WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Borgholm Theme borgholm-marketing-agency-theme PHP Object Injection No login needed ≤ < 1.6 Fixed in 1.6 CVE-2026-32502 Patchstack
9.3 Critical ChatBot Plugin chatbot SQL Injection No login needed ≤ <= 7.7.9 Fixed in 7.8.0 CVE-2026-32499 Patchstack
9.9 Critical Ona Plugin ona Arbitrary File Upload ≤ < 1.24 Fixed in 1.24 CVE-2026-32482 Patchstack
9.3 Critical Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce SQL Injection No login needed ≤ <= 1.2.2 CVE-2026-31920 Patchstack
9.8 Critical Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation PHP Object Injection No login needed ≤ 5.6.0 CVE-2026-27095 Patchstack
9.8 Critical Buisson Theme buisson PHP Object Injection No login needed ≤ 1.1.11 CVE-2026-27084 Patchstack
9.8 Critical Work & Travel Company Theme work-travel-company PHP Object Injection No login needed ≤ 1.2 CVE-2026-27083 Patchstack
9.8 Critical Love Story Theme lovestory PHP Object Injection No login needed ≤ 1.3.12 CVE-2026-27082 Patchstack
9.1 Critical WPCafe Plugin wp-cafe Broken Access Control No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-27071 Patchstack
9.8 Critical Golo Plugin golo Privilege Escalation No login needed ≤ 1.7.0 CVE-2026-27051 Patchstack
9.8 Critical Jobica Core Plugin jobica-core Privilege Escalation Account Takeover No login needed ≤ 1.4.2 CVE-2026-27049 Patchstack
9.9 Critical Total Poll Lite Plugin totalpoll-lite Remote Code Execution ≤ 4.12.0 CVE-2026-27044 Patchstack
9.1 Critical Widget Wrangler Plugin widget-wrangler Remote Code Execution ≤ 2.3.9 Fixed in 2.4.0 CVE-2026-25447 Patchstack
9.8 Critical Nexa Blocks Plugin nexa-blocks PHP Object Injection No login needed ≤ 1.1.1 CVE-2026-25429 Patchstack
9.9 Critical WPBookit Pro Plugin wpbookit-pro Arbitrary File Upload ≤ 1.6.18 CVE-2026-25413 Patchstack
9.3 Critical Addon Jobsearch Chat Plugin addon-jobsearch-chat SQL Injection No login needed ≤ 3.0 Fixed in 3.1 CVE-2026-25377 Patchstack
9.3 Critical Lumise Product Designer Plugin lumise SQL Injection No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2026-25371 Patchstack
9.9 Critical Woody ad snippets Plugin insert-php Remote Code Execution ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-25366 Patchstack
9.9 Critical SimpLy Gallery Plugin simply-gallery-block Remote Code Execution Arbitrary Code Execution ≤ 3.3.2 Fixed in 3.3.2.1 CVE-2026-25345 Patchstack
9.3 Critical Jobmonster Theme noo-jobmonster SQL Injection No login needed ≤ 4.8.4 Fixed in 4.8.4 CVE-2026-25340 Patchstack
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Account Takeover No login needed ≤ 28.1.2.2 Fixed in 28.1.3 CVE-2026-25035 Patchstack
9.8 Critical Ricky Theme ricky PHP Object Injection No login needed ≤ 2.31 Fixed in 2.31 CVE-2026-25032 Patchstack
9.8 Critical Tasty Daily Theme tastydaily PHP Object Injection No login needed ≤ 1.27 Fixed in 1.27 CVE-2026-25031 Patchstack
9.8 Critical Goldish Theme goldish PHP Object Injection No login needed ≤ 3.47 Fixed in 3.47 CVE-2026-25030 Patchstack
9.8 Critical KIDZ Theme kidz PHP Object Injection No login needed ≤ 5.24 Fixed in 5.25 CVE-2026-25029 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2026-24993 Patchstack
9.8 Critical SUMO Affiliates Pro Plugin affs PHP Object Injection No login needed ≤ 11.4.0 Fixed in 11.4.0 CVE-2026-24989 Patchstack
9.8 Critical Search & Go Theme searchgo Privilege Escalation No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-24971 Patchstack
9.8 Critical Xagio SEO Plugin xagio-seo Privilege Escalation No login needed ≤ 7.1.0.30 Fixed in 7.1.0.31 CVE-2026-24968 Patchstack
9.8 Critical EventPrime Plugin eventprime-event-calendar-management PHP Object Injection No login needed ≤ 4.2.8.0 Fixed in 4.2.8.1 CVE-2026-24378 Patchstack
9.8 Critical Beelove Theme beelove PHP Object Injection No login needed ≤ 1.2.6 CVE-2026-22507 Patchstack
9.8 Critical m2 | Construction and Tools Store Theme m2-ce PHP Object Injection No login needed ≤ 1.1.2 CVE-2026-22500 Patchstack
9.3 Critical Lisfinity Core Plugin lisfinity-core SQL Injection No login needed ≤ 1.5.0 CVE-2026-22484 Patchstack
9.1 Critical WP DSGVO Tools (GDPR) Plugin shapepress-dsgvo Broken Access Control Missing Authorization to Unauthenticated Account Destruction of Non-Admin Users No login needed ≤ 3.1.38 CVE-2026-4283 Wordfence
9.8 Critical Woocommerce Custom Product Addons Pro Plugin Remote Code Execution Unauthenticated Remote Code Execution via Custom Pricing Formula No login needed ≤ 5.4.1 CVE-2026-4001 Wordfence
9.8 Critical Kali Forms Plugin kali-forms Remote Code Execution Unauthenticated Remote Code Execution via form_process No login needed ≤ 2.4.9 CVE-2026-3584 Wordfence
9.8 Critical Aimogen Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via Arbitrary Function Call No login needed ≤ 2.7.5 CVE-2026-4038 Wordfence
9.1 Critical Mobile App Editor Plugin mobile-app-editor Arbitrary File Upload ≤ 1.3.1 CVE-2026-27067 Patchstack
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack
9.8 Critical Finag Theme finag PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60237 Patchstack
9.8 Critical Zuut Theme zuut PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-60233 Patchstack
9.3 Critical Profile Builder Pro Plugin profile-builder-pro SQL Injection No login needed < 3.14.0 Fixed in 3.14.0 CVE-2026-27413 Patchstack
9.0 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Arbitrary File Upload No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27540 Patchstack
9.8 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Privilege Escalation No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27542 Patchstack
9.8 Critical Traveler Plugin traveler PHP Object Injection No login needed ≤ 3.2.8.1 Fixed in 3.2.8.1 CVE-2026-25449 Patchstack
9.1 Critical Modal Dialog Plugin modal-dialog Remote Code Execution ≤ 3.5.16 Fixed in 3.5.17 CVE-2026-32367 Patchstack
9.8 Critical Pix for WooCommerce Plugin payment-gateway-pix-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.5.0 CVE-2026-3891 Wordfence
9.8 Critical Datalogics Ecommerce Delivery Plugin datalogics Privilege Escalation Unauthenticated Privilege Escalation No login needed < 2.6.60 Fixed in 2.6.60 CVE-2026-2631 WPScan
9.8 Critical Tutor LMS Pro Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 3.9.5 CVE-2026-0953 Wordfence
9.8 Critical Powerpack for LearnDash Plugin powerpack-for-learndash Broken Access Control Unauthenticated Arbitrary Option Update No login needed < 1.3.0 Fixed in 1.3.0 CVE-2026-2446 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only