WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,651–1,700 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 34 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium BD Courier Order Ratio Checker Plugin bd-courier-order-ratio-checker Broken Access Control ≤ 2.0.1 CVE-2026-22481 Patchstack
4.3 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control ≤ 3.9.6 Fixed in 4.0.0 CVE-2026-22472 Patchstack
5.3 Medium DeepDigital Theme deepdigital Arbitrary Shortcode Execution No login needed ≤ 1.0.2 CVE-2026-22469 Patchstack
4.3 Medium Absolute Addons For Elementor Plugin absolute-addons Broken Access Control ≤ 1.0.14 CVE-2026-22468 Patchstack
4.3 Medium WP MapIt Plugin wp-mapit Broken Access Control ≤ 3.0.3 CVE-2026-22466 Patchstack
6.5 Medium Form to Chat App Plugin form-to-chat Cross-Site Scripting ≤ 1.2.5 CVE-2026-22463 Patchstack
4.3 Medium Add Polylang support for Customizer Plugin add-polylang-support-for-customizer Cross-Site Request Forgery No login needed ≤ 1.4.5 CVE-2026-22462 Patchstack
5.3 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Broken Access Control No login needed ≤ 6.6.18 Fixed in 6.6.19 CVE-2026-22461 Patchstack
4.3 Medium Wanderland Plugin wanderland Broken Access Control ≤ 1.5 CVE-2026-22458 Patchstack
4.3 Medium Don Peppe Theme donpeppe Broken Access Control ≤ 1.3 CVE-2026-22450 Patchstack
4.3 Medium Prowess Theme prowess Broken Access Control No login needed ≤ 1.8.1 CVE-2026-22447 Patchstack
5.3 Medium Apimo Connector Plugin apimo Broken Access Control No login needed ≤ 2.6.5.2 CVE-2026-22445 Patchstack
5.4 Medium Verdure Theme verdure Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6 CVE-2026-22430 Patchstack
5.4 Medium Sweet Jane Theme sweetjane Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2 CVE-2026-22426 Patchstack
5.4 Medium Dolcino Theme dolcino Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6 CVE-2026-22411 Patchstack
5.4 Medium Justicia Theme justicia Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2 CVE-2026-22409 Patchstack
5.4 Medium Roam Plugin roam Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.1 CVE-2026-22407 Patchstack
5.4 Medium Overton Theme overton Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3 CVE-2026-22406 Patchstack
5.4 Medium Innovio Theme innovio Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22404 Patchstack
5.4 Medium Holmes Theme holmes Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22400 Patchstack
5.4 Medium Fleur Theme fleur Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0 CVE-2026-22398 Patchstack
5.4 Medium Fiorello Theme fiorello Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0 CVE-2026-22396 Patchstack
5.4 Medium Curly Theme curly Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3 CVE-2026-22393 Patchstack
5.4 Medium Cocco Theme cocco Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.5.1 CVE-2026-22391 Patchstack
5.9 Medium Owl Carousel WP Plugin owl-carousel-wp Cross-Site Scripting ≤ 2.2.2 CVE-2026-22388 Patchstack
5.4 Medium PawFriends - Pet Shop and Veterinary Theme pawfriends Cross-Site Request Forgery Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2026-22382 Patchstack
4.3 Medium SearchAzon Plugin searchazon Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2026-22360 Patchstack
5.4 Medium Electrician - Electrical Service Plugin electrician Server-Side Request Forgery Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) No login needed ≤ 5.6 CVE-2026-22358 Patchstack
6.5 Medium teachPress Plugin teachpress Cross-Site Scripting ≤ 9.0.12 CVE-2026-22353 Patchstack
6.5 Medium Menu In Post Plugin menu-in-post Cross-Site Scripting ≤ 1.4.1 CVE-2026-22349 Patchstack
5.3 Medium Civic Cookie Control Plugin civic-cookie-control-8 Broken Access Control No login needed ≤ 1.53 Fixed in 1.54 CVE-2026-22348 Patchstack
6.5 Medium Carousel Horizontal Posts Content Slider Plugin carousel-horizontal-posts-content-slider Cross-Site Scripting ≤ 3.3.2 CVE-2026-22347 Patchstack
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.9.15 Fixed in 1.6.9.17 CVE-2025-69315 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control Settings Change ≤ 4.11.63 Fixed in 4.11.64 CVE-2025-69300 Patchstack
6.5 Medium Reservation Plugin dt-reservation-plugin Broken Access Control Settings Change No login needed ≤ 1.7 CVE-2025-69095 Patchstack
6.5 Medium BM Content Builder Plugin bm-builder Path Traversal Arbitrary File Download ≤ 3.16.3.3 Fixed in 3.16.3.3 CVE-2025-69055 Patchstack
5.3 Medium FluentForm Plugin fluentform Arbitrary Shortcode Execution No login needed ≤ 6.1.11 Fixed in 6.1.12 CVE-2025-69001 Patchstack
6.5 Medium Solace Plugin solace Broken Access Control ≤ 2.1.16 CVE-2025-68911 Patchstack
6.5 Medium Enfold Theme enfold Cross-Site Scripting ≤ 7.1.3 Fixed in 7.1.4 CVE-2025-68900 Patchstack
5.8 Medium Synergy Project Manager Plugin synergy-project-manager Cross-Site Scripting No login needed ≤ 1.5 CVE-2025-68898 Patchstack
6.5 Medium WDV One Page Docs Plugin wdv-one-page-docs Broken Access Control No login needed ≤ 1.2.4 CVE-2025-68896 Patchstack
6.5 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 4.0.4 Fixed in 4.0.5 CVE-2025-68558 Patchstack
6.5 Medium Icegram Plugin icegram Broken Access Control No login needed ≤ 3.1.35 Fixed in 3.1.36 CVE-2025-68507 Patchstack
6.5 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68073 Patchstack
6.5 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.20 Fixed in 3.5.21 CVE-2025-68072 Patchstack
6.5 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-68046 Patchstack
6.5 Medium WP BackItUp Plugin wp-backitup Broken Access Control No login needed ≤ 2.1.0 CVE-2025-68039 Patchstack
6.5 Medium Notifier Plugin notifier Broken Access Control No login needed ≤ 2.7.13 Fixed in 3.0.0 CVE-2025-68020 Patchstack
6.5 Medium SEO Booster Plugin seo-booster Broken Access Control No login needed ≤ 6.1.8 CVE-2025-68019 Patchstack
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only