WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 901–950 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.2 Fixed in 1.53.2 CVE-2026-45210 Patchstack
6.1 Medium Tm – WordPress Redirection Plugin tm-wordpress-redirection Cross-Site Request Forgery WordPress Redirection <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2026-7561 Wordfence
6.4 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting WordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL 1.4.2 CVE-2021-47951 VulnCheck
5.4 Medium Payments Plugin GetPaid Plugin invoicing Content Injection WordPress GetPaid Plugin 2.4.6 HTML Injection via Help Text 2.4.6 CVE-2021-47948 VulnCheck
6.4 Medium Filterable Portfolio Gallery Plugin fg-gallery Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS 1.0 CVE-2021-47929 VulnCheck
6.4 Medium WP Symposium Pro Plugin wp-symposium-pro Cross-Site Scripting WordPress Plugin WP Symposium Pro 2021.10 Stored XSS via wps_admin_forum_add_name 2021.10 CVE-2021-47927 VulnCheck
6.4 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Scripting WordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price 5.8.2 CVE-2021-47924 VulnCheck
6.4 Medium Slider by Soliloquy Plugin soliloquy-lite Cross-Site Scripting WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS 2.6.2 CVE-2021-47922 VulnCheck
6.4 Medium AccessPress Social Icons Plugin accesspress-social-icons Cross-Site Scripting WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS 1.8.2 CVE-2021-47910 VulnCheck
5.4 Medium WordPress Plugin AAWP Plugin Cross-Site Scripting WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter 3.16 CVE-2022-50970 VulnCheck
6.4 Medium IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Scripting WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS 2.26.7 CVE-2022-50961 VulnCheck
6.1 Medium International Sms For Contact Form Plugin cf7-international-sms-integration Cross-Site Scripting WordPress International Sms Contact Form 7 Integration 1.2 XSS No login needed 1.2 CVE-2022-50960 VulnCheck
6.1 Medium Contact Form Builder Plugin contact-forms-builder Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed 1.6.1 CVE-2022-50959 VulnCheck
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php No login needed 9.1 CVE-2022-50958 VulnCheck
6.2 Medium amministrazione-aperta Plugin amministrazione-aperta Path Traversal WordPress Plugin amministrazione-aperta 3.7.3 Local File Read No login needed 3.7.3 CVE-2022-50956 VulnCheck
4.3 Medium Curtain Plugin curtain Cross-Site Request Forgery WordPress Plugin Curtain 1.0.2 Cross-site Request Forgery 1.0.2 CVE-2022-50955 VulnCheck
6.2 Medium cab-fare-calculator Plugin cab-fare-calculator Local File Inclusion WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion No login needed 1.0.3 CVE-2022-50954 VulnCheck
6.4 Medium Videos sync PDF Plugin Cross-Site Scripting WordPress Plugin Videos sync PDF 1.7.4 Stored XSS 1.7.4 CVE-2022-50949 VulnCheck
6.4 Medium Testimonial Slider and Showcase Plugin testimonial-slider-and-showcase Cross-Site Scripting WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS 2.2.6 CVE-2022-50947 VulnCheck
6.4 Medium Netroics Blog Posts Grid Plugin netroics-blog-posts-grid Cross-Site Scripting WordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS 1.0 CVE-2022-50946 VulnCheck
6.4 Medium E2Pdf – Export Pdf Tool Plugin e2pdf Cross-Site Scripting Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.32.17 CVE-2026-7650 Wordfence
4.3 Medium BEAR Plugin woo-bulk-editor Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-27415 Patchstack
5.3 Medium PDF Poster Plugin pdf-poster Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.5.0 CVE-2026-27416 Patchstack
5.9 Medium WEN Logo Slider Plugin wen-logo-slider Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5 CVE-2025-62127 Patchstack
5.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control No login needed < 5.6.8 Fixed in 5.6.8 CVE-2025-66105 Patchstack
5.4 Medium WPGraphQL Plugin wp-graphql Cross-Site Request Forgery No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-68604 Patchstack
5.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Information Disclosure Sensitive Data Exposure No login needed ≤ 3.20.8 Fixed in 3.21.0 CVE-2026-25468 Patchstack
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed < 1.7.1053 Fixed in 1.7.1053 CVE-2026-25436 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting < 1.7.1053 Fixed in 1.7.1053 CVE-2026-27421 Patchstack
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Server-Side Request Forgery Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl' ≤ 3.5.3 CVE-2026-2948 Wordfence
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Cross-Site Scripting Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG' ≤ 3.5.3 CVE-2026-2868 Wordfence
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.19.22 Fixed in 2.19.23 CVE-2026-42648 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.11.0 Fixed in 1.12.0 CVE-2026-42645 Patchstack
5.3 Medium BetterDocs Plugin betterdocs Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-42644 Patchstack
5.9 Medium Image Widget Plugin image-widget Cross-Site Scripting ≤ 4.4.11 Fixed in 4.4.12 CVE-2026-42643 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42642 Patchstack
5.4 Medium Share This Image Plugin share-this-image Server-Side Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-42641 Patchstack
6.5 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-42412 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-42410 Patchstack
6.5 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting ≤ 3.3 Fixed in 3.4 CVE-2025-62110 Patchstack
4.3 Medium ACF Galerie 4 Plugin acf-galerie-4 Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-62104 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed < 7.13.2 Fixed in 7.13.2 CVE-2025-58922 Patchstack
4.7 Medium wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin Cross-Site Scripting WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import No login needed ≤ 6.5.0.4 CVE-2026-5721 Wordfence
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium YouTube Showcase Plugin youtube-showcase Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-15636 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.6.0 CVE-2025-15635 Patchstack
4.3 Medium Userpro Plugin userpro Cross-Site Request Forgery No login needed ≤ 5.1.11 Fixed in 5.1.11 CVE-2025-53444 Patchstack
4.3 Medium MyRewards Plugin woorewards Broken Access Control ≤ 5.7.3 Fixed in 5.7.4 CVE-2026-40786 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only