WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,501–1,550 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Roisin Theme roisin Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.4 CVE-2026-22512 Patchstack
8.1 High NeoBeat Theme neobeat Local File Inclusion No login needed ≤ 1.2 Fixed in 1.7 CVE-2026-22511 Patchstack
8.1 High Melody Theme melodyschool PHP Object Injection No login needed ≤ 1.6.3 CVE-2026-22510 Patchstack
8.1 High Gioia Theme gioia Local File Inclusion No login needed ≤ 1.4 CVE-2026-22509 Patchstack
8.1 High Dentalux Theme dentalux Local File Inclusion No login needed ≤ 3.3 CVE-2026-22508 Patchstack
8.1 High Amoli Theme amoli Local File Inclusion No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-22506 Patchstack
8.1 High Morning Records Theme morning-records PHP Object Injection No login needed ≤ 1.2 CVE-2026-22505 Patchstack
8.1 High ProLingua Theme prolingua Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-22504 Patchstack
8.1 High Nelson Theme nelson Local File Inclusion No login needed ≤ 1.2.0 CVE-2026-22503 Patchstack
8.1 High Mr. Cobbler Theme mr-cobbler Local File Inclusion No login needed ≤ 1.1.9 CVE-2026-22502 Patchstack
8.1 High Lella Theme lella Local File Inclusion No login needed ≤ 1.2 CVE-2026-22499 Patchstack
8.1 High Laurent Theme laurent Local File Inclusion No login needed ≤ 3.1 CVE-2026-22498 Patchstack
8.1 High Hypnotherapy Theme hypnotherapy Local File Inclusion No login needed ≤ 1.2.10 CVE-2026-22496 Patchstack
8.1 High Greenville Theme greenville Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-22495 Patchstack
8.1 High Good Homes Theme good-homes Local File Inclusion No login needed ≤ 1.3.13 CVE-2026-22494 Patchstack
8.1 High Gaspard Theme gaspard Local File Inclusion No login needed ≤ 1.3 CVE-2026-22493 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.35 CVE-2026-22491 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
7.5 High PitchPrint Plugin pitchprint Arbitrary File Deletion No login needed ≤ 11.1.2 Fixed in 11.2.0 CVE-2026-22448 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.2.6.0 Fixed in 4.2.7.0 CVE-2025-69358 Patchstack
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
7.1 High Zorka Theme zorka Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 CVE-2025-69096 Patchstack
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Privilege Escalation WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module ≤ 3.2.4 CVE-2026-4314 Wordfence
8.1 High Melania Theme melania Local File Inclusion No login needed ≤ 2.5.0 CVE-2026-22324 Patchstack
7.1 High Flash Video Player Plugin flash-video-player Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.0.4 CVE-2024-32537 Patchstack
7.2 High Photography Theme photography Arbitrary File Upload < 7.7.6 Fixed in 7.7.6 CVE-2026-27043 Patchstack
7.1 High Everest Forms Pro Plugin everest-forms-pro Cross-Site Scripting No login needed ≤ 1.9.10 CVE-2026-27070 Patchstack
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
8.8 High WishList Member X Plugin wishlist-member-x PHP Object Injection ≤ 3.29.0 CVE-2026-25445 Patchstack
7.5 High Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-25443 Patchstack
7.1 High Kentha Theme kentha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.2 CVE-2026-25442 Patchstack
7.1 High Gutenberg Blocks Plugin unlimited-blocks Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2026-25438 Patchstack
7.1 High Table of Contents Creator Plugin table-of-contents-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.4.1 CVE-2025-68836 Patchstack
7.1 High Brookside Theme brookside Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-67618 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-53222 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50001 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Payment Bypass No login needed ≤ 4.2.8.3 Fixed in 4.2.8.4 CVE-2026-25312 Patchstack
8.1 High Admin Safety Guard Plugin admin-safety-guard Authentication Bypass Broken Authentication No login needed ≤ 1.2.6 CVE-2026-25471 Patchstack
8.1 High Tripgo Theme tripgo Local File Inclusion No login needed ≤ 1.5.6 Fixed in 1.5.6 CVE-2026-27093 Patchstack
8.1 High ColorFolio - Freelance Designer Theme colorfolio PHP Object Injection Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data No login needed ≤ 1.3 CVE-2026-27096 Patchstack
7.1 High WP eMember Plugin wp-emember Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v10.2.2 CVE-2026-28073 Patchstack
7.1 High Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.15.9 Fixed in 3.15.10 CVE-2026-25369 Patchstack
7.5 High NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id No login needed ≤ 9.1.9 CVE-2026-1947 Wordfence
7.6 High UpsellWP Plugin checkout-upsell-and-order-bumps SQL Injection ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-32459 Patchstack
7.6 High WOLF Plugin bulk-editor SQL Injection ≤ 1.0.8.7 Fixed in 1.0.9 CVE-2026-32458 Patchstack
8.5 High CP Contact Form with Paypal Plugin cp-contact-form-with-paypal SQL Injection ≤ 1.3.61 Fixed in 1.3.62 CVE-2026-32433 Patchstack
7.5 High Medilazar Core Plugin medilazar-core Local File Inclusion ≤ 1.4.7 Fixed in 1.4.7 CVE-2026-32426 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.8.13 Fixed in 5.8.14 CVE-2026-32422 Patchstack
7.6 High Meow Gallery Plugin meow-gallery SQL Injection ≤ 5.4.4 Fixed in 5.4.5 CVE-2026-32418 Patchstack
7.2 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution ≤ 2.36 Fixed in 2.37 CVE-2026-32414 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only