WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,501–1,550 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Timetics Plugin timetics Cross-Site Scripting No login needed ≤ 1.0.58 Fixed in 1.0.59 CVE-2026-57674 Patchstack
7.1 High Optimole Plugin optimole-wp Cross-Site Scripting No login needed ≤ 4.2.7 Fixed in 4.2.8 CVE-2026-57673 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.1 Fixed in 6.5.1.2 CVE-2026-57672 Patchstack
7.1 High perfmatters Plugin perfmatters Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2026-57671 Patchstack
7.1 High Google Maps CP Plugin codepeople-post-map Cross-Site Scripting No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-57670 Patchstack
7.1 High Modula - PRO Plugin modula Cross-Site Scripting PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) No login needed ≤ 2.10.8 Fixed in 2.10.9 CVE-2026-57426 Patchstack
7.1 High WPAdverts Plugin wpadverts Cross-Site Scripting No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-57366 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.3.2 Fixed in 8.3.3 CVE-2026-57362 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.2.5 Fixed in 5.2.2.6 CVE-2026-57361 Patchstack
7.1 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting No login needed ≤ 3.5.4 Fixed in 3.5.5 CVE-2026-57360 Patchstack
7.1 High ReviewX Plugin reviewx Cross-Site Scripting No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2026-57359 Patchstack
7.1 High Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.9 Fixed in 4.3.10 CVE-2026-57358 Patchstack
7.1 High Search Atlas SEO Plugin metasync Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2026-57357 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.19 Fixed in 1.9.20 CVE-2026-57356 Patchstack
7.1 High HandL UTM Grabber Plugin handl-utm-grabber Cross-Site Scripting No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2026-57351 Patchstack
7.1 High WP Debugging Plugin wp-debugging Cross-Site Scripting No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2026-57350 Patchstack
7.1 High WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting No login needed ≤ 2.8.17 Fixed in 2.8.18 CVE-2026-57349 Patchstack
7.2 High Paid Member Subscriptions Plugin paid-member-subscriptions Server-Side Request Forgery No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-57348 Patchstack
7.1 High Internal Links Manager Plugin seo-automated-link-building Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2026-57345 Patchstack
7.1 High Classified Listing Plugin classified-listing Cross-Site Scripting No login needed ≤ 5.4.2 Fixed in 5.4.3 CVE-2026-57344 Patchstack
7.1 High Real Estate 7 Theme realestate-7 Cross-Site Scripting No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2026-57343 Patchstack
8.1 High Audrey Theme audrey Local File Inclusion No login needed ≤ 1.5 CVE-2026-42382 Patchstack
7.5 High NOWPayments for WooCommerce Plugin nowpayments-for-woocommerce Broken Access Control No login needed ≤ 1.4.0 CVE-2026-39448 Patchstack
7.1 High TheFox Theme thefox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.76 CVE-2026-27430 Patchstack
7.1 High Automotive Car Dealership Business Theme automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.3.3 CVE-2026-27426 Patchstack
7.1 High Automotive Listings Plugin automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 18.6 CVE-2026-27425 Patchstack
8.8 High Werkstatt Theme werkstatt PHP Object Injection ≤ 4.8.3 CVE-2026-27414 Patchstack
8.1 High Pearl - Corporate Business Theme pearl Local File Inclusion Corporate Business theme <= 3.4.10 - Local File Inclusion No login needed ≤ 3.4.10 CVE-2026-27412 Patchstack
7.1 High NativeChurch Theme nativechurch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.8.2 CVE-2026-27408 Patchstack
7.1 High LMS Theme lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.7 CVE-2026-27404 Patchstack
7.1 High Kids Life | Children School Theme kidslife Cross-Site Scripting No login needed ≤ 5.2 CVE-2026-27402 Patchstack
8.8 High ARMember Premium Plugin armember PHP Object Injection < 7.6 Fixed in 7.6 CVE-2026-27060 Patchstack
7.1 High Kids Zone - Children Theme kidszone Cross-Site Scripting Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) No login needed ≤ 5.4 CVE-2025-69156 Patchstack
7.1 High Fitness Zone Theme fitnesszone Cross-Site Scripting No login needed ≤ 5.7 CVE-2025-69155 Patchstack
7.1 High SpaLab | Beauty Salon Theme spalab Cross-Site Scripting No login needed ≤ 6.7 CVE-2025-69154 Patchstack
7.1 High Trendy Travel Theme trendytravel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.7 CVE-2025-69153 Patchstack
7.1 High Artale | Wedding Photography Theme artale Cross-Site Scripting No login needed ≤ 2.2.2 CVE-2025-69152 Patchstack
7.5 High OpenAI Chatbot for WordPress – Helper Plugin helper Broken Access Control Helper plugin <= 1.1.4 - Arbitrary Content Deletion No login needed ≤ 1.1.4 CVE-2025-69134 Patchstack
7.5 High Tourmaster Plugin tourmaster Local File Inclusion ≤ 5.4.5 CVE-2025-69133 Patchstack
8.5 High Unicamp Theme unicamp SQL Injection ≤ 2.2.2 CVE-2025-69094 Patchstack
8.1 High Lighthouse Theme lighthouseschool Local File Inclusion No login needed ≤ 1.2.12 CVE-2025-58902 Patchstack
7.5 High Ninja Forms - File Uploads Plugin ninja-forms-uploads Arbitrary File Upload File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter No login needed ≤ 3.3.29 CVE-2026-13369 Wordfence
7.5 High WP Review Slider Pro Plugin SQL Injection Unauthenticated SQL Injection via 'notinstring' Parameter No login needed ≤ 12.7.2 CVE-2026-8441 Wordfence
7.5 High Perfmatters Plugin perfmatters Path Traversal Unauthenticated Arbitrary File Read via 's' Parameter No login needed ≤ 2.6.4 CVE-2026-13251 Wordfence
7.2 High WP Database Backup Plugin wp-database-backup Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter ≤ 7.11 CVE-2026-9834 Wordfence
8.1 High Image Optimizer Plugin image-optimization Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection ≤ 1.7.4 CVE-2026-5821 Wordfence
7.5 High Request a Quote Form Plugin request-a-quote Remote Code Execution Unauthenticated Code Injection via 'path' Parameter No login needed ≤ 2.5.5 CVE-2026-14249 Wordfence
7.4 High HubSpot Plugin leadin Information Disclosure Sensitive Data Exposure ≤ 11.3.51 CVE-2026-57736 Patchstack
7.4 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2026-57723 Patchstack
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter ≤ 5.6.3 CVE-2026-13228 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only