WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,201–1,250 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-34898 Patchstack
7.5 High IDPay Payment Gateway for Woocommerce Plugin woo-idpay-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.5 CVE-2026-34891 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-34886 Patchstack
7.2 High AI Engine Plugin ai-engine Privilege Escalation ≤ 3.4.9 Fixed in 3.5.0 CVE-2026-27407 Patchstack
8.1 High Paid Videochat Turnkey Site Plugin ppv-live-webcams PHP Object Injection Deserialization of untrusted data No login needed ≤ 7.3.23 Fixed in 7.3.24 CVE-2026-27333 Patchstack
7.5 High WpTravelly Plugin tour-booking-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-27089 Patchstack
7.5 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-25425 Patchstack
8.5 High PowerPress Podcasting Plugin powerpress SQL Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-24637 Patchstack
7.1 High Redirection for Contact Form 7 Plugin wpcf7-redirect Cross-Site Scripting No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-23970 Patchstack
7.1 High Eli's WordCents adSense Widget with Analytics Plugin wordcents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.03.27 CVE-2025-68872 Patchstack
7.1 High Okay Toolkit Plugin okay-toolkit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-68851 Patchstack
7.1 High iRobots.txt SEO Plugin irobotstxt-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-68840 Patchstack
7.5 High Projectopia Plugin projectopia-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.25.2 CVE-2025-59133 Patchstack
7.5 High GetPaid Plugin invoicing Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.49 Fixed in 2.8.50 CVE-2026-49064 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
8.8 High Faust.js Plugin faustwp Authentication Bypass Broken Authentication ≤ 1.8.7 Fixed in 1.8.8 CVE-2026-49062 Patchstack
7.1 High Sliced Invoices Plugin sliced-invoices SQL Injection WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter 3.8.2 CVE-2019-25746 VulnCheck
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
8.2 High Answer My Question Plugin answer-my-question SQL Injection Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php No login needed 1.3 CVE-2016-20073 VulnCheck
8.2 High BBS e-Franchise Plugin bbs-e-franchise SQL Injection BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid No login needed 1.1.1 CVE-2016-20072 VulnCheck
8.2 High 404 Redirection Manager Plugin 404-redirection-manager SQL Injection WordPress 404 Redirection Manager Plugin 1.0 SQL Injection No login needed 1.0 CVE-2016-20071 VulnCheck
7.5 High WP Ticket Plugin wp-ticket SQL Injection Unauthenticated SQL Injection via WordPress Search 's' Parameter No login needed ≤ 6.0.4 CVE-2026-9848 Wordfence
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-42653 Patchstack
7.1 High WP Mail Log Plugin wp-mail-log Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.1.1 CVE-2023-33999 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
8.2 High KittyCatfish Plugin SQL Injection KittyCatfish 2.2 Plugin for WordPress SQL Injection No login needed 2.2 CVE-2017-20246 VulnCheck
8.2 High Wow Viral Signups Plugin mwp-viral-signup SQL Injection Wow Viral Signups 2.1 WordPress Plugin SQL Injection No login needed 2.1 CVE-2017-20245 VulnCheck
8.2 High Wow Forms Plugin mwp-forms SQL Injection Wow Forms WordPress Plugin 2.1 SQL Injection No login needed 2.1 CVE-2017-20244 VulnCheck
8.2 High Product Catalog 8 Plugin product-catalog-8 SQL Injection Product Catalog 8 1.2 Plugin WordPress SQL Injection No login needed 1.2.0 CVE-2016-20065 VulnCheck
7.1 High Single Personal Message Plugin simple-personal-message SQL Injection Single Personal Message 1.0.3 WordPress Plugin SQL Injection 1.0.3 CVE-2016-20063 VulnCheck
8.2 High Simply Poll Plugin simply-poll SQL Injection Simply Poll 1.4.1 Plugin for WordPress SQL Injection No login needed 1.4.1 CVE-2016-20062 VulnCheck
7.2 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Text No login needed ≤ 7.5.49.7212 CVE-2026-7556 Wordfence
8.2 High Google Review Slider Plugin wp-google-places-review-slider SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed 6.1 CVE-2019-25745 VulnCheck
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
8.8 High School Management Plugin school-management Privilege Escalation ≤ 93.2.0 CVE-2025-15656 Patchstack
7.6 High School Management Plugin school-management SQL Injection ≤ 93.2.0 CVE-2025-15655 Patchstack
7.1 High Prague Plugin prague-plugins Cross-Site Scripting No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-15654 Patchstack
7.5 High BookIt Plugin bookit Authentication Bypass Broken Authentication No login needed < 2.5.4.1 Fixed in 2.5.4.1 CVE-2026-40780 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
8.1 High Cookiteer Theme cookiteer Local File Inclusion No login needed ≤ 1.4.8 CVE-2025-68886 Patchstack
8.1 High Racquet Theme racquet Local File Inclusion No login needed ≤ 1.12.0 CVE-2025-69369 Patchstack
8.1 High Fermentio Theme fermentio Local File Inclusion No login needed ≤ 1.5.0 CVE-2025-58897 Patchstack
8.1 High Spin Theme spin Local File Inclusion No login needed ≤ 1.8 CVE-2025-58707 Patchstack
8.1 High Askka Theme askka PHP Object Injection No login needed ≤ 1.3.1 Fixed in 1.4 CVE-2026-39555 Patchstack
8.1 High WaveRide Theme waveride Local File Inclusion No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-39553 Patchstack
8.1 High Blueprint Theme blueprint Local File Inclusion No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-39552 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only