WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 751–800 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2026-57383 Patchstack
7.1 High Simple File List Plugin simple-file-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3.8 Fixed in 6.3.9 CVE-2026-57382 Patchstack
7.1 High PropertyHive Plugin propertyhive Cross-Site Scripting No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2026-57381 Patchstack
7.1 High Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting No login needed ≤ 5.1 Fixed in 5.2 CVE-2026-57380 Patchstack
7.1 High FormyChat Plugin social-contact-form Cross-Site Scripting No login needed ≤ 2.15.3 Fixed in 2.15.4 CVE-2026-57379 Patchstack
7.5 High Advanced Forms Plugin advanced-forms Broken Access Control No login needed ≤ 1.9.3.7 Fixed in 1.9.3.8 CVE-2026-57378 Patchstack
7.1 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-57376 Patchstack
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.8 High WPJAM Basic Plugin wpjam-basic PHP Object Injection ≤ 7.0 Fixed in 7.0.1 CVE-2026-57371 Patchstack
7.1 High Themify Builder Plugin themify-builder Cross-Site Scripting No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2026-57369 Patchstack
7.1 High Jobmonster Theme noo-jobmonster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.5 Fixed in 4.8.5.1 CVE-2026-57368 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2026-57363 Patchstack
8.1 High SureCart Plugin surecart Privilege Escalation Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook No login needed ≤ 4.2.3 CVE-2026-7655 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms Price Manipulation Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation No login needed ≤ 2.2.1 CVE-2026-15288 Wordfence
7.5 High AR Plugin ar-for-wordpress Path Traversal Unauthenticated Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14327 Wordfence
7.1 High Slider Revolution Plugin revslider Cross-Site Scripting No login needed 7.0.0 – 7.0.16 Fixed in 7.1.0 CVE-2026-57678 Patchstack
8.8 High Themify Popup Plugin themify-popup PHP Object Injection ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-56037 Patchstack
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.0 CVE-2026-57765 Patchstack
7.1 High SEOWP Theme seowp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.12.2 CVE-2026-57761 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
7.1 High Permalink Manager for WooCommerce Plugin permalink-manager-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.8.2 CVE-2026-57758 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.5 High nicen-localize-image Plugin nicen-localize-image SQL Injection ≤ 1.4.9 CVE-2026-57756 Patchstack
8.5 High iNET Webkit Plugin inet-webkit SQL Injection 1.2.4 CVE-2026-57752 Patchstack
8.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2026-57751 Patchstack
7.5 High SportsPress Pro Plugin sportspress-pro Local File Inclusion ≤ 2.7.29 CVE-2026-57749 Patchstack
7.5 High Shopify Plugin shopify-plugin Local File Inclusion ≤ 1.0.0 CVE-2026-57748 Patchstack
7.1 High Booked Plugin booked Broken Access Control ≤ 3.0.0 CVE-2026-57746 Patchstack
8.2 High POS Entegratör Plugin pos-entegrator Broken Access Control No login needed ≤ 3.7.103 Fixed in 3.8.0 CVE-2026-57688 Patchstack
8.5 High Custom Field Template Plugin custom-field-template SQL Injection ≤ 2.7.8 Fixed in 2.8 CVE-2026-57687 Patchstack
7.1 High WowAddons Plugin product-addons Cross-Site Scripting No login needed ≤ 1.6.14 Fixed in 1.6.15 CVE-2026-57686 Patchstack
7.1 High Simple Link Directory Plugin qc-simple-link-directory Cross-Site Scripting No login needed ≤ 15.0.5 Fixed in 15.0.6 CVE-2026-57682 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.2.02.004 Fixed in 9.2.03.001 CVE-2026-57675 Patchstack
7.1 High Timetics Plugin timetics Cross-Site Scripting No login needed ≤ 1.0.58 Fixed in 1.0.59 CVE-2026-57674 Patchstack
7.1 High Optimole Plugin optimole-wp Cross-Site Scripting No login needed ≤ 4.2.7 Fixed in 4.2.8 CVE-2026-57673 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.1 Fixed in 6.5.1.2 CVE-2026-57672 Patchstack
7.1 High perfmatters Plugin perfmatters Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2026-57671 Patchstack
7.1 High Google Maps CP Plugin codepeople-post-map Cross-Site Scripting No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-57670 Patchstack
7.1 High Modula - PRO Plugin modula Cross-Site Scripting PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) No login needed ≤ 2.10.8 Fixed in 2.10.9 CVE-2026-57426 Patchstack
7.1 High WPAdverts Plugin wpadverts Cross-Site Scripting No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-57366 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.3.2 Fixed in 8.3.3 CVE-2026-57362 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.2.5 Fixed in 5.2.2.6 CVE-2026-57361 Patchstack
7.1 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting No login needed ≤ 3.5.4 Fixed in 3.5.5 CVE-2026-57360 Patchstack
7.1 High ReviewX Plugin reviewx Cross-Site Scripting No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2026-57359 Patchstack
7.1 High Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.9 Fixed in 4.3.10 CVE-2026-57358 Patchstack
7.1 High Search Atlas SEO Plugin metasync Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2026-57357 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.19 Fixed in 1.9.20 CVE-2026-57356 Patchstack
7.1 High HandL UTM Grabber Plugin handl-utm-grabber Cross-Site Scripting No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2026-57351 Patchstack
7.1 High WP Debugging Plugin wp-debugging Cross-Site Scripting No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2026-57350 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only