WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,351–1,400 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Open User Map Plugin open-user-map Path Traversal Arbitrary File Download ≤ 1.4.16 Fixed in 1.4.17 CVE-2025-68002 Patchstack
6.5 Medium Testimonial Slider Plugin testimonial Broken Access Control ≤ 2.0.15 CVE-2025-68000 Patchstack
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-67993 Patchstack
6.5 Medium aDirectory Plugin adirectory Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67975 Patchstack
6.5 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.6.2 Fixed in 3.5.7.1 CVE-2025-67973 Patchstack
4.3 Medium Zoho ZeptoMail Plugin transmail Broken Access Control ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-67972 Patchstack
5.9 Medium Schedula Plugin schedula-smart-appointment-booking Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-67970 Patchstack
6.5 Medium UPI QR Code Payment Gateway for WooCommerce Plugin upi-qr-code-payment-for-woocommerce Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.6.1 CVE-2025-67969 Patchstack
6.5 Medium Optimize More! – Images Plugin optimize-more-images Broken Access Control Images plugin <= 1.1.3 - Broken Access Control No login needed ≤ 1.1.3 CVE-2025-67624 Patchstack
6.5 Medium Konte Theme konte Broken Access Control No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-67547 Patchstack
5.9 Medium Silencesoft RSS Reader Plugin external-rss-reader Cross-Site Scripting ≤ 0.6 CVE-2025-60183 Patchstack
6.5 Medium NewsMash Plugin newsmash Cross-Site Scripting ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-56208 Patchstack
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Information Disclosure Authenticated Sensitive Data Exposure ≤ 2.22.15 Fixed in 2.22.16 CVE-2024-54222 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2024-52387 Patchstack
6.5 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting ≤ 6.5.2 Fixed in 6.5.3 CVE-2024-51915 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.29.0 Fixed in 3.29.1 CVE-2024-50555 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 3.3.3 Fixed in 4.0.0 CVE-2024-50452 Patchstack
5.3 Medium SecuPress Free Plugin secupress Broken Access Control No login needed ≤ 2.2.5.3 Fixed in 2.3 CVE-2024-43228 Patchstack
5.3 Medium Shared Files Plugin shared-files Broken Access Control No login needed ≤ 1.7.19 Fixed in 1.7.20 CVE-2024-34438 Patchstack
6.1 Medium Survey Maker Plugin survey-maker Cross-Site Scripting WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in… No login needed 5.1.7.7 and prior CVE-2026-26370 jpcert
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.9.7.6 Fixed in 3.0 CVE-2026-27440 Patchstack
5.4 Medium DirectoryPress Plugin directorypress Broken Access Control ≤ 3.6.26 Fixed in 3.6.27 CVE-2026-27387 Patchstack
5.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Broken Access Control No login needed ≤ 6.19.8 Fixed in 6.19.9 CVE-2026-27368 Patchstack
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.38 Fixed in 1.8.39 CVE-2026-27360 Patchstack
5.3 Medium EduBlink Theme edublink Broken Access Control No login needed ≤ 2.0.7 CVE-2026-27328 Patchstack
4.3 Medium YayMail Plugin yaymail Broken Access Control WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-27327 Patchstack
6.5 Medium CoBlocks Plugin coblocks Cross-Site Scripting ≤ 3.1.16 Fixed in 3.1.17 CVE-2026-27094 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Broken Access Control ≤ 2.3.0 CVE-2026-27092 Patchstack
4.3 Medium Kenta Companion Plugin kenta-companion Cross-Site Request Forgery No login needed ≤ 1.3.3 CVE-2026-27090 Patchstack
6.5 Medium Shortcoder Plugin shortcoder Cross-Site Scripting ≤ 6.5.1 Fixed in 6.5.2 CVE-2026-27074 Patchstack
6.5 Medium Soledad Theme soledad Cross-Site Scripting ≤ 8.7.2 CVE-2026-27069 Patchstack
6.5 Medium Penci Recipe Plugin penci-recipe Cross-Site Scripting ≤ 4.1 CVE-2026-27059 Patchstack
6.5 Medium Penci Podcast Plugin penci-podcast Cross-Site Scripting ≤ 1.7 CVE-2026-27058 Patchstack
6.5 Medium Penci Filter Everything Plugin penci-filter-everything Cross-Site Scripting ≤ 1.7 CVE-2026-27057 Patchstack
4.3 Medium Penci AI SmartContent Creator Plugin penci-ai Broken Access Control ≤ 2.0 CVE-2026-27055 Patchstack
5.4 Medium RealPress Plugin realpress Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-27050 Patchstack
5.3 Medium NotificationX Plugin notificationx Broken Access Control No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2026-27042 Patchstack
5.4 Medium WZone Plugin woozone Broken Access Control ≤ 14.0.31 CVE-2026-25473 Patchstack
6.5 Medium Fusion Builder Plugin fusion-builder Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-25472 Patchstack
6.5 Medium Wpresidence Core Plugin wpresidence-core Cross-Site Scripting ≤ 5.4.0 CVE-2026-25463 Patchstack
4.3 Medium Sober Plugin sober Broken Access Control ≤ 3.5.12 CVE-2026-25459 Patchstack
6.5 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting ≤ 2025.10 Fixed in 2026.0 CVE-2026-25453 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.6.9 Fixed in 5.7.0 CVE-2026-25451 Patchstack
5.3 Medium LeadConnector Plugin leadconnector Broken Access Control No login needed ≤ 3.0.21 Fixed in 3.0.22 CVE-2026-25441 Patchstack
6.5 Medium Omnipress Plugin omnipress Cross-Site Scripting ≤ 1.6.7 CVE-2026-25432 Patchstack
4.4 Medium TS Poll Plugin poll-wp Server-Side Request Forgery ≤ 2.5.5 CVE-2026-25428 Patchstack
5.4 Medium Popularis Extra Plugin popularis-extra Cross-Site Request Forgery No login needed ≤ 1.2.10 CVE-2026-25422 Patchstack
4.3 Medium MailerLite Plugin official-mailerlite-sign-up-forms Broken Access Control ≤ 1.7.18 Fixed in 1.7.19 CVE-2026-25420 Patchstack
4.3 Medium UpsellWP Plugin checkout-upsell-and-order-bumps Broken Access Control ≤ 2.2.5 CVE-2026-25419 Patchstack
4.3 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.4.2 CVE-2026-25416 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only