WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical GP Premium Plugin gp-premium Arbitrary File Upload ≤ 2.5.5 Fixed in 2.5.6 CVE-2026-66627 Patchstack
9.9 Critical Templatiq Plugin templatiq Arbitrary File Upload ≤ 0.2.5 CVE-2026-32474 Patchstack
9.8 Critical FundEngine Plugin wp-fundraising-donation PHP Object Injection No login needed ≤ 1.7.9 Fixed in 1.8.0 CVE-2026-32470 Patchstack
9.9 Critical Sync Post With Other Site Plugin sync-post-with-other-site Arbitrary File Upload ≤ 1.9.3 CVE-2026-32463 Patchstack
9.9 Critical Cwicly Plugin cwicly Remote Code Execution ≤ 1.4.4 CVE-2026-32444 Patchstack
9.6 Critical Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Arbitrary File Upload No login needed ≤ 7.1.67 CVE-2026-28192 Patchstack
9.8 Critical Nokri Theme nokri Broken Access Control No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-66691 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-66478 Patchstack
9.3 Critical Everest Backup Plugin everest-backup SQL Injection No login needed ≤ 2.3.12 CVE-2026-66472 Patchstack
9.8 Critical Cartify Theme cartify-multipurpose-woocommerce-wordpress-theme Privilege Escalation Account Takeover No login needed ≤ 1.3.0.1 CVE-2026-66465 Patchstack
9.3 Critical RealPress Plugin realpress SQL Injection No login needed ≤ 1.1.2 CVE-2026-66458 Patchstack
9.8 Critical Salon booking system Plugin salon-booking-system Authentication Bypass Broken Authentication No login needed ≤ 10.30.26 Fixed in 10.30.27 CVE-2026-66453 Patchstack
9.3 Critical If-So Dynamic Content Personalization Plugin if-so SQL Injection No login needed ≤ 1.10 Fixed in 1.10.0.1 CVE-2026-66446 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.1.1 Fixed in 2.1.2 CVE-2026-66436 Patchstack
9.8 Critical SMS Alert Order Notifications Plugin sms-alert Privilege Escalation No login needed ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-66424 Patchstack
9.3 Critical Listdom Plugin listdom SQL Injection No login needed ≤ 5.6.0 Fixed in 5.7.0 CVE-2026-61969 Patchstack
9.8 Critical miniorange otp verification Plugin miniorange-otp-verification Privilege Escalation No login needed ≤ 5.5.1 Fixed in 5.5.2 CVE-2026-61967 Patchstack
9.3 Critical WPJAM Basic Plugin wpjam-basic SQL Injection No login needed ≤ 7.0.1 Fixed in 7.0.2 CVE-2026-61966 Patchstack
10.0 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2026-61962 Patchstack
9.8 Critical Log in with Google Plugin login-with-google Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-28185 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on PHP Object Injection No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-28149 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Other Bypass Vulnerability No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-28148 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.13 Fixed in 2.0 CVE-2026-28142 Patchstack
9.8 Critical OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication No login needed ≤ 7.0.0 Fixed in 7.0.1 CVE-2026-28008 Patchstack
9.3 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-28001 Patchstack
10.0 Critical QA Analytics Plugin qa-heatmap-analytics Remote Code Execution No login needed ≤ 5.2.0.0 Fixed in 5.2.0.1 CVE-2026-27544 Patchstack
9.3 Critical Tablesome Table Plugin tablesome SQL Injection No login needed ≤ 1.2.9 CVE-2026-66659 Patchstack
9.1 Critical CTX Feed Plugin webappick-product-feed-for-woocommerce Remote Code Execution ≤ 6.6.42 Fixed in 6.6.43 CVE-2026-66709 Patchstack
10.0 Critical Type Hub Plugin typehub Arbitrary File Upload No login needed ≤ 2.0.6 CVE-2026-66665 Patchstack
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation No login needed ≤ 3.29.10 CVE-2026-66662 Patchstack
9.3 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload SQL Injection No login needed ≤ 5.1.7 Fixed in 5.1.8 CVE-2026-66447 Patchstack
9.8 Critical AI ANN Theme ann PHP Object Injection No login needed ≤ 1.29.0 CVE-2026-65581 Patchstack
9.8 Critical Agricola Theme agricola PHP Object Injection No login needed ≤ 1.21.0 CVE-2026-65579 Patchstack
9.8 Critical Agora Theme agora PHP Object Injection No login needed ≤ 1.9 CVE-2026-65578 Patchstack
9.8 Critical Advice Theme advice PHP Object Injection No login needed ≤ 1.18.0 CVE-2026-65577 Patchstack
9.8 Critical Adrena Theme adrena PHP Object Injection No login needed ≤ 1.2.14 CVE-2026-65576 Patchstack
9.8 Critical Accalia Theme accalia PHP Object Injection No login needed ≤ 1.5.3 CVE-2026-65575 Patchstack
9.8 Critical Abogado Theme abogado PHP Object Injection No login needed ≤ 1.18 CVE-2026-65574 Patchstack
9.8 Critical Abelle Theme abelle PHP Object Injection No login needed ≤ 1.22 CVE-2026-65573 Patchstack
9.8 Critical A.Williams Theme alisha-williams PHP Object Injection No login needed ≤ 1.3.1 CVE-2026-65572 Patchstack
9.8 Critical 69 Clothing Theme clothing69 PHP Object Injection No login needed ≤ 1.2.11.1 CVE-2026-65571 Patchstack
9.8 Critical WPBruiser {no- Captcha anti-Spam} Plugin goodbye-captcha PHP Object Injection No login needed ≤ 3.1.43 CVE-2026-65556 Patchstack
10.0 Critical Spider Analyser – WordPress搜索引擎蜘蛛分析插件 Plugin spider-analyser Remote Code Execution WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) No login needed ≤ 2.1.3 CVE-2026-65553 Patchstack
9.8 Critical Export User Data Plugin export-user-data PHP Object Injection No login needed ≤ 2.2.6 CVE-2026-65552 Patchstack
9.9 Critical Betheme Theme betheme Remote Code Execution ≤ 28.4.2 CVE-2026-65548 Patchstack
9.3 Critical Qode Tours Plugin qode-tours SQL Injection No login needed ≤ 3.1.3.1 CVE-2026-65546 Patchstack
9.3 Critical WP OAuth Server Plugin miniorange-oauth-20-server SQL Injection No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-65520 Patchstack
9.3 Critical Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65508 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.5.6 Fixed in 1.5.8 CVE-2026-65507 Patchstack
9.8 Critical Ajax Search Lite Plugin ajax-search-lite PHP Object Injection No login needed ≤ 4.14.4 Fixed in 4.14.5 CVE-2026-28139 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only