WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,701–1,750 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Gecko Theme gecko Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.8 CVE-2026-27375 Patchstack
7.5 High WooCommerce Order Details Plugin woocommerce-order-details Broken Access Control No login needed ≤ 3.1 CVE-2026-27374 Patchstack
8.5 High Tablesome Plugin tablesome SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-27373 Patchstack
7.5 High Chaty Plugin chaty Information Disclosure Sensitive Data Exposure No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-27370 Patchstack
8.1 High Celeste Theme celeste PHP Object Injection No login needed ≤ 1.3.6 CVE-2026-27369 Patchstack
7.1 High Musico Theme musico Cross-Site Scripting No login needed ≤ 3.4.5 Fixed in 3.4.5 CVE-2026-27367 Patchstack
7.1 High WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2026-27363 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
7.1 High Awa Plugins Plugin awa-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2026-27359 Patchstack
7.1 High Architecturer Theme architecturer Cross-Site Scripting No login needed ≤ 3.9.5 Fixed in 3.9.5 CVE-2026-27358 Patchstack
7.1 High Grand News Theme grandnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.3 CVE-2026-27353 Patchstack
7.1 High Starto Theme starto Cross-Site Scripting No login needed ≤ 2.2.5 Fixed in 2.2.5 CVE-2026-27352 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.6 Fixed in 7.7.6 CVE-2026-27348 Patchstack
8.1 High TopFit - Fitness and Gym Theme topfit Local File Inclusion Fitness and Gym WordPress Theme theme <= 1.9 - Local File Inclusion No login needed ≤ 1.9 CVE-2026-27342 Patchstack
8.1 High TopScorer - Sports Theme topscorer Local File Inclusion Sports WordPress Theme theme <= 1.2 - Local File Inclusion No login needed ≤ 1.2 CVE-2026-27341 Patchstack
8.1 High Apollo | Night Club, DJ Event Theme apollo Local File Inclusion No login needed ≤ 1.3.1 CVE-2026-27340 Patchstack
8.1 High Buzz Stone | Magazine & Viral Blog Theme buzzstone Local File Inclusion No login needed ≤ 1.0.2 CVE-2026-27339 Patchstack
8.8 High Car Zone Theme carzone PHP Object Injection Deserialization of untrusted data ≤ 3.7 CVE-2026-27338 Patchstack
8.1 High Chronicle - Lifestyle Magazine & Blog Theme chronicle Local File Inclusion Lifestyle Magazine & Blog WordPress Theme theme <= 1.0 - Local File Inclusion No login needed ≤ 1.0 CVE-2026-27337 Patchstack
8.1 High Consultor | Consulting, Accounting & Legal Counsel Theme consultor Local File Inclusion No login needed ≤ 1.2.4 CVE-2026-27336 Patchstack
8.1 High Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra Local File Inclusion NonProfit, Green Energy & Ecology Theme theme <= 1.0.0 - Local File Inclusion No login needed ≤ 1.0.0 CVE-2026-27335 Patchstack
8.1 High Alchemists Theme alchemists Local File Inclusion No login needed ≤ 4.6.0 CVE-2026-27334 Patchstack
7.1 High Agrofood Theme agrofood Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.0 CVE-2026-27332 Patchstack
8.1 High AC Services | HVAC, Air Conditioning & Heating Company Theme window-ac-services Local File Inclusion No login needed ≤ 1.2.5 CVE-2026-27326 Patchstack
8.1 High Au Pair Agency - Babysitting & Nanny Theme au-pair-agency PHP Object Injection Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data No login needed ≤ 1.2.2 CVE-2026-27098 Patchstack
8.1 High CasaMia | Property Rental Real Estate Theme casamia Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-27097 Patchstack
7.2 High Amelia Plugin ameliabooking Privilege Escalation ≤ 1.2.38 Fixed in 2.0 CVE-2026-24963 Patchstack
7.5 High Podlove Web Player Plugin podlove-web-player PHP Object Injection ≤ 5.9.1 Fixed in 5.9.2 CVE-2026-24385 Patchstack
8.1 High The Issue Theme theissue Local File Inclusion No login needed ≤ 1.6.11 Fixed in 1.6.12 CVE-2026-23801 Patchstack
8.8 High PowerPress Podcasting Plugin powerpress PHP Object Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-23798 Patchstack
7.5 High Easy Post Submission Plugin easy-post-submission Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.5.0 CVE-2026-22479 Patchstack
8.1 High FindAll Theme findall Local File Inclusion No login needed ≤ 1.4 CVE-2026-22478 Patchstack
8.1 High Felizia Theme felizia Local File Inclusion No login needed ≤ 1.3.4 CVE-2026-22477 Patchstack
8.1 High Etchy Theme etchy Local File Inclusion No login needed ≤ 1.0 CVE-2026-22476 Patchstack
8.8 High Dental Clinic Theme dental PHP Object Injection ≤ 3.7 CVE-2026-22473 Patchstack
8.8 High Secudeal Payments for Ecommerce Plugin secudeal-payments-for-ecommerce PHP Object Injection ≤ 1.1 CVE-2026-22471 Patchstack
7.1 High DeepDigital Theme deepdigital Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2026-22467 Patchstack
7.1 High BuddyApp Theme buddyapp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2026-22465 Patchstack
8.6 High FormGent Plugin formgent Arbitrary File Deletion No login needed ≤ 1.7.0 CVE-2026-22460 Patchstack
8.1 High Wanderland Plugin wanderland Local File Inclusion No login needed ≤ 1.5 CVE-2026-22457 Patchstack
8.1 High Askka Theme askka Local File Inclusion No login needed ≤ 1.0 CVE-2026-22456 Patchstack
7.1 High Thebe Theme thebe Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2026-22455 Patchstack
8.1 High Hoverex Theme hoverex Local File Inclusion No login needed ≤ 1.5.10 CVE-2026-22452 Patchstack
8.1 High Don Peppe Theme donpeppe Local File Inclusion No login needed ≤ 1.3 CVE-2026-22449 Patchstack
8.1 High Prowess Theme prowess Local File Inclusion No login needed ≤ 1.8.1 CVE-2026-22446 Patchstack
8.1 High Alliance Theme alliance Local File Inclusion No login needed ≤ 3.1.1 CVE-2026-22443 Patchstack
8.1 High Tribe Theme tribe Local File Inclusion No login needed ≤ 1.7.3 CVE-2026-22442 Patchstack
8.1 High Zentrum Theme zentrum Local File Inclusion No login needed ≤ 1.0 CVE-2026-22441 Patchstack
7.1 High Thecs Theme thecs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.7 CVE-2026-22440 Patchstack
8.1 High Green Planet Theme green-planet Local File Inclusion No login needed ≤ 1.1.14 CVE-2026-22439 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only