WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,301–1,350 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Broken Access Control Missing Authorization to Unauthenticated Arbitrary Subscription Deletion No login needed ≤ 4.11.1 CVE-2026-1781 Wordfence
4.3 Medium Rank Math SEO PRO Plugin seo-by-rank-math-pro Broken Access Control ≤ 3.0.95 CVE-2026-28080 Patchstack
4.7 Medium B2BKing Premium Plugin b2bking Open Redirect No login needed < 5.4.20 Fixed in 5.4.20 CVE-2026-28106 Patchstack
5.9 Medium Preferred Languages Plugin preferred-languages Cross-Site Scripting ≤ 2.2.2 Fixed in 2.3.0 CVE-2024-35644 Patchstack
6.5 Medium Site Suggest Plugin site-suggest Broken Access Control No login needed ≤ 1.3.9 CVE-2026-28104 Patchstack
4.9 Medium uListing Plugin ulisting Path Traversal Arbitrary File Download ≤ 2.2.0 CVE-2026-28078 Patchstack
6.3 Medium pixfort Core Plugin pixfort-core Broken Access Control ≤ 3.2.22 Fixed in 3.2.26 CVE-2026-28071 Patchstack
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Broken Access Control ≤ 3.21.1 Fixed in 3.21.2 CVE-2026-28038 Patchstack
6.4 Medium Ratatouille Plugin ratatouille Server-Side Request Forgery ≤ 1.2.6 CVE-2026-28036 Patchstack
5.4 Medium SiteGuard WP Plugin siteguard Authentication Bypass Captcha Bypass No login needed ≤ 1.7.9 Fixed in 1.7.10 CVE-2026-27411 Patchstack
6.5 Medium WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Broken Access Control No login needed ≤ 1.0.6 CVE-2026-27362 Patchstack
6.5 Medium WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Cross-Site Scripting ≤ 5.0 CVE-2026-27354 Patchstack
5.9 Medium inseri core Plugin inseri-core Broken Access Control No login needed ≤ 1.0.5 CVE-2026-27344 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2026-23799 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Information Disclosure Sensitive Data Exposure ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-23546 Patchstack
6.5 Medium WordPress CTA Plugin easy-sticky-sidebar Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-22459 Patchstack
6.5 Medium Theater Plugin theatre Cross-Site Scripting ≤ 0.19 Fixed in 0.19.1 CVE-2025-69343 Patchstack
5.8 Medium WP Booking System Plugin wp-booking-system Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.19.12 Fixed in 2.0.19.13 CVE-2025-68515 Patchstack
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API ≤ 1.12.3 CVE-2026-1236 Wordfence
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action Fields ≤ 13.4 CVE-2025-14040 Wordfence
5.3 Medium WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Content Injection No login needed ≤ 1.4.4 CVE-2026-28132 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
6.5 Medium Flatsome Plugin flatsome Cross-Site Scripting ≤ 3.20.5 Fixed in 3.20.6 CVE-2026-28083 Patchstack
5.3 Medium Simple Ajax Chat Plugin simple-ajax-chat Information Disclosure Sensitive Data Exposure No login needed ≤ 20251121 Fixed in 20260217 CVE-2026-3075 Patchstack
6.5 Medium Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download ≤ 6.1.15 Fixed in 6.1.16 CVE-2026-24953 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
6.5 Medium Subscribe2 Plugin subscribe2 Broken Access Control No login needed ≤ 10.44 Fixed in 10.45 CVE-2026-24944 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
6.7 Medium Booked Plugin booked Privilege Escalation Account Takeover ≤ 3.0.0 CVE-2026-22341 Patchstack
6.5 Medium Cliengo – Chatbot Plugin cliengo Broken Access Control Chatbot plugin <= 3.0.4 - Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-69388 Patchstack
6.5 Medium Cartify - WooCommerce Gutenberg Theme cartify Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion ≤ 1.3 CVE-2025-69385 Patchstack
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
6.5 Medium AhaChat Messenger Marketing Plugin ahachat-messenger-marketing Authentication Bypass Broken Authentication No login needed ≤ 1.1 CVE-2025-68895 Patchstack
5.9 Medium JobBoard Job listing Plugin job-board-light Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.8 CVE-2025-68855 Patchstack
6.5 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-68837 Patchstack
6.5 Medium Sendy Plugin sendy Broken Access Control No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-68564 Patchstack
6.5 Medium Checkout Gateway for IRIS Plugin checkout-gateway-iris Broken Access Control No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-68542 Patchstack
6.5 Medium PDF for WPForms Plugin pdf-for-wpforms Broken Access Control ≤ 6.3.0 Fixed in 6.3.1 CVE-2025-68534 Patchstack
6.5 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.16.8 Fixed in 2.16.9 CVE-2025-68514 Patchstack
6.5 Medium Leadpages Plugin leadpages Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-68050 Patchstack
6.5 Medium Travelpayouts Plugin travelpayouts Broken Access Control ≤ 1.2.2 CVE-2025-68042 Patchstack
6.5 Medium Advanced WC Analytics Plugin advance-wc-analytics Broken Access Control Settings Change No login needed ≤ 3.19.0 Fixed in 4.0.0 CVE-2025-68032 Patchstack
6.5 Medium GA4WP: Google Analytics Plugin ga-for-wp Broken Access Control No login needed ≤ 2.10.0 CVE-2025-68028 Patchstack
6.5 Medium LC Wizard Plugin ghl-wizard Broken Access Control Settings Change No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-68026 Patchstack
6.5 Medium Addonify Floating Cart For WooCommerce Plugin addonify-floating-cart Broken Access Control No login needed ≤ 1.2.17 CVE-2025-68025 Patchstack
6.5 Medium Addonify – WooCommerce Wishlist Plugin addonify-wishlist Broken Access Control WooCommerce Wishlist plugin <= 2.0.15 - Settings Change No login needed ≤ 2.0.15 Fixed in 2.0.16 CVE-2025-68024 Patchstack
6.5 Medium Addonify – Compare Products For WooCommerce Plugin addonify-compare-products Broken Access Control Compare Products For WooCommerce plugin <= 1.1.17 - Settings Change No login needed ≤ 1.1.17 Fixed in 1.1.18 CVE-2025-68023 Patchstack
6.5 Medium ConveyThis Plugin conveythis-translate Broken Access Control No login needed ≤ 269.9 CVE-2025-68021 Patchstack
6.5 Medium Easy Hotel Booking Plugin easy-hotel Broken Access Control ≤ 1.9.2 CVE-2025-68005 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only