WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,651–1,700 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 34 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High EmojiNation Theme emojination Local File Inclusion No login needed ≤ 1.0.12 CVE-2026-28029 Patchstack
8.1 High MoneyFlow Theme moneyflow Local File Inclusion No login needed ≤ 1.0 CVE-2026-28028 Patchstack
8.1 High Kayon Theme kayon Local File Inclusion No login needed ≤ 1.3 CVE-2026-28027 Patchstack
8.1 High Motorix Theme motorix Local File Inclusion No login needed ≤ 1.6 CVE-2026-28026 Patchstack
8.1 High Stargaze Theme stargaze Local File Inclusion No login needed ≤ 1.5 CVE-2026-28025 Patchstack
8.1 High Helion Theme helion Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-28024 Patchstack
8.1 High Nuts Theme nuts Local File Inclusion No login needed ≤ 1.10 CVE-2026-28023 Patchstack
8.1 High Foodie Theme foodie Local File Inclusion No login needed ≤ 1.14 CVE-2026-28022 Patchstack
8.1 High Craftis Theme craftis Local File Inclusion No login needed ≤ 1.2.8 CVE-2026-28021 Patchstack
8.1 High Chroma Theme chroma Local File Inclusion No login needed ≤ 1.11 CVE-2026-28020 Patchstack
8.1 High Manoir Theme manoir Local File Inclusion No login needed ≤ 1.11 CVE-2026-28019 Patchstack
8.1 High Global Logistics Theme globallogistics Local File Inclusion No login needed ≤ 3.20 CVE-2026-28018 Patchstack
8.1 High Green Thumb Theme greenthumb Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-28017 Patchstack
8.1 High Luxury Wine Theme luxury-wine Local File Inclusion No login needed ≤ 1.1.14 CVE-2026-28016 Patchstack
8.1 High ShiftCV Theme shift-cv Local File Inclusion No login needed ≤ 3.0.14 CVE-2026-28015 Patchstack
8.1 High Translogic Theme translogic Local File Inclusion No login needed ≤ 1.2.11 CVE-2026-28014 Patchstack
8.1 High Kratz Theme kratz Local File Inclusion No login needed ≤ 1.0.12 CVE-2026-28013 Patchstack
8.1 High Gridiron Theme gridiron Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28012 Patchstack
8.1 High Yottis Theme yottis Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-28011 Patchstack
8.1 High Scientia Theme scientia Local File Inclusion No login needed ≤ 1.2.4 CVE-2026-28010 Patchstack
8.1 High DroneX Theme dronex Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-28009 Patchstack
8.1 High Coinpress Theme coinpress Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28007 Patchstack
8.1 High Yungen Theme yungen Local File Inclusion No login needed ≤ 1.0.12 CVE-2026-28006 Patchstack
8.1 High Vixus Theme vixus Local File Inclusion No login needed ≤ 1.0.16 CVE-2026-27998 Patchstack
8.1 High Maxify Theme maxify Local File Inclusion No login needed ≤ 1.0.16 CVE-2026-27997 Patchstack
8.1 High Lingvico Theme lingvico Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-27996 Patchstack
8.1 High Justitia Theme justitia Local File Inclusion No login needed ≤ 1.1.0 CVE-2026-27995 Patchstack
8.1 High Tediss Theme tediss Local File Inclusion No login needed ≤ 1.2.4 CVE-2026-27994 Patchstack
8.1 High Aldo Theme aldo Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-27993 Patchstack
8.1 High Meals & Wheels Theme meals-wheels Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-27992 Patchstack
8.1 High Avventure Theme avventure Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-27991 Patchstack
8.1 High ConFix Theme confix Local File Inclusion No login needed ≤ 1.013 CVE-2026-27990 Patchstack
8.1 High Quanzo Theme quanzo Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-27989 Patchstack
8.1 High Equadio Theme equadio Local File Inclusion No login needed ≤ 1.1.3 CVE-2026-27988 Patchstack
8.1 High The Qlean Theme the-qlean Local File Inclusion No login needed ≤ 2.12 CVE-2026-27987 Patchstack
8.1 High OsTende Theme ostende Local File Inclusion No login needed ≤ 1.4.3 CVE-2026-27986 Patchstack
8.1 High Humanum Theme humanum Local File Inclusion No login needed ≤ 1.1.4 CVE-2026-27985 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.6 Fixed in 2.2.7 CVE-2026-27541 Patchstack
8.5 High Eagle Booking Plugin eagle-booking SQL Injection ≤ 1.3.4.3 CVE-2026-27428 Patchstack
7.5 High My Tickets Plugin my-tickets Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2026-27406 Patchstack
7.3 High Directory Pro Plugin directory-pro Broken Access Control No login needed ≤ 2.5.6 CVE-2026-27396 Patchstack
8.8 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2026-27390 Patchstack
7.5 High DesignThemes Booking Manager Plugin designthemes-booking-manager Broken Access Control No login needed ≤ 2.0 CVE-2026-27388 Patchstack
7.5 High DesignThemes Directory Addon Plugin designthemes-directory-addon Broken Access Control No login needed ≤ 1.8 CVE-2026-27386 Patchstack
7.1 High DesignThemes Portfolio Plugin designthemes-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2026-27385 Patchstack
8.1 High Metro Plugin metro Local File Inclusion No login needed ≤ 2.13 CVE-2026-27383 Patchstack
7.1 High Metro Plugin metro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13 CVE-2026-27382 Patchstack
8.1 High Aora Theme aora Local File Inclusion No login needed ≤ 1.3.15 CVE-2026-27381 Patchstack
8.8 High NextScripts Plugin social-networks-auto-poster-facebook-twitter-g PHP Object Injection ≤ 4.4.7 CVE-2026-27379 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only