WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Widget Options Plugin widget-options Information Disclosure Subscriber+ User Meta Data Exposure ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-35690 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 8.0 Fixed in 9.0 CVE-2024-35648 Patchstack
5.3 Medium iPages Flipbook Plugin ipages-flipbook Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-33909 Patchstack
4.3 Medium Shareaholic Plugin shareaholic Broken Access Control ≤ 9.7.11 Fixed in 9.7.12 CVE-2024-24709 Patchstack
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-31435 Patchstack
4.3 Medium Startupzy Theme startupzy Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-33685 Patchstack
4.3 Medium Skyline WP Theme skyline-wp Cross-Site Request Forgery No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-34810 Patchstack
6.8 Medium JetFormBuilder Plugin jetformbuilder Privilege Escalation ≤ 3.6.1 Fixed in 3.6.1.1 CVE-2026-54196 Patchstack
6.5 Medium WooCommerce Anti-Fraud Plugin woocommerce-anti-fraud Broken Access Control No login needed ≤ 7.2.6 Fixed in 7.2.7 CVE-2026-49072 Patchstack
6.5 Medium WooCommerce Dropshipping Plugin woocommerce-dropshipping Authentication Bypass Broken Authentication No login needed ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-49071 Patchstack
6.5 Medium WPBakery Page Builder Plugin js_composer Broken Access Control ≤ 8.7.2 Fixed in 8.7.3 CVE-2026-45436 Patchstack
6.5 Medium Client Portal (Pro) Plugin leco-client-portal Path Traversal Arbitrary File Download ≤ 5.6.2 Fixed in 5.6.3 CVE-2026-40724 Patchstack
4.3 Medium Bricks Builder Theme bricks Broken Access Control ≤ 2.1.4 Fixed in 2.2 CVE-2026-40723 Patchstack
4.7 Medium W3 Total Cache Plugin w3-total-cache Broken Access Control ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-39595 Patchstack
6.5 Medium Slimstat Analytics Plugin wp-slimstat PHP Object Injection Deserialization of untrusted data No login needed < 5.4.0 Fixed in 5.4.0 CVE-2026-27410 Patchstack
4.3 Medium MetForm Pro Plugin metform-pro Broken Access Control ≤ 3.9.1 CVE-2026-24610 Patchstack
4.3 Medium WishList Member X Plugin wishlist-member-x Broken Access Control ≤ 3.29.0 CVE-2026-24575 Patchstack
5.5 Medium Yoast SEO Premium Plugin wordpress-seo-premium Broken Access Control ≤ 26.6 Fixed in 26.7 CVE-2026-40722 Patchstack
6.5 Medium WPAMS Plugin apartment-management Broken Access Control Arbitrary Content Deletion < 49.5.3 Fixed in 49.5.3 CVE-2026-39433 Patchstack
6.5 Medium Genemy Theme genemy Broken Access Control ≤ 1.6.6 CVE-2025-69137 Patchstack
6.5 Medium Metro Magazine Theme metro-magazine Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-40809 Patchstack
6.5 Medium GetGenie Plugin getgenie Information Disclosure Sensitive Data Exposure No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-54197 Patchstack
6.5 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control No login needed ≤ 1.12.5 Fixed in 1.12.6 CVE-2026-54190 Patchstack
6.5 Medium Welcart e-Commerce Plugin usc-e-shop Broken Access Control No login needed ≤ 2.11.28 Fixed in 2.11.29 CVE-2026-49775 Patchstack
6.5 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting < 7.5.51.7212 Fixed in 7.5.51.7212 CVE-2026-49773 Patchstack
4.7 Medium WP Migrate Lite Plugin wp-migrate-db Cross-Site Request Forgery No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2026-49043 Patchstack
6.5 Medium XCloner Plugin xcloner-backup-and-restore Information Disclosure Sensitive Data Exposure No login needed ≤ 4.8.6 Fixed in 4.8.7 CVE-2026-48965 Patchstack
6.5 Medium JS Help Desk Plugin js-support-ticket Broken Access Control No login needed ≤ 3.0.9 Fixed in 3.1.0 CVE-2026-48887 Patchstack
6.5 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.5.2 Fixed in 2.5.3 CVE-2026-48880 Patchstack
6.5 Medium Visual Link Preview Plugin visual-link-preview Information Disclosure Sensitive Data Exposure ≤ 2.4.1 Fixed in 2.4.2 CVE-2026-48878 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.62 Fixed in 51.1.63 CVE-2026-48870 Patchstack
6.5 Medium Stripe Payments Plugin stripe-payments Other Bypass Vulnerability No login needed ≤ 2.0.98 Fixed in 2.0.99 CVE-2026-42752 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Authentication Bypass LMS plugin <= 2.1.8 - Broken Authentication No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2026-42743 Patchstack
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting ≤ 2.14.23 Fixed in 2.14.24 CVE-2026-42688 Patchstack
6.5 Medium Simple Membership Plugin simple-membership Cross-Site Scripting ≤ 4.7.2 Fixed in 4.7.3 CVE-2026-42663 Patchstack
6.5 Medium Event Tickets Plugin event-tickets Authentication Bypass Bypass Vulnerability No login needed ≤ 5.27.5 Fixed in 5.27.6.1 CVE-2026-42662 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Information Disclosure Sensitive Data Exposure ≤ 28.1.7 Fixed in 29.0.0 CVE-2026-42660 Patchstack
6.5 Medium Advanced Form Integration Plugin advanced-form-integration Broken Access Control ≤ 1.126.12 Fixed in 1.127.0 CVE-2026-42659 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Other Other Vulnerability Type No login needed ≤ 28.1.7 Fixed in 29.0.0 CVE-2026-42657 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 28.1.6 Fixed in 29.0.0 CVE-2026-42656 Patchstack
6.3 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 5.3.9 Fixed in 5.3.10 CVE-2026-42651 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Broken Access Control No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2026-42640 Patchstack
6.5 Medium WP Full Stripe Free Plugin wp-full-stripe-free Authentication Bypass Broken Authentication ≤ 8.4.1 Fixed in 8.4.2 CVE-2026-42378 Patchstack
6.5 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting ≤ 4.16.13 Fixed in 4.16.14 CVE-2026-41556 Patchstack
5.8 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Broken Authentication No login needed ≤ 1.38.0 Fixed in 1.38.1 CVE-2026-40799 Patchstack
6.5 Medium WPPizza Plugin wppizza Information Disclosure Sensitive Data Exposure ≤ 3.19.9 Fixed in 3.20 CVE-2026-40796 Patchstack
6.5 Medium Amelia Plugin ameliabooking Broken Access Control ≤ 2.2 Fixed in 2.2.1 CVE-2026-40795 Patchstack
6.5 Medium myCred Plugin mycred Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2026-40794 Patchstack
6.5 Medium Groundhogg Plugin groundhogg Broken Access Control < 4.4.1 Fixed in 4.4.1 CVE-2026-40793 Patchstack
6.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.1 Fixed in 4.3.0 CVE-2026-40792 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only