.2 CVE-2025-8877 Wordfence
6.4 Medium FancyTabs Plugin fancytabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter ≤ 1.1.0 CVE-2025-8560 Wordfence
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-58985 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Information Disclosure Sensitive Data Exposure ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53985 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.9.1 Fixed in 2.2.9.2 CVE-2025-54687 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53984 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-39450 Patchstack
7.2 High WP Tabs Plugin wp-expand-tabs-free PHP Object Injection ≤ 2.2.12 Fixed in 2.2.13 CVE-2025-48134 Patchstack
7.1 High Tabs Plugin gt-tabs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.3 CVE-2025-46522 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-26749 Patchstack
6.1 Medium WP Tabs Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.2.7 Fixed in 2.2.7 CVE-2024-11503 WPScan
7.1 High cTabs Plugin ctabs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-30586 Patchstack
7.1 High sidebarTabs Plugin sidebartabs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1 CVE-2025-26587 Patchstack
7.2 High Tabs for WooCommerce Plugin wc-tabs PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs ≤ 1.0.0 CVE-2024-13831 Wordfence
7.2 High Custom Product Tabs Lite for WooCommerce Plugin woocommerce-custom-product-tabs-lite PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.9.0 CVE-2024-12600 Wordfence
6.4 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via anchor ≤ 1.1.8 CVE-2024-13721 Wordfence
6.5 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.5 Fixed in 1.2.1 CVE-2025-24709 Patchstack
6.4 Medium WP Responsive Tabs Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.9 CVE-2024-13387 Wordfence
5.3 Medium Tabs Shortcode Plugin Cross-Site Scripting Contributor+ XSS via Shortcode No login needed ≤ 2.0.2 CVE-2024-11606 WPScan
7.2 High Custom Product Tabs for WooCommerce Plugin yikes-inc-easy-custom-woocommerce-product-tabs PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.8.5 CVE-2024-11465 Wordfence
7.2 High Custom Product Tabs For WooCommerce Plugin wb-custom-product-tabs-for-woocommerce PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.2.4 CVE-2024-12721 Wordfence
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
6.4 Medium Tabs Maker Plugin tabs-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-11865 Wordfence
5.3 Medium Gou Manage My Account Menu Plugin gou-wc-account-tabs Broken Access Control No login needed ≤ 1.0.1.8 Fixed in 1.0.1.9 CVE-2024-54310 Patchstack
4.3 Medium XLTab – Accordions and Tabs for Elementor Page Builder Plugin xl-tab Information Disclosure Accordions and Tabs for Elementor Page Builder <= 1.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.4 CVE-2024-10689 Wordfence
6.5 Medium XLTab – Accordions and Tabs for Elementor Page Builder Plugin xl-tab Cross-Site Scripting Accordions and Tabs for Elementor Page Builder plugin <= 1.3 - Cross Site Scripting (XSS) ≤ 1.3 Fixed in 1.4 CVE-2024-47375 Patchstack
8.8 High JetTabs Plugin Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion ≤ 2.2.3 CVE-2024-7146 Wordfence
5.9 Medium Responsive Tabs Plugin responsive-tabs Cross-Site Scripting Contributor+ Stored XSS ≤ 4.0.8 CVE-2024-4096 WPScan
5.9 Medium Tabs Plugin vc-tabs Cross-Site Scripting ≤ 4.0.6 CVE-2024-37120 Patchstack
6.5 Medium Tabs For WPBakery Page Builder Plugin tabs-for-visual-composer Cross-Site Scripting ≤ 1.2 CVE-2024-37936 Patchstack
6.4 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via tab Shortcode ≤ 0.4.8 CVE-2024-5946 Wordfence
6.4 Medium Ultimate Post Kit Addons for Elementor Plugin ultimate-post-kit Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget ≤ 3.11.7 CVE-2024-5662 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets ≤ 2.6.5 CVE-2024-4479 Wordfence
5.4 Medium Responsive Tabs Plugin responsive-tabs Content Injection HTML Content Injection < 4.0.6 Fixed in 4.0.6 CVE-2023-45635 Patchstack
5.4 Medium Tabs & Accordion Plugin tabs Content Injection ≤ 1.3.10 CVE-2023-40557 Patchstack
4.3 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Request Forgery No login needed ≤ 0.4.7 CVE-2024-4463 Wordfence
6.4 Medium GeoDirectory – WordPress Business Directory Plugin, or Classified Directory Plugin Cross-Site Scripting WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' Shortcode ≤ 2.3.48 CVE-2024-3732 Wordfence
5.4 Medium Responsive Tabs Plugin responsive-tabs Cross-Site Scripting Contributor+ Stored XSS < 4.0.7 Fixed in 4.0.7 CVE-2024-1846 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only