WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Machete Plugin machete Cross-Site Scripting ≤ 5.2 CVE-2026-65538 Patchstack
4.3 Medium Cyr to Lat reloaded – transliteration of links and file names Plugin cyr-and-lat Broken Access Control transliteration of links and file names plugin <= 1.3.3 - Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-65537 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Request Forgery No login needed ≤ 4.4.5 CVE-2026-65536 Patchstack
4.3 Medium TinyMCE Templates Plugin tinymce-templates Information Disclosure Sensitive Data Exposure ≤ 4.8.1 CVE-2026-65535 Patchstack
5.9 Medium Custom links in Elementor Image Carousel Plugin custom-links-in-elementor-image-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2026-65534 Patchstack
6.5 Medium Smart SEO Tool Plugin smart-seo-tool Cross-Site Scripting ≤ 4.1.2 CVE-2026-65533 Patchstack
4.8 Medium Qubely Plugin qubely Broken Access Control No login needed ≤ 1.8.14 CVE-2026-65531 Patchstack
4.3 Medium TemplateSpare Plugin templatespare Broken Access Control ≤ 4.2.2 CVE-2026-65530 Patchstack
5.3 Medium Graphina Plugin graphina-elementor-charts-and-graphs Broken Access Control No login needed ≤ 3.1.12 CVE-2026-65529 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.8 CVE-2026-65528 Patchstack
6.5 Medium LIQUID SPEECH BALLOON Plugin liquid-speech-balloon Cross-Site Scripting ≤ 1.2.5 CVE-2026-65527 Patchstack
5.3 Medium Civi Framework Plugin civi-framework Broken Access Control No login needed ≤ 2.2.0 CVE-2026-65525 Patchstack
4.3 Medium Avada Custom Branding Plugin fusion-white-label-branding Broken Access Control ≤ 1.2 CVE-2026-65524 Patchstack
6.5 Medium Manual - Documentation, Knowledge Base & Education Theme manual Cross-Site Scripting Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) ≤ 7.5.4 CVE-2026-65522 Patchstack
5.3 Medium WP Social Ninja Plugin wp-social-reviews Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-65521 Patchstack
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting ≤ 2.7.7.29 Fixed in 2.7.7.30 CVE-2026-65519 Patchstack
6.5 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-65518 Patchstack
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting ≤ 1.5.86 Fixed in 1.5.87 CVE-2026-65514 Patchstack
5.4 Medium WP Activity Log Plugin wp-security-audit-log Cross-Site Request Forgery No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-65512 Patchstack
5.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control No login needed ≤ 5.12 Fixed in 5.13 CVE-2026-65506 Patchstack
5.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65505 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65503 Patchstack
5.3 Medium Shiptastic for WooCommerce Plugin shiptastic-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65501 Patchstack
6.5 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control No login needed ≤ 2.2.6 CVE-2026-65499 Patchstack
5.3 Medium Complianz Plugin complianz-gdpr Information Disclosure Sensitive Data Exposure No login needed ≤ 7.5.0 CVE-2026-65498 Patchstack
4.4 Medium Complianz Plugin complianz-gdpr Server-Side Request Forgery ≤ 7.5.0 CVE-2026-65496 Patchstack
4.3 Medium Query Wrangler Plugin query-wrangler Broken Access Control ≤ 1.5.57 CVE-2026-65491 Patchstack
5.3 Medium Create Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-65490 Patchstack
5.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65489 Patchstack
5.3 Medium Photography Theme photography Broken Access Control No login needed ≤ 7.7.6 CVE-2026-65487 Patchstack
5.3 Medium Event post Plugin event-post Broken Access Control No login needed ≤ 6.0.1 CVE-2026-65486 Patchstack
5.3 Medium Content Control Plugin content-control Broken Access Control No login needed ≤ 2.6.5 CVE-2026-65485 Patchstack
6.3 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 CVE-2026-65484 Patchstack
5.9 Medium HashThemes Demo Importer Plugin hashthemes-demo-importer Cross-Site Scripting ≤ 1.4.2 CVE-2026-65483 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.6.3 CVE-2026-65482 Patchstack
6.5 Medium TheGem Theme thegem Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-65480 Patchstack
5.4 Medium Reviewer Plugin reviewer Broken Access Control ≤ 3.14.2 CVE-2026-65479 Patchstack
5.4 Medium ListingPro Plugin listingpro-plugin Broken Access Control ≤ 2.9.10 CVE-2026-65478 Patchstack
5.3 Medium Civi Theme civi Broken Access Control No login needed ≤ 2.2.4 CVE-2026-65476 Patchstack
5.3 Medium Ninja Tables Plugin ninja-tables Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.10 Fixed in 5.2.11 CVE-2026-65474 Patchstack
6.5 Medium Virtue/Ascend/Pinnacle Toolkit Plugin virtue-toolkit Cross-Site Scripting ≤ 4.9.12 Fixed in 4.9.12.1 CVE-2026-65473 Patchstack
5.3 Medium Kit (formerly ConvertKit) Plugin convertkit Broken Access Control No login needed ≤ 3.3.5 Fixed in 3.3.6 CVE-2026-65472 Patchstack
6.5 Medium Fluent Support Plugin fluent-support Cross-Site Scripting ≤ 2.3.0 Fixed in 2.3.1 CVE-2026-65470 Patchstack
5.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control No login needed ≤ 4.4.7 Fixed in 4.4.8 CVE-2026-65469 Patchstack
5.3 Medium JetBooking Plugin jet-booking Broken Access Control No login needed ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65468 Patchstack
4.9 Medium JetEngine Plugin jet-engine Server-Side Request Forgery ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-65467 Patchstack
4.9 Medium JetBooking Plugin jet-booking Server-Side Request Forgery ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65466 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.1.1 Fixed in 2.9.1.2 CVE-2026-65465 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65464 Patchstack
5.4 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-65463 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only