WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,551–1,600 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 32 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Client Invoicing by Sprout Invoices Plugin sprout-invoices Local File Inclusion ≤ 20.8.9 Fixed in 20.8.10 CVE-2026-32401 Patchstack
7.5 High Boldman Theme boldman Local File Inclusion ≤ 7.7 Fixed in 7.8 CVE-2026-32400 Patchstack
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.32 Fixed in 3.33 CVE-2026-32399 Patchstack
7.5 High Greenly Theme Addons Plugin greenly-addons Local File Inclusion ≤ 8.2 Fixed in 8.2 CVE-2026-32393 Patchstack
7.5 High Greenly Theme greenly Local File Inclusion ≤ 8.1 Fixed in 8.2 CVE-2026-32392 Patchstack
7.5 High WpBookingly Plugin service-booking-manager Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32384 Patchstack
7.5 High Medilink-Core Plugin medilink-core Local File Inclusion ≤ 2.0.7 Fixed in 2.0.7 CVE-2026-32369 Patchstack
8.5 High Geo to Lat Plugin geo-to-lat SQL Injection ≤ 1.0.19 Fixed in 1.1 CVE-2026-32368 Patchstack
8.5 High Collapsing Categories Plugin collapsing-categories SQL Injection ≤ 3.0.9 Fixed in 3.0.12 CVE-2026-32366 Patchstack
8.5 High Collapsing Archives Plugin collapsing-archives SQL Injection ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-32365 Patchstack
7.5 High Turbo Manager Plugin turbo-manager Local File Inclusion ≤ 4.0.8 Fixed in 4.0.8 CVE-2026-32364 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 10.14.15 Fixed in 10.14.16 CVE-2026-32358 Patchstack
8.8 High JetEngine Plugin jet-engine PHP Object Injection Deserialization of untrusted data ≤ 3.8.4.1 Fixed in 3.8.4.1 CVE-2026-32355 Patchstack
8.5 High Fox LMS Plugin fox-lms SQL Injection ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2026-31922 Patchstack
8.5 High WP ERP Plugin erp SQL Injection ≤ 1.16.10 Fixed in 1.16.11 CVE-2026-31917 Patchstack
7.1 High MediCenter - Health Medical Clinic Plugin medicenter Cross-Site Scripting Health Medical Clinic WordPress Theme theme <= 14.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 14.9 CVE-2026-28137 Patchstack
8.2 High Royal Elementor Addons Plugin royal-elementor-addons Other Other vulnerability Type No login needed ≤ 1.7.1052 Fixed in 1.7.1053 CVE-2026-28135 Patchstack
8.5 High JetEngine Plugin jet-engine Remote Code Execution ≤ 3.7.2 Fixed in 3.8.1.2 CVE-2026-28134 Patchstack
8.5 High Filr Plugin filr-protection Arbitrary File Upload ≤ 1.2.14 CVE-2026-28133 Patchstack
7.1 High UDesign Plugin u-design Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.14.0 CVE-2026-28130 Patchstack
8.1 High Little Birdies Theme little-birdies Local File Inclusion No login needed ≤ 1.3.16 CVE-2026-28129 Patchstack
8.1 High Verse Theme verse Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-28128 Patchstack
7.1 High Lawyer Directory Plugin lawyer-directory Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2026-28127 Patchstack
7.1 High RH Frontend Publishing Pro Plugin rh-frontend Cross-Site Scripting No login needed ≤ 4.3.4 Fixed in 4.3.4 CVE-2026-28126 Patchstack
8.1 High Midi Theme midi Local File Inclusion No login needed ≤ 1.14 CVE-2026-28125 Patchstack
8.1 High Notarius Theme notarius Local File Inclusion No login needed ≤ 1.9 CVE-2026-28124 Patchstack
8.1 High Veil Theme veil Local File Inclusion No login needed ≤ 1.9 CVE-2026-28123 Patchstack
7.1 High ListingPro Plugin listingpro-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.8 CVE-2026-28122 Patchstack
8.1 High Anderson Theme andersonclinic Local File Inclusion No login needed ≤ 1.4.2 CVE-2026-28121 Patchstack
8.1 High Dr.Patterson Theme dr-patterson Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-28120 Patchstack
8.1 High Nirvana Theme nir-vana Local File Inclusion No login needed ≤ 2.6 CVE-2026-28119 Patchstack
8.1 High Welldone Theme welldone Local File Inclusion No login needed ≤ 2.4 CVE-2026-28118 Patchstack
8.1 High smart SEO Theme smartseo Local File Inclusion No login needed ≤ 2.9 CVE-2026-28117 Patchstack
7.1 High Ultimate Learning Pro Plugin indeed-learning-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.1 CVE-2026-28113 Patchstack
7.1 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator Cross-Site Scripting Banner Rotator plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28112 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist Cross-Site Scripting AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28110 Patchstack
7.1 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider Cross-Site Scripting AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28109 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner Cross-Site Scripting AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28108 Patchstack
8.1 High Muzicon Theme muzicon Local File Inclusion No login needed ≤ 1.9.0 CVE-2026-28107 Patchstack
7.1 High LBG Zoominoutslider Plugin lbg_zoominoutslider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.5 CVE-2026-28103 Patchstack
7.1 High UberSlider Classic Plugin uberslider_classic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2026-28102 Patchstack
7.1 High UberSlider MouseInteraction Plugin uberslider_mouseinteraction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28101 Patchstack
7.1 High UberSlider PerpetuumMobile Plugin uberslider_perpetuummobile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28100 Patchstack
7.1 High UberSlider Ultra Plugin uberslider_ultra Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28099 Patchstack
8.1 High Save Life Theme save-life Local File Inclusion No login needed ≤ 1.2.13 CVE-2026-28098 Patchstack
8.1 High Artrium Theme artrium Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28097 Patchstack
8.1 High WealthCo Theme wealthco Local File Inclusion No login needed ≤ 2.18 CVE-2026-28096 Patchstack
8.1 High Marcell Theme marcell Local File Inclusion No login needed ≤ 1.2.14 CVE-2026-28095 Patchstack
8.1 High RexCoin Theme rexcoin Local File Inclusion No login needed ≤ 1.2.6 CVE-2026-28094 Patchstack
8.1 High Ozisti Theme ozisti Local File Inclusion No login needed ≤ 1.1.10 CVE-2026-28093 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only