WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,751–6,800 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 136 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Lumise Product Designer Plugin lumise SQL Injection No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2026-25371 Patchstack
9.9 Critical Woody ad snippets Plugin insert-php Remote Code Execution ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-25366 Patchstack
6.5 Medium Kargo Takip Plugin kargo-takip-turkiye Broken Access Control ≤ 0.2.4 Fixed in 0.2.4 CVE-2026-25365 Patchstack
7.1 High WpEvently Plugin mage-eventpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.4 Fixed in 5.1.5 CVE-2026-25361 Patchstack
8.8 High Vex Theme vex PHP Object Injection ≤ 1.2.9 Fixed in 1.2.9 CVE-2026-25360 Patchstack
8.8 High Pendulum Theme pendulum PHP Object Injection ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-25359 Patchstack
8.8 High Meloo Theme meloo PHP Object Injection ≤ 2.8.2 Fixed in 2.8.2 CVE-2026-25358 Patchstack
8.1 High Ultimate Membership Pro Plugin indeed-membership-pro Privilege Escalation Account Takeover No login needed ≤ 13.7 Fixed in 13.7.1 CVE-2026-25357 Patchstack
7.1 High Yobazar Theme yobazar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.7 CVE-2026-25356 Patchstack
6.5 Medium Sanzo Theme sanzo Cross-Site Scripting ≤ 2.4.3 Fixed in 2.4.3 CVE-2026-25355 Patchstack
7.1 High Reebox Theme reebox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2026-25354 Patchstack
7.1 High Nooni Theme nooni Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.1 CVE-2026-25353 Patchstack
7.1 High MyDecor Theme mydecor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.9 Fixed in 1.5.9 CVE-2026-25352 Patchstack
7.1 High MyMedi Theme mymedi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.7 Fixed in 1.7.7 CVE-2026-25351 Patchstack
7.1 High Miti Theme miti Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.3 CVE-2026-25350 Patchstack
7.1 High Loobek Theme loobek Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.2 CVE-2026-25349 Patchstack
7.1 High WP REST Cache Plugin wp-rest-cache Cross-Site Scripting No login needed ≤ 2026.1.0 Fixed in 2026.1.1 CVE-2026-25347 Patchstack
7.1 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-25346 Patchstack
9.9 Critical SimpLy Gallery Plugin simply-gallery-block Remote Code Execution Arbitrary Code Execution ≤ 3.3.2 Fixed in 3.3.2.1 CVE-2026-25345 Patchstack
6.5 Medium Review Schema Plugin review-schema Information Disclosure Sensitive Data Exposure ≤ 2.2.6 Fixed in 2.2.7 CVE-2026-25344 Patchstack
7.1 High Boutique Theme kute-boutique Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2026-25342 Patchstack
7.1 High RSFirewall! Plugin rsfirewall Cross-Site Scripting No login needed ≤ 1.1.45 Fixed in 1.1.46 CVE-2026-25341 Patchstack
9.3 Critical Jobmonster Theme noo-jobmonster SQL Injection No login needed ≤ 4.8.4 Fixed in 4.8.4 CVE-2026-25340 Patchstack
6.5 Medium Contact Form by WPForms Plugin wpforms-lite Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.8.7 Fixed in 1.9.9.2 CVE-2026-25339 Patchstack
8.1 High Salon Booking System Pro Plugin salon-booking-plugin-pro Privilege Escalation Account Takeover No login needed ≤ 10.30.12 Fixed in 10.30.12 CVE-2026-25334 Patchstack
6.8 Medium Product File Upload for WooCommerce Plugin products-file-upload-for-woocommerce Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-25328 Patchstack
6.5 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2026-25327 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-25317 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Broken Access Control No login needed ≤ 4.10.1 Fixed in 4.11.0 CVE-2026-25309 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-25306 Patchstack
7.1 High Jaroti Theme jaroti Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2026-25304 Patchstack
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Account Takeover No login needed ≤ 28.1.2.2 Fixed in 28.1.3 CVE-2026-25035 Patchstack
6.5 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control No login needed ≤ 3.6.16 Fixed in 4.0.0 CVE-2026-25034 Patchstack
7.1 High Motta Addons Plugin motta-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.1 CVE-2026-25033 Patchstack
9.8 Critical Ricky Theme ricky PHP Object Injection No login needed ≤ 2.31 Fixed in 2.31 CVE-2026-25032 Patchstack
9.8 Critical Tasty Daily Theme tastydaily PHP Object Injection No login needed ≤ 1.27 Fixed in 1.27 CVE-2026-25031 Patchstack
9.8 Critical Goldish Theme goldish PHP Object Injection No login needed ≤ 3.47 Fixed in 3.47 CVE-2026-25030 Patchstack
9.8 Critical KIDZ Theme kidz PHP Object Injection No login needed ≤ 5.24 Fixed in 5.25 CVE-2026-25029 Patchstack
7.5 High Team Plugin tlp-team Broken Access Control No login needed ≤ 5.0.11 Fixed in 5.0.12 CVE-2026-25026 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-25025 Patchstack
7.1 High NaturaLife Extensions Plugin naturalife-extensions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2026-25018 Patchstack
8.1 High NaturaLife Extensions Plugin naturalife-extensions Local File Inclusion No login needed ≤ 2.1 Fixed in 2.2 CVE-2026-25017 Patchstack
7.1 High Phox Hosting Plugin phox-host Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-25013 Patchstack
6.5 Medium Education Zone Plugin education-zone Broken Access Control No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2026-25009 Patchstack
8.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-25007 Patchstack
7.5 High LearnPress – Sepay Payment Plugin learnpress-sepay-payment Authentication Bypass Sepay Payment plugin <= 4.0.0 - Broken Authentication No login needed ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-25002 Patchstack
8.5 High Post Snippets Plugin post-snippets Remote Code Execution ≤ 4.0.12 Fixed in 4.0.13 CVE-2026-25001 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2026-24993 Patchstack
9.8 Critical SUMO Affiliates Pro Plugin affs PHP Object Injection No login needed ≤ 11.4.0 Fixed in 11.4.0 CVE-2026-24989 Patchstack
6.5 Medium WP System Log Plugin winterlock Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2026-24987 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only