WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,451–1,500 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP REST Cache Plugin wp-rest-cache Cross-Site Scripting No login needed ≤ 2026.1.0 Fixed in 2026.1.1 CVE-2026-25347 Patchstack
7.1 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-25346 Patchstack
7.1 High Boutique Theme kute-boutique Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2026-25342 Patchstack
7.1 High RSFirewall! Plugin rsfirewall Cross-Site Scripting No login needed ≤ 1.1.45 Fixed in 1.1.46 CVE-2026-25341 Patchstack
8.1 High Salon Booking System Pro Plugin salon-booking-plugin-pro Privilege Escalation Account Takeover No login needed ≤ 10.30.12 Fixed in 10.30.12 CVE-2026-25334 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-25317 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Broken Access Control No login needed ≤ 4.10.1 Fixed in 4.11.0 CVE-2026-25309 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-25306 Patchstack
7.1 High Jaroti Theme jaroti Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2026-25304 Patchstack
7.1 High Motta Addons Plugin motta-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.1 CVE-2026-25033 Patchstack
7.5 High Team Plugin tlp-team Broken Access Control No login needed ≤ 5.0.11 Fixed in 5.0.12 CVE-2026-25026 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-25025 Patchstack
7.1 High NaturaLife Extensions Plugin naturalife-extensions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2026-25018 Patchstack
8.1 High NaturaLife Extensions Plugin naturalife-extensions Local File Inclusion No login needed ≤ 2.1 Fixed in 2.2 CVE-2026-25017 Patchstack
7.1 High Phox Hosting Plugin phox-host Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-25013 Patchstack
8.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-25007 Patchstack
7.5 High LearnPress – Sepay Payment Plugin learnpress-sepay-payment Authentication Bypass Sepay Payment plugin <= 4.0.0 - Broken Authentication No login needed ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-25002 Patchstack
8.5 High Post Snippets Plugin post-snippets Remote Code Execution ≤ 4.0.12 Fixed in 4.0.13 CVE-2026-25001 Patchstack
7.1 High UpSolution Core Plugin us-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.41 Fixed in 8.42 CVE-2026-24983 Patchstack
8.8 High Visionary Core Plugin noo-visionary-core PHP Object Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-24981 Patchstack
7.1 High Visionary Core Plugin noo-visionary-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-24980 Patchstack
7.1 High Jobica Core Plugin jobica-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24979 Patchstack
8.8 High Jobica Core Plugin jobica-core PHP Object Injection ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24978 Patchstack
8.5 High Organici Library Plugin noo-organici-library SQL Injection ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-24977 Patchstack
8.8 High Organici Library Plugin noo-organici-library PHP Object Injection ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-24976 Patchstack
7.1 High Organici Library Plugin noo-organici-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-24975 Patchstack
8.8 High CitiLights Theme noo-citilights PHP Object Injection ≤ 3.7.1 Fixed in 3.7.2 CVE-2026-24974 Patchstack
7.1 High CitiLights Theme noo-citilights Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2026-24973 Patchstack
7.7 High Energox Theme energox Arbitrary File Deletion ≤ 1.2 Fixed in 1.3 CVE-2026-24970 Patchstack
7.7 High Instant VA Theme instantva Arbitrary File Deletion ≤ 1.0.1 Fixed in 1.0.2 CVE-2026-24969 Patchstack
7.1 High Car Dealer Theme cardealer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2026-24391 Patchstack
7.5 High News Magazine X Plugin news-magazine-x Broken Access Control No login needed ≤ 1.2.50 Fixed in 1.2.51 CVE-2026-24382 Patchstack
8.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Account Takeover No login needed ≤ 6.0.7.1 Fixed in 6.0.7.2 CVE-2026-24373 Patchstack
7.5 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 1.8.10 Fixed in 1.9.0 CVE-2026-24372 Patchstack
7.1 High The Grid Plugin the-grid Broken Access Control ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-24369 Patchstack
7.5 High WP Cost Estimation & Payment Forms Builder Plugin wp_estimation_form Broken Access Control No login needed ≤ 10.3.0 Fixed in 10.3.0 CVE-2026-24363 Patchstack
8.8 High Dokan Plugin dokan-lite Authentication Bypass Broken Authentication ≤ 4.2.4 Fixed in 4.2.5 CVE-2026-24359 Patchstack
7.1 High Gyan Elements Plugin gyan-elements Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2026-23979 Patchstack
7.5 High Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-23977 Patchstack
7.1 High Golo Plugin golo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.5 Fixed in 1.7.5 CVE-2026-23973 Patchstack
8.1 High WoodMart Theme woodmart PHP Object Injection No login needed ≤ 8.3.8 Fixed in 8.3.9 CVE-2026-23971 Patchstack
7.1 High WP Telegram Widget and Join Link Plugin wptelegram-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.13 Fixed in 2.2.14 CVE-2026-23807 Patchstack
7.5 High Jobs Plugin job-postings Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-23806 Patchstack
7.1 High Legacy Admin Plugin legacy-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.5 CVE-2026-22524 Patchstack
7.1 High Ultra WordPress Admin Plugin ultra-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.7 CVE-2026-22523 Patchstack
7.1 High Handmade Framework Plugin handmade-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9 CVE-2026-22520 Patchstack
8.1 High Wizor's Theme wizors-investments Local File Inclusion No login needed ≤ 2.12 CVE-2026-22516 Patchstack
8.1 High VegaDays Theme vegadays Local File Inclusion No login needed ≤ 1.2.0 CVE-2026-22515 Patchstack
8.1 High Unica Theme unica Local File Inclusion No login needed ≤ 1.4.1 CVE-2026-22514 Patchstack
8.1 High Triompher Theme triompher Local File Inclusion No login needed ≤ 1.1.0 CVE-2026-22513 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only