WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via 'download_csv' No login needed ≤ 1.4.7 CVE-2026-2599 Wordfence
9.1 Critical Login with Salesforce Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.0.2 CVE-2026-2418 WPScan
9.3 Critical WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem SQL Injection Easy Stripe & Paypal donations plugin <= 1.25 - SQL Injection No login needed ≤ 1.25 CVE-2026-28115 Patchstack
9.1 Critical WooCommerce License Manager Plugin fs-license-manager Arbitrary File Upload ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-28114 Patchstack
9.8 Critical Good Energy Theme goodenergy PHP Object Injection No login needed ≤ 1.7.7 CVE-2026-28105 Patchstack
9.8 Critical Pizza House Theme pizzahouse PHP Object Injection No login needed ≤ 1.4.0 CVE-2026-28074 Patchstack
9.8 Critical Healer - Doctor, Clinic & Medical Theme healer Local File Inclusion Doctor, Clinic & Medical WordPress Theme theme <= 1.0.0 - Local File Inclusion No login needed ≤ 1.0.0 CVE-2026-28043 Patchstack
9.0 Critical Widget Options Plugin widget-options Remote Code Execution ≤ 4.1.3 Fixed in 4.2.0 CVE-2026-27984 Patchstack
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
9.8 Critical Dentario Theme dentario PHP Object Injection No login needed ≤ 1.5 CVE-2026-27439 Patchstack
9.8 Critical Kingler Theme kingler PHP Object Injection No login needed ≤ 1.7 CVE-2026-27438 Patchstack
9.8 Critical Tennis Club Theme tennis-sportclub PHP Object Injection No login needed ≤ 1.2.3 CVE-2026-27437 Patchstack
9.8 Critical Sweet Date Theme sweetdate PHP Object Injection No login needed ≤ 4.0.1 Fixed in 4.0.1 CVE-2026-27417 Patchstack
9.8 Critical WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2026-27389 Patchstack
9.0 Critical W3 Total Cache Plugin w3-total-cache Remote Code Execution Arbitrary Code Execution No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-27384 Patchstack
9.9 Critical Charety Theme charety Arbitrary File Upload ≤ 2.0.2 Fixed in 2.0.2 CVE-2026-24960 Patchstack
9.1 Critical AI Engine Plugin ai-engine Arbitrary File Upload ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-23802 Patchstack
9.8 Critical Mounthood Theme mounthood PHP Object Injection No login needed ≤ 1.3.2 CVE-2026-22501 Patchstack
9.8 Critical Jardi Theme jardi PHP Object Injection No login needed ≤ 1.7.2 CVE-2026-22497 Patchstack
9.8 Critical Estate Plugin estate PHP Object Injection No login needed ≤ 1.3.4 CVE-2026-22475 Patchstack
9.8 Critical Equestrian Centre Theme equestrian-centre PHP Object Injection No login needed ≤ 1.5 CVE-2026-22474 Patchstack
9.8 Critical Solaris Theme solaris PHP Object Injection No login needed ≤ 2.5 CVE-2026-22454 Patchstack
9.8 Critical Pets Club Theme petclub PHP Object Injection No login needed ≤ 2.3 CVE-2026-22453 Patchstack
9.8 Critical Handyman Theme handyman-services PHP Object Injection No login needed ≤ 1.4.7 CVE-2026-22451 Patchstack
9.8 Critical Grand Wedding Theme grandwedding PHP Object Injection No login needed ≤ 3.1.11 Fixed in 3.1.11 CVE-2026-22417 Patchstack
9.9 Critical Builderall Builder Plugin builderall-cheetah-for-wp Remote Code Execution ≤ 3.0.1 CVE-2026-22390 Patchstack
9.3 Critical Riode Core Plugin riode-core SQL Injection No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2025-69338 Patchstack
9.9 Critical Nutrie Theme nutrie Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68555 Patchstack
9.9 Critical Keenarch Theme keenarch Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68554 Patchstack
9.9 Critical Lendiz Theme lendiz Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68553 Patchstack
9.8 Critical Classter Theme classter PHP Object Injection No login needed ≤ 2.5 CVE-2025-54001 Patchstack
9.8 Critical User Registration & Membership Plugin user-registration Privilege Escalation Unauthenticated Privilege Escalation via Membership Registration No login needed ≤ 5.1.2 CVE-2026-1492 Wordfence
9.8 Critical All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin login-with-azure Authentication Bypass No login needed ≤ 2.2.5 CVE-2026-2628 Wordfence
9.8 Critical Listee Theme listee Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.1.6 CVE-2025-12981 Wordfence
10.0 Critical ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor Plugin elementskit-lite Broken Access Control ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint No login needed < 3.7.9 Fixed in 3.7.9 CVE-2026-23693 VulnCheck
9.3 Critical Download Manager Addons for Elementor Plugin wpdm-elementor SQL Injection No login needed ≤ 1.3.0 Fixed in 2.0.0 CVE-2026-24956 Patchstack
9.8 Critical Applay - Shortcodes Plugin applay-shortcodes PHP Object Injection Shortcodes plugin <= 3.7 - PHP Object Injection No login needed ≤ 3.7 CVE-2026-22384 Patchstack
9.8 Critical Lorem Ipsum | Books & Media Store Theme lorem-ipsum-books-media-store PHP Object Injection No login needed ≤ 1.2.11 CVE-2025-69405 Patchstack
9.8 Critical Extreme Store Theme extremestore PHP Object Injection No login needed ≤ 1.5.10 CVE-2025-69404 Patchstack
9.9 Critical Bravis Addons Plugin bravis-addons Arbitrary File Upload ≤ 1.3.0 CVE-2025-69403 Patchstack
9.8 Critical Themesflat Elementor Plugin themesflat-elementor PHP Object Injection No login needed ≤ 1.0.1 CVE-2025-69382 Patchstack
9.8 Critical SevenHills Theme sevenhills PHP Object Injection No login needed ≤ 1.6.2 CVE-2025-69372 Patchstack
9.8 Critical KindlyCare Theme kindlycare PHP Object Injection No login needed ≤ 1.6.1 CVE-2025-69371 Patchstack
9.8 Critical Capella Theme capella PHP Object Injection No login needed ≤ 2.5.5 CVE-2025-69370 Patchstack
9.3 Critical Emerce Core Plugin emerce-core SQL Injection No login needed ≤ 1.8 CVE-2025-69366 Patchstack
9.3 Critical Uroan Core Plugin uroan-core SQL Injection No login needed ≤ 1.4.4 CVE-2025-69365 Patchstack
9.3 Critical Wolmart Core Plugin wolmart-core SQL Injection No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-69337 Patchstack
9.8 Critical Prestige Theme prestige PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.1 CVE-2025-69329 Patchstack
9.3 Critical Woodly Core Plugin woodly-core SQL Injection No login needed ≤ 1.4 CVE-2025-69310 Patchstack
9.3 Critical Saasplate Core Plugin saasplate-core SQL Injection No login needed ≤ 1.2.8 CVE-2025-69309 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only