WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 1,491 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Organization chart Plugin organization-chart Cross-Site Request Forgery No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2026-24597 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-27415 Patchstack
5.4 Medium WPGraphQL Plugin wp-graphql Cross-Site Request Forgery No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-68604 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.11.0 Fixed in 1.12.0 CVE-2026-42645 Patchstack
5.4 Medium Share This Image Plugin share-this-image Server-Side Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-42641 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed < 7.13.2 Fixed in 7.13.2 CVE-2025-58922 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.6.0 CVE-2025-15635 Patchstack
4.3 Medium Userpro Plugin userpro Cross-Site Request Forgery No login needed ≤ 5.1.11 Fixed in 5.1.11 CVE-2025-53444 Patchstack
5.4 Medium RT-Theme 18 | Extensions Plugin rt18-extensions Cross-Site Request Forgery No login needed ≤ 2.5 CVE-2026-39710 Patchstack
5.4 Medium Podigee Plugin podigee Server-Side Request Forgery No login needed ≤ 1.4.0 CVE-2026-39695 Patchstack
6.0 Medium Visual Link Preview Plugin visual-link-preview Server-Side Request Forgery ≤ 2.3.0 CVE-2026-39670 Patchstack
5.4 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery No login needed ≤ 5.11 CVE-2026-39647 Patchstack
5.4 Medium GlobalPayments WooCommerce Plugin global-payments-woocommerce Server-Side Request Forgery No login needed ≤ 1.18.0 CVE-2026-39645 Patchstack
6.5 Medium Blackfyre Theme blackfyre Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2026-39641 Patchstack
5.4 Medium Grand Magazine Theme grandmagazine Cross-Site Request Forgery No login needed ≤ 3.5.5 CVE-2026-39635 Patchstack
5.4 Medium Grand Portfolio Theme grandportfolio Cross-Site Request Forgery No login needed ≤ 3.3 CVE-2026-39634 Patchstack
6.5 Medium Grand Car Rental Plugin grandcarrental Cross-Site Request Forgery No login needed ≤ 3.6.9 CVE-2026-39633 Patchstack
6.5 Medium Grand Blog Theme grandblog Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2026-39632 Patchstack
6.4 Medium Getty Images Plugin getty-images Server-Side Request Forgery ≤ 4.1.0 CVE-2026-39630 Patchstack
4.3 Medium NewsExo Plugin newsexo Cross-Site Request Forgery No login needed ≤ 7.1 CVE-2026-39618 Patchstack
5.4 Medium Grand Photography Theme grandphotography Cross-Site Request Forgery No login needed ≤ 5.7.8 CVE-2026-39603 Patchstack
5.3 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.21.4 Fixed in 2.21.5 CVE-2026-39543 Patchstack
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-39521 Patchstack
4.3 Medium User Feedback Plugin userfeedback-lite Broken Access Control ≤ 1.10.1 Fixed in 1.11.0 CVE-2026-39476 Patchstack
5.5 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Server-Side Request Forgery ≤ 6.19.8 Fixed in 6.19.9 CVE-2026-39464 Patchstack
5.4 Medium Popup Box AYS Pro Plugin Cross-Site Scripting Admin+ Stored Cross-Site Scripting (XSS) via CSRF < 5.5.0 Fixed in 5.5.0 CVE-2025-15611 WPScan
5.8 Medium Performance Monitor Plugin Server-Side Request Forgery Unauthenticated Blind SSRF No login needed ≤ 1.0.6 CVE-2026-3881 WPScan
6.5 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Cross-Site Scripting ≤ <= 7.42 Fixed in 7.43 CVE-2026-32521 Patchstack
6.4 Medium Contest Gallery Plugin contest-gallery Server-Side Request Forgery ≤ 28.1.2.1 Fixed in 28.1.2.2 CVE-2026-24964 Patchstack
5.6 Medium Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed ≤ 1.7.2 CVE-2024-13785 Wordfence
4.3 Medium Admin Menu Editor Plugin admin-menu-editor Cross-Site Request Forgery No login needed ≤ 1.14.1 Fixed in 1.15 CVE-2026-32456 Patchstack
6.5 Medium Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery No login needed ≤ 13.5.2 Fixed in 13.5.2.1 CVE-2026-32443 Patchstack
5.4 Medium GamiPress Plugin gamipress Cross-Site Request Forgery No login needed ≤ 7.6.6 Fixed in 7.6.7 CVE-2026-32420 Patchstack
5.4 Medium Gift Up Gift Cards for WordPress and WooCommerce Plugin gift-up Server-Side Request Forgery No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-32412 Patchstack
6.4 Medium Simple Blog Card Plugin simple-blog-card Server-Side Request Forgery ≤ 2.37 Fixed in 2.38 CVE-2026-32357 Patchstack
6.4 Medium MailerPress Plugin mailerpress Server-Side Request Forgery ≤ 1.4.2 Fixed in 1.5.0 CVE-2026-32353 Patchstack
4.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Server-Side Request Forgery ≤ 2.4.7 Fixed in 2.4.8 CVE-2026-32349 Patchstack
5.3 Medium Perfect Portfolio Plugin perfect-portfolio Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2026-32345 Patchstack
4.3 Medium Corpiva Plugin corpiva Cross-Site Request Forgery No login needed ≤ 1.0.96 Fixed in 1.0.97 CVE-2026-32344 Patchstack
4.3 Medium Easy Table of Contents Plugin easy-table-of-contents Cross-Site Request Forgery No login needed ≤ 2.0.80 Fixed in 2.0.81 CVE-2026-32343 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.1.2 Fixed in 6.7.1.3 CVE-2026-32342 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Request Forgery No login needed ≤ 1.8.37 Fixed in 1.8.38 CVE-2026-32330 Patchstack
5.4 Medium Lemmony Plugin lemmony Cross-Site Request Forgery No login needed ≤ 1.7.1 Fixed in 1.7.1 CVE-2026-32328 Patchstack
4.3 Medium wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Missing CSRF Protection on wpdGetFollowsPage No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22215 VulnCheck
4.3 Medium Court Reservation Plugin court-reservation Cross-Site Request Forgery Event Deletion via CSRF No login needed < 1.10.9 Fixed in 1.10.9 CVE-2026-1508 WPScan
4.3 Medium WP eCommerce Plugin Cross-Site Request Forgery Coupon Deletion via CSRF No login needed ≤ 3.15.1 CVE-2026-1128 WPScan
6.4 Medium Ratatouille Plugin ratatouille Server-Side Request Forgery ≤ 1.2.6 CVE-2026-28036 Patchstack
5.3 Medium Featured Image from Content Plugin featured-image-from-content Server-Side Request Forgery Featured Image from Content < 1.7 Authenticated SSRF via save_post < 1.7 Fixed in 1.7 CVE-2026-27759 VulnCheck
5.1 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Cross-Site Request Forgery Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions No login needed < 3.0.5 Fixed in 3.0.5 CVE-2026-23694 VulnCheck
4.3 Medium Kenta Companion Plugin kenta-companion Cross-Site Request Forgery No login needed ≤ 1.3.3 CVE-2026-27090 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only