WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Digits Plugin digits Privilege Escalation No login needed ≤ 9.2 CVE-2026-28165 Patchstack
7.1 High Events Made Easy Plugin events-made-easy Cross-Site Scripting No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2026-28162 Patchstack
7.5 High Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Plugin notification-master Broken Access Control Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 CVE-2026-28153 Patchstack
8.1 High Tonda Core Plugin tonda-core Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28152 Patchstack
8.1 High Tonda Theme tonda Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28151 Patchstack
8.1 High Verdure Core Plugin verdure-core Local File Inclusion No login needed ≤ 1.2 CVE-2026-66671 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-78290 Patchstack
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
5.3 Medium Fluent Boards Pro Plugin fluent-boards-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78278 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78272 Patchstack
7.6 High FluentCRM Pro Plugin fluentcampaign-pro SQL Injection ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78270 Patchstack
6.4 Medium Shared Files Plugin shared-files Server-Side Request Forgery ≤ 1.7.69 Fixed in 1.7.70 CVE-2026-78269 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78258 Patchstack
7.1 High Social Media & Share Icons Plugin ultimate-social-media-icons Cross-Site Scripting No login needed ≤ 2.9.9 Fixed in 3.0.0 CVE-2026-66623 Patchstack
7.1 High WPComplete Plugin wpcomplete Cross-Site Scripting No login needed ≤ 2.9.5.6 Fixed in 2.9.5.7 CVE-2026-66599 Patchstack
7.1 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting No login needed ≤ 3.19.16 Fixed in 3.19.17 CVE-2026-66584 Patchstack
5.3 Medium RepairBuddy Plugin computer-repair-shop Broken Access Control No login needed ≤ 4.1223 Fixed in 4.1224 CVE-2026-78291 Patchstack
6.4 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages ≤ 4.12.0 CVE-2026-4561 Wordfence
9.8 Critical Mailgun Plugin mailgun Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed ≤ 2.2.0 CVE-2026-78003 Wordfence
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
5.3 Medium New User Approve Plugin new-user-approve Broken Access Control No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-28163 Patchstack
7.6 High InfiniteWP Client Plugin iwp-client SQL Injection ≤ 1.13.9 Fixed in 1.13.10 CVE-2026-74011 Patchstack
7.5 High Koji Theme koji Broken Access Control No login needed ≤ 2.2.1 CVE-2026-74020 Patchstack
7.1 High EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 2.4.2 CVE-2026-74019 Patchstack
9.9 Critical Warehouse Cargo Theme warehouse-cargo Arbitrary File Upload ≤ 2.6.9 CVE-2026-74018 Patchstack
9.9 Critical Smart Cleaning Theme smart-cleaning Arbitrary File Upload ≤ 4.8.6 CVE-2026-74016 Patchstack
9.9 Critical IT Residence Theme it-residence Arbitrary File Upload ≤ 3.2.1 CVE-2026-74014 Patchstack
8.5 High eShipper Commerce Plugin eshipper-commerce SQL Injection ≤ 2.16.13 CVE-2026-74013 Patchstack
9.8 Critical User Registration & Membership Pro Plugin user-registration-pro Privilege Escalation Account Takeover No login needed ≤ 5.4.5 Fixed in 5.4.6 CVE-2026-74001 Patchstack
8.5 High WP w3all phpBB Plugin wp-w3all-phpbb-integration SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2026-73998 Patchstack
9.8 Critical FundEngine Plugin wp-fundraising-donation PHP Object Injection No login needed ≤ 1.7.9 Fixed in 1.8.0 CVE-2026-73993 Patchstack
9.9 Critical Query Wrangler Plugin query-wrangler Remote Code Execution ≤ 1.5.57 Fixed in 1.5.58 CVE-2026-73992 Patchstack
6.5 Medium WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting ≤ 6.3.2 Fixed in 6.4.0 CVE-2026-73402 Patchstack
9.3 Critical BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection No login needed ≤ 6.0.2 CVE-2026-68566 Patchstack
7.1 High NotificationX Pro Plugin notificationx-pro Cross-Site Scripting No login needed ≤ 3.1.4 CVE-2026-68564 Patchstack
9.8 Critical Abandoned Cart Pro for WooCommerce Plugin woocommerce-abandon-cart-pro Privilege Escalation No login needed ≤ 10.4.0 CVE-2026-66682 Patchstack
9.3 Critical Locatoraid Store Locator Plugin locatoraid SQL Injection No login needed ≤ 3.9.72 CVE-2026-66680 Patchstack
7.6 High Leyka Plugin leyka Authentication Bypass Broken Authentication ≤ 3.32.3 CVE-2026-66677 Patchstack
7.1 High Flatastic Theme flatastic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2026-66673 Patchstack
9.8 Critical Flatastic Theme flatastic PHP Object Injection No login needed ≤ 2.0 CVE-2026-66672 Patchstack
9.3 Critical Directory Pro Plugin directory-pro SQL Injection No login needed ≤ 2.5.8 CVE-2026-66649 Patchstack
6.5 Medium Homlisti Theme homlisti Broken Access Control ≤ 3.1.2 CVE-2026-66647 Patchstack
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting No login needed ≤ 1.15.48 CVE-2026-66616 Patchstack
7.1 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2026-66615 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.2 Fixed in 14.2.3 CVE-2026-66614 Patchstack
7.1 High Aora Theme aora Cross-Site Scripting No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2026-66612 Patchstack
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
9.3 Critical TheGem (Elementor) Theme thegem-elementor SQL Injection No login needed ≤ 5.12.3 Fixed in 5.12.3.1 CVE-2026-66609 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only