WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,901–8,950 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 179 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Logo Slider Plugin logo-slider-wp Cross-Site Scripting ≤ 5.1.1 CVE-2026-24626 Patchstack
5.3 Medium File Uploads Addon for WooCommerce Plugin woo-addon-uploads Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2026-24625 Patchstack
7.6 High Neoforum Plugin neoforum SQL Injection ≤ 1.0 CVE-2026-24624 Patchstack
7.1 High Neoforum Plugin neoforum Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2026-24623 Patchstack
5.4 Medium Suggestion Toolkit Plugin suggestion-toolkit Broken Access Control ≤ 5.0 CVE-2026-24622 Patchstack
5.9 Medium Terms descriptions Plugin terms-descriptions Cross-Site Scripting ≤ 3.4.9 Fixed in 3.4.10 CVE-2026-24621 Patchstack
5.9 Medium Landing Page Builder Plugin page-builder-add Cross-Site Scripting ≤ 1.5.3.4 Fixed in 1.5.3.5 CVE-2026-24620 Patchstack
5.3 Medium PopCash.Net Code Integration Tool Plugin popcashnet-code-integration-tool Broken Access Control No login needed ≤ 1.8 Fixed in 2.0 CVE-2026-24619 Patchstack
6.5 Medium Easy Modal Plugin easy-modal Cross-Site Scripting ≤ 2.1.0 CVE-2026-24617 Patchstack
6.5 Medium WP Popups Plugin wp-popups-lite Broken Access Control ≤ 2.2.0.5 Fixed in 2.2.0.6 CVE-2026-24616 Patchstack
5.3 Medium Cream Magazine Plugin cream-magazine Broken Access Control No login needed ≤ 2.1.10 CVE-2026-24615 Patchstack
5.9 Medium Flex QR Code Generator Plugin flex-qr-code-generator Cross-Site Scripting ≤ 1.2.10 CVE-2026-24614 Patchstack
5.3 Medium Ecwid Shopping Cart Plugin ecwid-shopping-cart Broken Access Control No login needed ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-24613 Patchstack
5.3 Medium Orchid Store Plugin orchid-store Broken Access Control No login needed ≤ 1.5.15 CVE-2026-24612 Patchstack
7.5 High Laurent Theme laurent Local File Inclusion ≤ 3.1 CVE-2026-24609 Patchstack
7.5 High Laurent Core Plugin laurent-core Local File Inclusion ≤ 2.4.1 CVE-2026-24608 Patchstack
5.3 Medium Travel Monster Plugin travel-monster Broken Access Control No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-24607 Patchstack
5.3 Medium Bayarcash WooCommerce Plugin bayarcash-wc Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-24606 Patchstack
4.3 Medium X Addons for Elementor Plugin x-addons-elementor Broken Access Control ≤ 1.0.23 CVE-2026-24605 Patchstack
5.3 Medium Simple GDPR Cookie Compliance Plugin simple-gdpr-cookie-compliance Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-24604 Patchstack
5.3 Medium Universal Google Adsense and Ads manager Plugin universal-google-adsense-and-ads-manager Broken Access Control No login needed ≤ 1.1.8 CVE-2026-24603 Patchstack
6.5 Medium Penci Pay Writer Plugin penci-pay-writer Cross-Site Scripting ≤ 1.5 CVE-2026-24601 Patchstack
6.5 Medium Penci Review Plugin penci-review Cross-Site Scripting ≤ 3.5 CVE-2026-24600 Patchstack
5.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2026-24599 Patchstack
4.3 Medium Multilanguage by BestWebSoft Plugin multilanguage Broken Access Control ≤ 1.5.2 CVE-2026-24598 Patchstack
4.3 Medium Related Posts Thumbnails Plugin related-posts-thumbnails Cross-Site Request Forgery No login needed ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-24596 Patchstack
5.4 Medium Zoho CRM Lead Magnet Plugin zoho-crm-forms Broken Access Control ≤ 1.8.1.9 CVE-2026-24595 Patchstack
5.9 Medium Livemesh Addons for WPBakery Page Builder Plugin addons-for-visual-composer Cross-Site Scripting ≤ 3.9.4 CVE-2026-24594 Patchstack
5.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Information Disclosure Sensitive Data Exposure No login needed ≤ 4.4.3 Fixed in 4.4.4 CVE-2026-24593 Patchstack
6.5 Medium Turn Yoast SEO FAQ Block to Accordion Plugin faq-schema-block-to-accordion Cross-Site Scripting ≤ 1.0.6 CVE-2026-24591 Patchstack
5.3 Medium Cargus Plugin cargus Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.8 Fixed in 1.5.9 CVE-2026-24589 Patchstack
4.3 Medium Smart Product Viewer Plugin smart-product-viewer Broken Access Control ≤ 1.5.4 CVE-2026-24588 Patchstack
5.4 Medium AJAX Hits Counter + Popular Posts Widget Plugin ajax-hits-counter Broken Access Control ≤ 0.10.210305 CVE-2026-24587 Patchstack
6.5 Medium Hyyan WooCommerce Polylang Integration Plugin woo-poly-integration Broken Access Control ≤ 1.5.0 CVE-2026-24585 Patchstack
5.9 Medium Tutor LMS BunnyNet Integration Plugin tutor-lms-bunnynet-integration Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2026-24584 Patchstack
5.3 Medium SumUp Payment Gateway For WooCommerce Plugin sumup-payment-gateway-for-woocommerce Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2026-24583 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control ≤ 2.9.5 Fixed in 2.9.6 CVE-2026-24581 Patchstack
4.3 Medium Ecwid Shopping Cart Plugin ecwid-shopping-cart Broken Access Control ≤ 7.0.5 Fixed in 7.0.6 CVE-2026-24580 Patchstack
4.3 Medium Ai Image Alt Text Generator for WP Plugin ai-image-alt-text-generator-for-wp Broken Access Control ≤ 1.1.9 CVE-2026-24579 Patchstack
4.3 Medium Admin login URL Change Plugin admin-login-url-change Broken Access Control ≤ 1.1.5 CVE-2026-24578 Patchstack
5.3 Medium Pie Register Plugin pie-register Broken Access Control No login needed ≤ 3.8.4.8 Fixed in 3.8.4.9 CVE-2026-24577 Patchstack
6.5 Medium UX Flat Plugin ux-flat Cross-Site Scripting ≤ 5.4.0 CVE-2026-24576 Patchstack
8.5 High Nelio Content Plugin nelio-content SQL Injection ≤ 4.2.0 Fixed in 4.2.1 CVE-2026-24572 Patchstack
4.3 Medium BOX NOW Delivery Plugin box-now-delivery Broken Access Control ≤ 3.0.2 Fixed in 3.2.0 CVE-2026-24571 Patchstack
5.4 Medium Edwiser Bridge Plugin edwiser-bridge Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-24570 Patchstack
4.3 Medium Media Library File Size Plugin media-library-file-size Broken Access Control ≤ 1.6.7 Fixed in 1.6.8 CVE-2026-24569 Patchstack
5.3 Medium WP Travel Plugin wp-travel Broken Access Control No login needed ≤ 11.1.0 Fixed in 11.1.1 CVE-2026-24568 Patchstack
4.3 Medium Anything Order by Terms Plugin anything-order-by-terms Broken Access Control ≤ 1.4.0 CVE-2026-24567 Patchstack
6.5 Medium iNET Webkit Plugin inet-webkit Broken Access Control ≤ 1.2.4 CVE-2026-24566 Patchstack
6.5 Medium B Accordion Plugin b-accordion Information Disclosure Sensitive Data Exposure ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-24565 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only