WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,201–5,250 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 105 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-42653 Patchstack
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2026-39494 Patchstack
9.3 Critical JoomSport Plugin joomsport-sports-league-results-management SQL Injection No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2026-42647 Patchstack
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Privilege Escalation No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2026-49060 Patchstack
4.3 Medium MetroStore Theme metrostore Broken Access Control ≤ 1.3.2 CVE-2023-32959 Patchstack
5.4 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Broken Access Control No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2023-25969 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
5.4 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Broken Access Control Broken Access Control + CSRF ≤ 1.6.3.3 Fixed in 1.6.3.4 CVE-2022-45813 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
5.4 Medium Soledad Theme soledad Broken Access Control ≤ 8.2.5 Fixed in 8.2.6 CVE-2022-42479 Patchstack
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
7.1 High WP Mail Log Plugin wp-mail-log Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.1.1 CVE-2023-33999 Patchstack
8.1 High UpdraftPlus: WP Backup & Migration Plugin updraftplus Authentication Bypass Unauthenticated Authentication Bypass via UpdraftCentral udrpc No login needed ≤ 1.26.4 CVE-2026-10795 Wordfence
4.7 Medium Open User Map PRO Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification' No login needed ≤ 1.4.31 CVE-2026-2827 Wordfence
5.4 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Scripting Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes ≤ 9.0.4 CVE-2026-53742 VulnCheck
5.4 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Scripting Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option ≤ 9.0.4 CVE-2026-53741 VulnCheck
5.4 Medium Yoast Duplicate Post Plugin duplicate-post Cross-Site Scripting Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice ≤ 4.6 CVE-2026-53740 VulnCheck
4.3 Medium Yoast Duplicate Post Plugin duplicate-post Cross-Site Request Forgery Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice No login needed ≤ 4.6 CVE-2026-53739 VulnCheck
8.1 High Copy & Delete Posts Plugin copy-delete-posts Privilege Escalation Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler ≤ 1.5.4 CVE-2026-53738 VulnCheck
6.1 Medium Juicer Plugin juicer Cross-Site Scripting Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response No login needed ≤ 1.12.18 CVE-2026-53737 VulnCheck
4.3 Medium Easy Twitter Feeds Plugin easy-twitter-feeds Cross-Site Request Forgery Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action No login needed < 1.2.13 Fixed in 1.2.13 CVE-2026-53736 VulnCheck
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
7.5 High Newsletters Plugin newsletters-lite SQL Injection Unauthenticated SQL Injection via wpmlsubscriber_id Parameter No login needed ≤ 4.13 CVE-2026-3018 Wordfence
9.8 Critical Doctreat Core Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.6.8 CVE-2025-6254 Wordfence
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting ≤ 1.1.8 CVE-2026-8613 Wordfence
4.4 Medium MW WP Form Plugin mw-wp-form Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter ≤ 5.1.3 CVE-2026-8853 Wordfence
6.4 Medium Easy Image Collage Plugin easy-image-collage Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters ≤ 1.13.6 CVE-2026-9019 Wordfence
9.1 Critical Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Arbitrary File Upload Unauthenticated Arbitrary Media Upload No login needed < 1.60 Fixed in 1.60 CVE-2026-9067 WPScan
3.5 Low Agile Store Locator Plugin agile-store-locator Cross-Site Scripting Admin+ Stored XSS via map_style < 1.6.6 Fixed in 1.6.6 CVE-2026-9060 WPScan
8.8 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin Cross-Site Scripting Unauthenticated Stored XSS via Comment Shortcode Bypass No login needed < 6.79 Fixed in 6.79 CVE-2026-8071 WPScan
8.6 High XStore Theme SQL Injection Unauthenticated SQLi No login needed < 9.7.3 Fixed in 9.7.3 CVE-2026-3326 WPScan
6.4 Medium Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates Plugin animation-addons-for-elementor Cross-Site Scripting GSAP Powered Elementor Addons & Website Templates <= 2.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters ≤ 2.6.7 CVE-2025-8444 Wordfence
4.3 Medium BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Friends List IDOR via REST API ≤ 14.4.0 CVE-2026-53675 VulnCheck
7.1 High BuddyPress Plugin buddypress Denial of Service BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution ≤ 14.4.0 CVE-2026-53674 VulnCheck
8.1 High BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter ≤ 14.4.0 CVE-2026-53673 VulnCheck
9.8 Critical Woody Code Snippets Plugin insert-php Remote Code Execution WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API No login needed < 3.3.1 Fixed in 3.3.1 CVE-2017-20251 VulnCheck
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
8.2 High KittyCatfish Plugin SQL Injection KittyCatfish 2.2 Plugin for WordPress SQL Injection No login needed 2.2 CVE-2017-20246 VulnCheck
8.2 High Wow Viral Signups Plugin mwp-viral-signup SQL Injection Wow Viral Signups 2.1 WordPress Plugin SQL Injection No login needed 2.1 CVE-2017-20245 VulnCheck
8.2 High Wow Forms Plugin mwp-forms SQL Injection Wow Forms WordPress Plugin 2.1 SQL Injection No login needed 2.1 CVE-2017-20244 VulnCheck
8.2 High Product Catalog 8 Plugin product-catalog-8 SQL Injection Product Catalog 8 1.2 Plugin WordPress SQL Injection No login needed 1.2.0 CVE-2016-20065 VulnCheck
6.2 Medium WP Vault Plugin wp-vault Local File Inclusion WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter No login needed 0.8.6.6 CVE-2016-20064 VulnCheck
7.1 High Single Personal Message Plugin simple-personal-message SQL Injection Single Personal Message 1.0.3 WordPress Plugin SQL Injection 1.0.3 CVE-2016-20063 VulnCheck
8.2 High Simply Poll Plugin simply-poll SQL Injection Simply Poll 1.4.1 Plugin for WordPress SQL Injection No login needed 1.4.1 CVE-2016-20062 VulnCheck
4.3 Medium User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation ≤ 4.3.2 CVE-2026-4058 Wordfence
8.8 High Blocksy Theme blocksy PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field ≤ 2.1.41 CVE-2026-8365 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only