WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,301–8,350 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 167 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High bbpress Simple Advert Units Plugin bbpress-simple-advert-units Cross-Site Scripting No login needed ≤ 0.41 CVE-2025-53228 Patchstack
7.6 High AIO WP Builder Plugin all-in-one-wp-builder Broken Access Control ≤ 2.0.2 CVE-2025-53217 Patchstack
7.7 High Inpersttion For Plugin err-our-team Remote Code Execution Arbitrary Code Execution ≤ 1.0 CVE-2025-52744 Patchstack
6.5 Medium NewsMash Plugin newsmash Cross-Site Scripting ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-56208 Patchstack
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Information Disclosure Authenticated Sensitive Data Exposure ≤ 2.22.15 Fixed in 2.22.16 CVE-2024-54222 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2024-52387 Patchstack
6.5 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting ≤ 6.5.2 Fixed in 6.5.3 CVE-2024-51915 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.29.0 Fixed in 3.29.1 CVE-2024-50555 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 3.3.3 Fixed in 4.0.0 CVE-2024-50452 Patchstack
5.3 Medium SecuPress Free Plugin secupress Broken Access Control No login needed ≤ 2.2.5.3 Fixed in 2.3 CVE-2024-43228 Patchstack
5.3 Medium Shared Files Plugin shared-files Broken Access Control No login needed ≤ 1.7.19 Fixed in 1.7.20 CVE-2024-34438 Patchstack
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' ≤ 2.1.1 CVE-2026-2486 Wordfence
6.1 Medium Survey Maker Plugin survey-maker Cross-Site Scripting WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in… No login needed 5.1.7.7 and prior CVE-2026-26370 jpcert
6.4 Medium Quiz Maker Plugin quiz-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.7.1.7 CVE-2026-2384 Wordfence
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.9.7.6 Fixed in 3.0 CVE-2026-27440 Patchstack
5.4 Medium DirectoryPress Plugin directorypress Broken Access Control ≤ 3.6.26 Fixed in 3.6.27 CVE-2026-27387 Patchstack
5.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Broken Access Control No login needed ≤ 6.19.8 Fixed in 6.19.9 CVE-2026-27368 Patchstack
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.38 Fixed in 1.8.39 CVE-2026-27360 Patchstack
7.5 High Airtifact Theme airtifact Local File Inclusion ≤ 1.2.91 CVE-2026-27343 Patchstack
5.3 Medium EduBlink Theme edublink Broken Access Control No login needed ≤ 2.0.7 CVE-2026-27328 Patchstack
4.3 Medium YayMail Plugin yaymail Broken Access Control WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-27327 Patchstack
7.5 High Product Table and List Builder for WooCommerce Lite Plugin wc-product-table-lite SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed ≤ 4.6.2 CVE-2026-2232 Wordfence
7.5 High wpForo Forum Plugin wpforo SQL Injection Unauthenticated Time-Based SQL Injection No login needed ≤ 2.4.14 CVE-2026-1581 Wordfence
6.4 Medium Dealia Plugin dealia-request-a-quote Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block Attributes ≤ 1.0.8 CVE-2026-2718 Wordfence
5.3 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure No login needed 4.0 – 5.10 CVE-2026-1219 Wordfence
4.4 Medium Client Testimonial Slider Plugin wp-client-testimonial Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Testimonial Heading' Setting ≤ 2.0 CVE-2026-2716 Wordfence
6.5 Medium Simple Membership Plugin simple-membership Broken Access Control Unauthenticated Improper Handling of Missing Values No login needed ≤ 4.7.0 CVE-2026-1461 Wordfence
6.5 Medium CoBlocks Plugin coblocks Cross-Site Scripting ≤ 3.1.16 Fixed in 3.1.17 CVE-2026-27094 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Broken Access Control ≤ 2.3.0 CVE-2026-27092 Patchstack
4.3 Medium Kenta Companion Plugin kenta-companion Cross-Site Request Forgery No login needed ≤ 1.3.3 CVE-2026-27090 Patchstack
6.5 Medium Shortcoder Plugin shortcoder Cross-Site Scripting ≤ 6.5.1 Fixed in 6.5.2 CVE-2026-27074 Patchstack
6.5 Medium Soledad Theme soledad Cross-Site Scripting ≤ 8.7.2 CVE-2026-27069 Patchstack
6.5 Medium Penci Recipe Plugin penci-recipe Cross-Site Scripting ≤ 4.1 CVE-2026-27059 Patchstack
6.5 Medium Penci Podcast Plugin penci-podcast Cross-Site Scripting ≤ 1.7 CVE-2026-27058 Patchstack
6.5 Medium Penci Filter Everything Plugin penci-filter-everything Cross-Site Scripting ≤ 1.7 CVE-2026-27057 Patchstack
4.3 Medium Penci AI SmartContent Creator Plugin penci-ai Broken Access Control ≤ 2.0 CVE-2026-27055 Patchstack
7.5 High Sales Countdown Timer for WooCommerce and Plugin sctv-sales-countdown-timer Local File Inclusion ≤ 1.1.9 Fixed in 1.1.9 CVE-2026-27052 Patchstack
5.4 Medium RealPress Plugin realpress Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-27050 Patchstack
5.3 Medium NotificationX Plugin notificationx Broken Access Control No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2026-27042 Patchstack
5.4 Medium WZone Plugin woozone Broken Access Control ≤ 14.0.31 CVE-2026-25473 Patchstack
6.5 Medium Fusion Builder Plugin fusion-builder Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-25472 Patchstack
6.5 Medium Wpresidence Core Plugin wpresidence-core Cross-Site Scripting ≤ 5.4.0 CVE-2026-25463 Patchstack
4.3 Medium Sober Plugin sober Broken Access Control ≤ 3.5.12 CVE-2026-25459 Patchstack
6.5 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting ≤ 2025.10 Fixed in 2026.0 CVE-2026-25453 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.6.9 Fixed in 5.7.0 CVE-2026-25451 Patchstack
5.3 Medium LeadConnector Plugin leadconnector Broken Access Control No login needed ≤ 3.0.21 Fixed in 3.0.22 CVE-2026-25441 Patchstack
6.5 Medium Omnipress Plugin omnipress Cross-Site Scripting ≤ 1.6.7 CVE-2026-25432 Patchstack
4.4 Medium TS Poll Plugin poll-wp Server-Side Request Forgery ≤ 2.5.5 CVE-2026-25428 Patchstack
3.8 Low Real 3D FlipBook Plugin real3d-flipbook-lite Broken Access Control ≤ 4.19.1 Fixed in 4.19.2 CVE-2026-25423 Patchstack
5.4 Medium Popularis Extra Plugin popularis-extra Cross-Site Request Forgery No login needed ≤ 1.2.10 CVE-2026-25422 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only