WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 7,301–7,350 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 147 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Travel Diaries Plugin travel-diaries Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32375 Patchstack
5.3 Medium The Minimal Plugin the-minimal Broken Access Control No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32374 Patchstack
5.4 Medium SMS Alert Order Notifications Plugin sms-alert Broken Access Control ≤ 3.9.0 Fixed in 3.9.1 CVE-2026-32373 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
5.3 Medium Elegant Pink Plugin elegant-pink Broken Access Control No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-32371 Patchstack
5.3 Medium Influencer Plugin influencer Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-32370 Patchstack
7.5 High Medilink-Core Plugin medilink-core Local File Inclusion ≤ 2.0.7 Fixed in 2.0.7 CVE-2026-32369 Patchstack
8.5 High Geo to Lat Plugin geo-to-lat SQL Injection ≤ 1.0.19 Fixed in 1.1 CVE-2026-32368 Patchstack
9.1 Critical Modal Dialog Plugin modal-dialog Remote Code Execution ≤ 3.5.16 Fixed in 3.5.17 CVE-2026-32367 Patchstack
8.5 High Collapsing Categories Plugin collapsing-categories SQL Injection ≤ 3.0.9 Fixed in 3.0.12 CVE-2026-32366 Patchstack
8.5 High Collapsing Archives Plugin collapsing-archives SQL Injection ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-32365 Patchstack
7.5 High Turbo Manager Plugin turbo-manager Local File Inclusion ≤ 4.0.8 Fixed in 4.0.8 CVE-2026-32364 Patchstack
5.3 Medium WPLifeCycle Plugin free-php-version-info Broken Access Control No login needed ≤ 3.3.1 Fixed in 4.0 CVE-2026-32363 Patchstack
5.3 Medium WP Sessions Time Monitoring Full Automatic Plugin activitytime Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2026-32362 Patchstack
6.5 Medium Editorial Calendar Plugin editorial-calendar Cross-Site Scripting ≤ 3.9.0 Fixed in 3.9.1 CVE-2026-32361 Patchstack
5.9 Medium Rich Showcase for Google Reviews Plugin widget-google-reviews Cross-Site Scripting ≤ 6.9.4.3 Fixed in 6.9.4.4 CVE-2026-32360 Patchstack
6.5 Medium Icon List Block Plugin icon-list-block Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-32359 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 10.14.15 Fixed in 10.14.16 CVE-2026-32358 Patchstack
6.4 Medium Simple Blog Card Plugin simple-blog-card Server-Side Request Forgery ≤ 2.37 Fixed in 2.38 CVE-2026-32357 Patchstack
6.5 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-32356 Patchstack
8.8 High JetEngine Plugin jet-engine PHP Object Injection Deserialization of untrusted data ≤ 3.8.4.1 Fixed in 3.8.4.1 CVE-2026-32355 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.1.9 Fixed in 5.1.9 CVE-2026-32354 Patchstack
6.4 Medium MailerPress Plugin mailerpress Server-Side Request Forgery ≤ 1.4.2 Fixed in 1.5.0 CVE-2026-32353 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
5.9 Medium PowerPress Podcasting Plugin powerpress Cross-Site Scripting ≤ 11.15.13 Fixed in 11.15.14 CVE-2026-32351 Patchstack
5.3 Medium Chocolate House Plugin chocolate-house Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-32350 Patchstack
4.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Server-Side Request Forgery ≤ 2.4.7 Fixed in 2.4.8 CVE-2026-32349 Patchstack
5.3 Medium MAS Videos Plugin masvideos Broken Access Control No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-32348 Patchstack
5.3 Medium Restaurant and Cafe Plugin restaurant-and-cafe Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32347 Patchstack
5.3 Medium Travel Agency Plugin travel-agency Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-32346 Patchstack
5.3 Medium Perfect Portfolio Plugin perfect-portfolio Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32345 Patchstack
4.3 Medium Corpiva Plugin corpiva Cross-Site Request Forgery No login needed ≤ 1.0.96 Fixed in 1.0.97 CVE-2026-32344 Patchstack
4.3 Medium Easy Table of Contents Plugin easy-table-of-contents Cross-Site Request Forgery No login needed ≤ 2.0.80 Fixed in 2.0.81 CVE-2026-32343 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.1.2 Fixed in 6.7.1.3 CVE-2026-32342 Patchstack
5.3 Medium Benevolent Plugin benevolent Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2026-32341 Patchstack
5.3 Medium Business One Page Plugin business-one-page Broken Access Control No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-32340 Patchstack
5.3 Medium Bakes And Cakes Plugin bakes-and-cakes Broken Access Control No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32339 Patchstack
5.3 Medium Construction Landing Page Plugin construction-landing-page Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-32338 Patchstack
5.3 Medium Preschool and Kindergarten Plugin preschool-and-kindergarten Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32337 Patchstack
5.3 Medium Rara Business Plugin rara-business Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-32336 Patchstack
5.3 Medium The Conference Plugin the-conference Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32335 Patchstack
5.3 Medium JobScout Plugin jobscout Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-32334 Patchstack
5.3 Medium Easy Form Plugin easy-form Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.8.0 CVE-2026-32332 Patchstack
5.4 Medium Textmetrics Plugin webtexttool Broken Access Control ≤ 3.6.4 Fixed in 3.6.5 CVE-2026-32331 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Request Forgery No login needed ≤ 1.8.37 Fixed in 1.8.38 CVE-2026-32330 Patchstack
5.3 Medium Advanced Related Posts Plugin advanced-related-posts Broken Access Control No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-32329 Patchstack
5.4 Medium Lemmony Plugin lemmony Cross-Site Request Forgery No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2026-32328 Patchstack
8.5 High Fox LMS Plugin fox-lms SQL Injection ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2026-31922 Patchstack
4.3 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Broken Access Control ≤ 4.7.1 Fixed in 4.7.1.1 CVE-2026-31919 Patchstack
6.5 Medium immonex Kickstart Plugin immonex-kickstart Cross-Site Scripting ≤ 1.13.0 Fixed in 1.13.4 CVE-2026-31918 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only