WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 316 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin Broken Access Control PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification No login needed ≤ 5.0.5 CVE-2026-0718 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
7.5 High Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Local File Inclusion ≤ <= 3.5.1 Fixed in 3.5.2 CVE-2026-32537 Patchstack
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting ≤ 5.9.8.1 Fixed in 5.9.8.2 CVE-2026-25417 Patchstack
6.5 Medium The Grid Plugin the-grid Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24370 Patchstack
7.1 High The Grid Plugin the-grid Broken Access Control ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24369 Patchstack
7.5 High JetEngine Plugin jet-engine SQL Injection Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter No login needed ≤ 3.8.6.1 CVE-2026-4662 Wordfence
5.3 Medium Filter & Grids Plugin ymc-smart-filter Broken Access Control No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-32397 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery Cross-Site Request Forgery to Group Membership Request Approval/Denial No login needed ≤ 5.9.8.2 CVE-2026-2494 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion ≤ 5.9.8.1 CVE-2026-2488 Wordfence
8.1 High Gridiron Theme gridiron Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28012 Patchstack
4.3 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control ≤ 3.6.10 Fixed in 3.6.11 CVE-2026-25375 Patchstack
4.3 Medium Modula Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing ≤ 2.13.6 CVE-2026-1254 Wordfence
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
6.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Cross-Site Scripting for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode ≤ 3.7.11 CVE-2026-0559 Wordfence
5.3 Medium WPZOOM Addons for Elementor – Starter Templates & Widgets Plugin wpzoom-elementor-addons Broken Access Control Starter Templates & Widgets <= 1.3.2 - Unauthenticated Protected Post Exposure via ajax_post_grid_load_more No login needed ≤ 1.3.2 CVE-2026-2295 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid ≤ 5.5.3 CVE-2025-13463 Wordfence
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification No login needed ≤ 5.9.7.2 CVE-2026-1271 Wordfence
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension ≤ 5.9.7.2 CVE-2025-13416 Wordfence
4.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control ≤ 2.13.6 Fixed in 2.13.7 CVE-2026-24939 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-24389 Patchstack
5.3 Medium The Grid Plugin the-grid Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24368 Patchstack
5.9 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting ≤ 2.13.4 Fixed in 2.13.5 CVE-2026-23976 Patchstack
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management ≤ 3.6.9 CVE-2025-15466 Wordfence
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Broken Access Control ≤ 1.27.9 Fixed in 1.27.10 CVE-2025-69345 Patchstack
7.1 High Content Grid Slider Plugin content-grid-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-68879 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.3.23 CVE-2025-68605 Patchstack
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting ≤ 3.6.8 CVE-2025-13693 Wordfence
7.5 High Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin ultimate-post Broken Access Control PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 5.0.3 CVE-2025-12980 Wordfence
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Gallery Management ≤ 3.6.7 CVE-2025-14455 Wordfence
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
6.5 Medium Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Cross-Site Scripting ≤ 3.3.4 Fixed in 3.3.5 CVE-2025-67912 Patchstack
5.4 Medium Grider for Elementor Plugin grider-elementor Broken Access Control ≤ 1.0.8 CVE-2025-66161 Patchstack
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification ≤ 2.13.3 CVE-2025-14003 Wordfence
5.9 Medium Filter & Grids Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.2.0 CVE-2025-10289 Wordfence
6.5 Medium Image Gallery – Photo Grid & Video Gallery (Modula) Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing ≤ 2.13.3 CVE-2025-13891 Wordfence
4.3 Medium Custom Layouts – Post + Product grids made easy Plugin custom-layouts Broken Access Control Post + Product grids made easy plugin <= 1.4.12 - Broken Access Control ≤ 1.4.12 Fixed in 1.5.0 CVE-2025-62996 Patchstack
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence
7.2 High Modula Plugin modula-best-grid-gallery Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion 2.13.1 – 2.13.2 CVE-2025-13645 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Arbitrary File Deletion Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move ≤ 2.12.28 CVE-2025-12494 Wordfence
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-62924 Patchstack
9.8 Critical TF Woo Product Grid Addon For Elementor Plugin tf-woo-product-grid PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.0.1 CVE-2025-59007 Patchstack
7.1 High Grid Plus Plugin grid-plus Cross-Site Scripting No login needed ≤ 3.3 CVE-2025-53352 Patchstack
6.4 Medium Cinza Grid Plugin cinza-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Skin Content Field ≤ 1.2.1 CVE-2025-11824 Wordfence
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.9.5.7 Fixed in 5.9.5.8 CVE-2025-4957 Patchstack
5.9 Medium Advance Portfolio Grid Plugin advance-portfolio-grid Cross-Site Scripting ≤ 1.07.6 Fixed in 1.07.7 CVE-2025-57982 Patchstack
7.1 High Grid Plugin grid Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-58657 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only