WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Listdom Plugin listdom SQL Injection No login needed ≤ 5.4.0 Fixed in 5.5.0 CVE-2026-54819 Patchstack
9.8 Critical The Barber Shop Theme nrgbarbershop PHP Object Injection No login needed ≤ 1.9 CVE-2025-60230 Patchstack
9.8 Critical Lagom Theme lagom PHP Object Injection No login needed ≤ 2.0 CVE-2025-60229 Patchstack
9.8 Critical Moderno Theme moderno PHP Object Injection No login needed < 1.43 Fixed in 1.43 CVE-2026-49108 Patchstack
9.8 Critical Plumbing Theme plumbing-parts PHP Object Injection No login needed ≤ 1.6 CVE-2025-69127 Patchstack
9.8 Critical Reisen Theme reisen PHP Object Injection No login needed ≤ 1.4.1 CVE-2025-69111 Patchstack
9.3 Critical Advanced Ads – Tracking Plugin advanced-ads-tracking SQL Injection Tracking plugin < 3.0.7 - SQL Injection No login needed < 3.0.7 Fixed in 3.0.7 CVE-2025-59554 Patchstack
9.3 Critical WP eMember Plugin wp-emember SQL Injection No login needed < v10.9.4 Fixed in v10.9.4 CVE-2026-54811 Patchstack
9.8 Critical Registration Form for WooCommerce Plugin registration-form-for-woocommerce Privilege Escalation No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-54807 Patchstack
9.8 Critical WP Activity Log Plugin wp-security-audit-log PHP Object Injection No login needed ≤ 5.6.3.1 Fixed in 5.6.4 CVE-2026-54806 Patchstack
9.8 Critical SMS Alert Order Notifications Plugin sms-alert Privilege Escalation No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2026-54803 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed ≤ 3.8.10.1 Fixed in 3.8.10.2 CVE-2026-54187 Patchstack
9.3 Critical JobSearch Plugin wp-jobsearch SQL Injection No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2026-54186 Patchstack
9.8 Critical JetEngine Plugin jet-engine PHP Object Injection No login needed ≤ 3.8.10 Fixed in 3.8.10.1 CVE-2026-52706 Patchstack
9.0 Critical SigmaForms Pro – AI Generated Forms Plugin sigmaforms-pro Arbitrary File Upload AI Generated Forms plugin <= 1.4.5 - Arbitrary File Upload No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-52705 Patchstack
9.8 Critical wpForo Forum Plugin wpforo Authentication Bypass Broken Authentication No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-49767 Patchstack
9.8 Critical Thrive Apprentice Plugin thrive-apprentice PHP Object Injection No login needed < 10.8.10.2 Fixed in 10.8.10.2 CVE-2026-49107 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed < 3.8.9.1 Fixed in 3.8.9.1 CVE-2026-49084 Patchstack
9.3 Critical JetSearch Plugin jet-search SQL Injection No login needed ≤ 3.5.17 Fixed in 3.5.17.1 CVE-2026-49079 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed ≤ 3.8.9.1 Fixed in 3.8.10 CVE-2026-49076 Patchstack
9.8 Critical JetEngine Plugin jet-engine PHP Object Injection No login needed ≤ 3.8.9.1 Fixed in 3.8.10 CVE-2026-49075 Patchstack
9.8 Critical LoginPress Pro Plugin loginpress-pro Privilege Escalation No login needed ≤ 6.2.2 Fixed in 6.2.3 CVE-2026-49058 Patchstack
9.3 Critical JetSmartFilters Plugin jet-smart-filters SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.1.1 CVE-2026-48875 Patchstack
9.8 Critical AI Lab Theme ailab PHP Object Injection No login needed < 5.4.2 Fixed in 5.4.2 CVE-2026-42380 Patchstack
9.9 Critical Blocksy Companion Pro Plugin blocksy-companion-pro Remote Code Execution ≤ 2.1.37 Fixed in 2.1.38 CVE-2026-40783 Patchstack
9.9 Critical Charity Zone Theme charity-zone Arbitrary File Upload ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-40749 Patchstack
9.9 Critical Kids Gift Shop Theme kids-gift-shop Arbitrary File Upload ≤ 0.5.4 Fixed in 0.5.5 CVE-2026-40748 Patchstack
9.9 Critical Ecommerce Zone Theme ecommerce-zone Arbitrary File Upload ≤ 0.9.7 Fixed in 0.9.8 CVE-2026-40747 Patchstack
9.9 Critical Restaurant Zone Theme restaurant-zone Arbitrary File Upload ≤ 0.7.8 Fixed in 0.7.9 CVE-2026-40746 Patchstack
9.8 Critical WooCommerce Product Filters Plugin woocommerce-product-filters PHP Object Injection No login needed < 2.0.6 Fixed in 2.0.6 CVE-2026-40725 Patchstack
9.3 Critical Blocksy Companion Pro Plugin blocksy-companion-pro SQL Injection No login needed < 2.1.29 Fixed in 2.1.29 CVE-2026-39596 Patchstack
9.9 Critical Webenvo Theme webenvo Arbitrary File Upload ≤ 0.0.6 Fixed in 0.0.7 CVE-2026-39589 Patchstack
9.9 Critical Unlimited Elements for Elementor (Premium) Plugin unlimited-elements-for-elementor-premium Arbitrary File Upload ≤ 2.0.6 CVE-2026-27041 Patchstack
9.9 Critical WishList Member X Plugin wishlist-member-x Arbitrary File Upload ≤ 3.29.0 CVE-2026-25446 Patchstack
9.1 Critical MetForm Pro Plugin metform-pro Broken Access Control No login needed ≤ 3.9.1 CVE-2026-24611 Patchstack
9.3 Critical WPJobster Theme wpjobster SQL Injection No login needed ≤ 6.3.5 CVE-2026-22340 Patchstack
9.3 Critical Tutor LMS Pro Plugin tutor-pro SQL Injection No login needed ≤ 3.9.6 Fixed in 3.9.7 CVE-2026-22332 Patchstack
9.9 Critical Restaurt Theme restaurt Arbitrary File Upload ≤ 1.0.4 CVE-2026-22327 Patchstack
9.8 Critical Support Ticket Management System Plugin support_ticket Privilege Escalation No login needed ≤ 1.9 CVE-2025-69179 Patchstack
10.0 Critical WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Arbitrary File Upload No login needed ≤ 1.0.7 CVE-2025-69129 Patchstack
9.9 Critical PT Luxa Addons Plugin pt-luxa-addons Arbitrary File Upload ≤ 1.2.2 CVE-2025-60218 Patchstack
9.8 Critical ThemeREX Addons Plugin trx_addons PHP Object Injection No login needed ≤ 2.36.1.1 Fixed in 2.36.2 CVE-2025-60205 Patchstack
9.9 Critical Grip Theme grip Remote Code Execution Arbitrary Plugin Activation/Deactivation to RCE ≤ 1.0.9 CVE-2024-52488 Patchstack
10.0 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Remote Code Execution Custom Post Types plugin for WordPress plugin < 2.0.52 - Remote Code Execution (RCE) No login needed < 2.0.52 Fixed in 2.0.52 CVE-2026-25470 Patchstack
9.3 Critical wpDataTables Plugin wpdatatables SQL Injection No login needed ≤ 7.3.6 Fixed in 7.4 CVE-2026-49080 Patchstack
9.8 Critical Elementra Theme elementra PHP Object Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-39529 Patchstack
9.3 Critical ListingPro Plugin listingpro-plugin SQL Injection No login needed ≤ 2.9.10 Fixed in 2.9.11 CVE-2026-39438 Patchstack
9.8 Critical Nifty Theme nifty PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-27429 Patchstack
9.8 Critical Support Board Plugin supportboard Privilege Escalation No login needed < 3.8.9 Fixed in 3.8.9 CVE-2026-27395 Patchstack
9.8 Critical SeaFood Company Theme seafood-company PHP Object Injection No login needed ≤ 1.4 CVE-2025-69122 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only