WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,351–1,400 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Aqua Theme aqua Local File Inclusion ≤ 5.1.2 CVE-2026-57789 Patchstack
7.5 High Aalto Theme aalto Local File Inclusion ≤ 1.8 CVE-2026-57788 Patchstack
8.5 High CWS SVGicons Plugin cws-svgicons SQL Injection ≤ 1.5.5 CVE-2026-57787 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Broken Authentication No login needed ≤ 1.7.08 CVE-2026-57786 Patchstack
7.6 High Advanced Shipment Tracking for WooCommerce Plugin woo-advanced-shipment-tracking SQL Injection ≤ 4.0 Fixed in 4.0.1 CVE-2026-57773 Patchstack
8.5 High WP Inventory Manager Plugin wp-inventory-manager SQL Injection ≤ 2.4.0 CVE-2026-57772 Patchstack
8.5 High GD Rating System Plugin gd-rating-system SQL Injection ≤ 3.7 CVE-2026-57771 Patchstack
8.2 High Houzez Login Register Plugin houzez-login-register Privilege Escalation No login needed ≤ 3.3.3 CVE-2026-57768 Patchstack
7.1 High RT-Theme 18 | Extensions Plugin rt18-extensions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2026-57745 Patchstack
8.1 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.5 CVE-2026-57743 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Cross-Site Scripting No login needed ≤ 10.11.0 Fixed in 10.11.1 CVE-2026-57741 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Broken Access Control ≤ 10.11.1 CVE-2026-57740 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.3 CVE-2026-57734 Patchstack
7.1 High tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2026-57733 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2026-57732 Patchstack
7.5 High Flatsome Plugin flatsome Broken Access Control No login needed ≤ 3.20.5 CVE-2026-57729 Patchstack
7.1 High Flatsome Plugin flatsome Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.20.5 CVE-2026-57728 Patchstack
7.5 High Kirki Plugin kirki Broken Access Control No login needed ≤ 6.0.13 CVE-2026-57727 Patchstack
7.1 High Kirki Plugin kirki Cross-Site Scripting No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57725 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.12 Fixed in 2.0.13 CVE-2026-57718 Patchstack
7.1 High Fluent CRM Plugin fluent-crm Cross-Site Scripting No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-57715 Patchstack
8.8 High Events Manager Plugin events-manager PHP Object Injection No login needed ≤ 7.3.6 Fixed in 7.3.7 CVE-2026-57713 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.29 Fixed in 1.4.30 CVE-2026-57712 Patchstack
8.6 High Membership For WooCommerce Plugin membership-for-woocommerce Arbitrary File Deletion No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-57709 Patchstack
7.1 High Contact Form Entries Plugin contact-form-entries Cross-Site Scripting No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-57708 Patchstack
7.1 High Dokan Plugin dokan-lite Cross-Site Scripting No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2026-57706 Patchstack
7.5 High Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.28.5 Fixed in 5.28.5.1 CVE-2026-57705 Patchstack
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Authentication Bypass Broken Authentication No login needed ≤ 5.9.9.6 Fixed in 5.9.9.7 CVE-2026-57697 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-57695 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.2.2 Fixed in 9.2.3 CVE-2026-57668 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3.8 Fixed in 1.6.3.9 CVE-2026-57423 Patchstack
7.1 High Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-57422 Patchstack
7.1 High CRM Perks Forms Plugin crm-perks-forms Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-57421 Patchstack
7.1 High Cart Lift Plugin cart-lift Cross-Site Scripting No login needed ≤ 3.1.57 Fixed in 3.1.58 CVE-2026-57417 Patchstack
7.1 High SiteGround Email Marketing Plugin siteground-email-marketing Cross-Site Scripting No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2026-57416 Patchstack
7.1 High Gift Vouchers Plugin gift-voucher Cross-Site Scripting No login needed ≤ 4.7.0 Fixed in 4.7.1 CVE-2026-57415 Patchstack
7.1 High CF7 Views – Complete Entry Management for Contact Form 7 Plugin cf7-views Cross-Site Scripting Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-57411 Patchstack
8.8 High MailerPress Plugin mailerpress Privilege Escalation ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-57410 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57409 Patchstack
7.2 High PDF Generator Plugin pdf-generator-for-wp Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-57407 Patchstack
7.1 High Open Shop Plugin open-shop Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-57405 Patchstack
7.1 High GD Security Headers Plugin gd-security-headers Cross-Site Scripting No login needed ≤ 1.8 Fixed in 1.9 CVE-2026-57403 Patchstack
7.1 High Proxy & VPN Blocker Plugin proxy-vpn-blocker Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-57399 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting No login needed ≤ 12.8.3 Fixed in 12.8.4 CVE-2026-57398 Patchstack
7.1 High Free Gifts for WooCommerce Plugin free-gifts-for-woocommerce Cross-Site Scripting No login needed ≤ 13.1.0 Fixed in 13.3.0 CVE-2026-57396 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting No login needed ≤ 4.14 Fixed in 4.15 CVE-2026-57394 Patchstack
8.6 High Groundhogg Plugin groundhogg Arbitrary File Deletion No login needed ≤ 4.4.1 Fixed in 4.5 CVE-2026-57389 Patchstack
7.1 High Hydra Booking Plugin hydra-booking Cross-Site Scripting No login needed ≤ 1.1.44 Fixed in 1.1.45 CVE-2026-57388 Patchstack
7.1 High picu Plugin picu Cross-Site Scripting No login needed ≤ 3.5.1 Fixed in 3.6.1 CVE-2026-57387 Patchstack
8.8 High aBlocks Plugin ablocks Privilege Escalation ≤ 2.9.1 Fixed in 2.9.1 CVE-2026-57386 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only