WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,701–1,750 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium LIQUID SPEECH BALLOON Plugin liquid-speech-balloon Cross-Site Scripting ≤ 1.2.5 CVE-2026-65527 Patchstack
5.3 Medium Civi Framework Plugin civi-framework Broken Access Control No login needed ≤ 2.2.0 CVE-2026-65525 Patchstack
4.3 Medium Avada Custom Branding Plugin fusion-white-label-branding Broken Access Control ≤ 1.2 CVE-2026-65524 Patchstack
6.5 Medium Manual - Documentation, Knowledge Base & Education Theme manual Cross-Site Scripting Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) ≤ 7.5.4 CVE-2026-65522 Patchstack
5.3 Medium WP Social Ninja Plugin wp-social-reviews Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-65521 Patchstack
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting ≤ 2.7.7.29 Fixed in 2.7.7.30 CVE-2026-65519 Patchstack
6.5 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-65518 Patchstack
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting ≤ 1.5.86 Fixed in 1.5.87 CVE-2026-65514 Patchstack
5.4 Medium WP Activity Log Plugin wp-security-audit-log Cross-Site Request Forgery No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-65512 Patchstack
5.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control No login needed ≤ 5.12 Fixed in 5.13 CVE-2026-65506 Patchstack
5.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65505 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65503 Patchstack
5.3 Medium Shiptastic for WooCommerce Plugin shiptastic-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65501 Patchstack
6.5 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control No login needed ≤ 2.2.6 CVE-2026-65499 Patchstack
5.3 Medium Complianz Plugin complianz-gdpr Information Disclosure Sensitive Data Exposure No login needed ≤ 7.5.0 CVE-2026-65498 Patchstack
4.4 Medium Complianz Plugin complianz-gdpr Server-Side Request Forgery ≤ 7.5.0 CVE-2026-65496 Patchstack
4.3 Medium Query Wrangler Plugin query-wrangler Broken Access Control ≤ 1.5.57 CVE-2026-65491 Patchstack
5.3 Medium Create Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-65490 Patchstack
5.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65489 Patchstack
5.3 Medium Photography Theme photography Broken Access Control No login needed ≤ 7.7.6 CVE-2026-65487 Patchstack
5.3 Medium Event post Plugin event-post Broken Access Control No login needed ≤ 6.0.1 CVE-2026-65486 Patchstack
5.3 Medium Content Control Plugin content-control Broken Access Control No login needed ≤ 2.6.5 CVE-2026-65485 Patchstack
6.3 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 CVE-2026-65484 Patchstack
5.9 Medium HashThemes Demo Importer Plugin hashthemes-demo-importer Cross-Site Scripting ≤ 1.4.2 CVE-2026-65483 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.6.3 CVE-2026-65482 Patchstack
6.5 Medium TheGem Theme thegem Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-65480 Patchstack
5.4 Medium Reviewer Plugin reviewer Broken Access Control ≤ 3.14.2 CVE-2026-65479 Patchstack
5.4 Medium ListingPro Plugin listingpro-plugin Broken Access Control ≤ 2.9.10 CVE-2026-65478 Patchstack
5.3 Medium Civi Theme civi Broken Access Control No login needed ≤ 2.2.4 CVE-2026-65476 Patchstack
5.3 Medium Ninja Tables Plugin ninja-tables Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.10 Fixed in 5.2.11 CVE-2026-65474 Patchstack
6.5 Medium Virtue/Ascend/Pinnacle Toolkit Plugin virtue-toolkit Cross-Site Scripting ≤ 4.9.12 Fixed in 4.9.12.1 CVE-2026-65473 Patchstack
5.3 Medium Kit (formerly ConvertKit) Plugin convertkit Broken Access Control No login needed ≤ 3.3.5 Fixed in 3.3.6 CVE-2026-65472 Patchstack
6.5 Medium Fluent Support Plugin fluent-support Cross-Site Scripting ≤ 2.3.0 Fixed in 2.3.1 CVE-2026-65470 Patchstack
5.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control No login needed ≤ 4.4.7 Fixed in 4.4.8 CVE-2026-65469 Patchstack
5.3 Medium JetBooking Plugin jet-booking Broken Access Control No login needed ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65468 Patchstack
4.9 Medium JetEngine Plugin jet-engine Server-Side Request Forgery ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-65467 Patchstack
4.9 Medium JetBooking Plugin jet-booking Server-Side Request Forgery ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65466 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.1.1 Fixed in 2.9.1.2 CVE-2026-65465 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65464 Patchstack
5.4 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-65463 Patchstack
4.3 Medium Zarinpal Gateway Plugin zarinpal-woocommerce-payment-gateway Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65460 Patchstack
4.3 Medium Polylang Plugin polylang Information Disclosure Sensitive Data Exposure ≤ 3.8.5 Fixed in 3.8.6 CVE-2026-65458 Patchstack
4.3 Medium ЮKassa для WooCommerce Plugin yookassa Broken Access Control ≤ 2.16.1 Fixed in 2.16.2 CVE-2026-65457 Patchstack
4.3 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.13.62 Fixed in 1.13.63 CVE-2026-65456 Patchstack
5.3 Medium Ebook Store Plugin ebook-store Broken Access Control No login needed ≤ 6.19 Fixed in 6.20 CVE-2026-65453 Patchstack
5.3 Medium Ebook Store Plugin ebook-store Broken Access Control No login needed ≤ 6.19 Fixed in 6.20 CVE-2026-65452 Patchstack
6.5 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting ≤ 8.14.0 Fixed in 8.14.1 CVE-2026-65449 Patchstack
5.4 Medium Simple Link Directory Pro Plugin simple-link-directory-pro Cross-Site Request Forgery No login needed ≤ 15.0.8 Fixed in 15.0.9 CVE-2026-61981 Patchstack
4.3 Medium ShopLentor Pro Plugin woolentor-addons-pro Broken Access Control ≤ 2.8.5 Fixed in 2.8.6 CVE-2026-61973 Patchstack
5.3 Medium ShopLentor Pro Plugin woolentor-addons-pro Broken Access Control No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2026-61972 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only