WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,501–1,550 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical RT-Theme 18 | Extensions Plugin rt18-extensions PHP Object Injection No login needed ≤ 2.5 CVE-2026-57744 Patchstack
8.1 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.5 CVE-2026-57743 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Cross-Site Scripting No login needed ≤ 10.11.0 Fixed in 10.11.1 CVE-2026-57741 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Broken Access Control ≤ 10.11.1 CVE-2026-57740 Patchstack
9.3 Critical AcyMailing SMTP Newsletter Plugin acymailing SQL Injection No login needed ≤ 10.11.0 Fixed in 10.11.1 CVE-2026-57739 Patchstack
9.8 Critical 777 Theme triple-seven PHP Object Injection No login needed ≤ 1.13.0 CVE-2026-57738 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.3 CVE-2026-57734 Patchstack
7.1 High tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2026-57733 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2026-57732 Patchstack
7.5 High Flatsome Plugin flatsome Broken Access Control No login needed ≤ 3.20.5 CVE-2026-57729 Patchstack
7.1 High Flatsome Plugin flatsome Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.20.5 CVE-2026-57728 Patchstack
7.5 High Kirki Plugin kirki Broken Access Control No login needed ≤ 6.0.13 CVE-2026-57727 Patchstack
9.3 Critical Kirki Plugin kirki SQL Injection No login needed ≤ 6.0.12 Fixed in 6.0.13 CVE-2026-57726 Patchstack
7.1 High Kirki Plugin kirki Cross-Site Scripting No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57725 Patchstack
9.8 Critical Kirki Plugin kirki PHP Object Injection No login needed ≤ 6.0.12 Fixed in 6.0.13 CVE-2026-57724 Patchstack
10.0 Critical Aimogen Pro Plugin aimogen-pro Arbitrary File Upload No login needed ≤ 2.8.3 Fixed in 2.8.3.1 CVE-2026-57719 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.12 Fixed in 2.0.13 CVE-2026-57718 Patchstack
7.1 High Fluent CRM Plugin fluent-crm Cross-Site Scripting No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-57715 Patchstack
9.3 Critical LatePoint Plugin latepoint SQL Injection No login needed ≤ 5.6.3 Fixed in 5.6.4 CVE-2026-57714 Patchstack
8.8 High Events Manager Plugin events-manager PHP Object Injection No login needed ≤ 7.3.6 Fixed in 7.3.7 CVE-2026-57713 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.29 Fixed in 1.4.30 CVE-2026-57712 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.4.8 Fixed in 3.4.9 CVE-2026-57711 Patchstack
9.9 Critical WoowBot Pro Max Plugin woowbot-pro-max Arbitrary File Upload ≤ 14.1.7 Fixed in 14.1.8 CVE-2026-57710 Patchstack
8.6 High Membership For WooCommerce Plugin membership-for-woocommerce Arbitrary File Deletion No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-57709 Patchstack
7.1 High Contact Form Entries Plugin contact-form-entries Cross-Site Scripting No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-57708 Patchstack
9.3 Critical Simple Business Directory Pro Plugin simple-business-directory-pro SQL Injection No login needed ≤ 15.9.4 Fixed in 15.9.5 CVE-2026-57707 Patchstack
7.1 High Dokan Plugin dokan-lite Cross-Site Scripting No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2026-57706 Patchstack
7.5 High Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.28.5 Fixed in 5.28.5.1 CVE-2026-57705 Patchstack
9.3 Critical Amelia Plugin ameliabooking SQL Injection No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-57702 Patchstack
6.5 Medium Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Authentication Bypass Broken Authentication No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2026-57698 Patchstack
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Authentication Bypass Broken Authentication No login needed ≤ 5.9.9.6 Fixed in 5.9.9.7 CVE-2026-57697 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-57695 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
6.5 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting ≤ 2.8.11 Fixed in 2.8.12 CVE-2026-57693 Patchstack
5.8 Medium Anti-Malware Security and Brute-Force Firewall Plugin gotmls Cross-Site Scripting No login needed ≤ 4.23.89 Fixed in 4.23.90 CVE-2026-57691 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.2.2 Fixed in 9.2.3 CVE-2026-57668 Patchstack
6.5 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Broken Access Control No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57424 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3.8 Fixed in 1.6.3.9 CVE-2026-57423 Patchstack
7.1 High Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-57422 Patchstack
7.1 High CRM Perks Forms Plugin crm-perks-forms Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-57421 Patchstack
6.5 Medium Author Box WP Lens Plugin author-box-for-divi Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-57420 Patchstack
6.5 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 3.1.8 Fixed in 3.1.9 CVE-2026-57419 Patchstack
6.5 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.13 Fixed in 20.8.14 CVE-2026-57418 Patchstack
7.1 High Cart Lift Plugin cart-lift Cross-Site Scripting No login needed ≤ 3.1.57 Fixed in 3.1.58 CVE-2026-57417 Patchstack
7.1 High SiteGround Email Marketing Plugin siteground-email-marketing Cross-Site Scripting No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2026-57416 Patchstack
7.1 High Gift Vouchers Plugin gift-voucher Cross-Site Scripting No login needed ≤ 4.7.0 Fixed in 4.7.1 CVE-2026-57415 Patchstack
6.5 Medium ChatBot for eCommerce – WoowBot Plugin woowbot-woocommerce-chatbot Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) ≤ 4.6.1 Fixed in 4.7.0 CVE-2026-57414 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
6.5 Medium Gift Vouchers Plugin gift-voucher Broken Access Control No login needed ≤ 4.6.9 Fixed in 4.7.0 CVE-2026-57412 Patchstack
7.1 High CF7 Views – Complete Entry Management for Contact Form 7 Plugin cf7-views Cross-Site Scripting Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-57411 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only