WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,251–1,300 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium App Landing Page Plugin app-landing-page Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-32381 Patchstack
5.3 Medium Numinous Plugin numinous Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-32380 Patchstack
5.3 Medium Rara Academic Plugin rara-academic Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-32379 Patchstack
5.3 Medium Book Landing Page Plugin book-landing-page Broken Access Control No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2026-32378 Patchstack
5.3 Medium Pranayama Yoga Plugin pranayama-yoga Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-32377 Patchstack
5.3 Medium Kalon Plugin kalon Broken Access Control No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32376 Patchstack
5.3 Medium Travel Diaries Plugin travel-diaries Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32375 Patchstack
5.3 Medium The Minimal Plugin the-minimal Broken Access Control No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32374 Patchstack
5.4 Medium SMS Alert Order Notifications Plugin sms-alert Broken Access Control ≤ 3.9.0 Fixed in 3.9.1 CVE-2026-32373 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
5.3 Medium Elegant Pink Plugin elegant-pink Broken Access Control No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-32371 Patchstack
5.3 Medium Influencer Plugin influencer Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-32370 Patchstack
5.3 Medium WPLifeCycle Plugin free-php-version-info Broken Access Control No login needed ≤ 3.3.1 Fixed in 4.0 CVE-2026-32363 Patchstack
5.3 Medium WP Sessions Time Monitoring Full Automatic Plugin activitytime Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2026-32362 Patchstack
6.5 Medium Editorial Calendar Plugin editorial-calendar Cross-Site Scripting ≤ 3.9.0 Fixed in 3.9.1 CVE-2026-32361 Patchstack
5.9 Medium Rich Showcase for Google Reviews Plugin widget-google-reviews Cross-Site Scripting ≤ 6.9.4.3 Fixed in 6.9.4.4 CVE-2026-32360 Patchstack
6.5 Medium Icon List Block Plugin icon-list-block Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-32359 Patchstack
6.4 Medium Simple Blog Card Plugin simple-blog-card Server-Side Request Forgery ≤ 2.37 Fixed in 2.38 CVE-2026-32357 Patchstack
6.5 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-32356 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.1.9 Fixed in 5.1.9 CVE-2026-32354 Patchstack
6.4 Medium MailerPress Plugin mailerpress Server-Side Request Forgery ≤ 1.4.2 Fixed in 1.5.0 CVE-2026-32353 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
5.9 Medium PowerPress Podcasting Plugin powerpress Cross-Site Scripting ≤ 11.15.13 Fixed in 11.15.14 CVE-2026-32351 Patchstack
5.3 Medium Chocolate House Plugin chocolate-house Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-32350 Patchstack
4.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Server-Side Request Forgery ≤ 2.4.7 Fixed in 2.4.8 CVE-2026-32349 Patchstack
5.3 Medium MAS Videos Plugin masvideos Broken Access Control No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-32348 Patchstack
5.3 Medium Restaurant and Cafe Plugin restaurant-and-cafe Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32347 Patchstack
5.3 Medium Travel Agency Plugin travel-agency Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-32346 Patchstack
5.3 Medium Perfect Portfolio Plugin perfect-portfolio Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32345 Patchstack
4.3 Medium Corpiva Plugin corpiva Cross-Site Request Forgery No login needed ≤ 1.0.96 Fixed in 1.0.97 CVE-2026-32344 Patchstack
4.3 Medium Easy Table of Contents Plugin easy-table-of-contents Cross-Site Request Forgery No login needed ≤ 2.0.80 Fixed in 2.0.81 CVE-2026-32343 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.1.2 Fixed in 6.7.1.3 CVE-2026-32342 Patchstack
5.3 Medium Benevolent Plugin benevolent Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2026-32341 Patchstack
5.3 Medium Business One Page Plugin business-one-page Broken Access Control No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-32340 Patchstack
5.3 Medium Bakes And Cakes Plugin bakes-and-cakes Broken Access Control No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32339 Patchstack
5.3 Medium Construction Landing Page Plugin construction-landing-page Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-32338 Patchstack
5.3 Medium Preschool and Kindergarten Plugin preschool-and-kindergarten Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32337 Patchstack
5.3 Medium Rara Business Plugin rara-business Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-32336 Patchstack
5.3 Medium The Conference Plugin the-conference Broken Access Control No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-32335 Patchstack
5.3 Medium JobScout Plugin jobscout Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-32334 Patchstack
5.3 Medium Easy Form Plugin easy-form Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.8.0 CVE-2026-32332 Patchstack
5.4 Medium Textmetrics Plugin webtexttool Broken Access Control ≤ 3.6.4 Fixed in 3.6.5 CVE-2026-32331 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Request Forgery No login needed ≤ 1.8.37 Fixed in 1.8.38 CVE-2026-32330 Patchstack
5.3 Medium Advanced Related Posts Plugin advanced-related-posts Broken Access Control No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-32329 Patchstack
5.4 Medium Lemmony Plugin lemmony Cross-Site Request Forgery No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2026-32328 Patchstack
4.3 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Broken Access Control ≤ 4.7.1 Fixed in 4.7.1.1 CVE-2026-31919 Patchstack
6.5 Medium immonex Kickstart Plugin immonex-kickstart Cross-Site Scripting ≤ 1.13.0 Fixed in 1.13.4 CVE-2026-31918 Patchstack
5.3 Medium Latest Post Shortcode Plugin latest-post-shortcode Broken Access Control No login needed ≤ 14.2.1 Fixed in 14.2.2 CVE-2026-31916 Patchstack
5.3 Medium Flatsome Plugin flatsome Broken Access Control No login needed ≤ 3.19.6 Fixed in 3.19.7 CVE-2026-31915 Patchstack
4.3 Medium WordPress Core Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API 6.9 – 6.9.1 CVE-2026-3906 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only