WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,751–1,800 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 36 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High TheBi Theme thebi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2026-22438 Patchstack
8.1 High Playa Theme playa Local File Inclusion No login needed ≤ 1.3.9 CVE-2026-22437 Patchstack
8.1 High Helvig Theme helvig Local File Inclusion No login needed ≤ 1.0 CVE-2026-22436 Patchstack
8.1 High ElectroServ Theme electroserv Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-22435 Patchstack
8.1 High Crown Art Theme crown-art Local File Inclusion No login needed ≤ 1.2.11 CVE-2026-22434 Patchstack
8.1 High CloudMe Theme cloudme Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22433 Patchstack
8.1 High Woopy Theme woopy Local File Inclusion No login needed ≤ 1.2 CVE-2026-22432 Patchstack
8.1 High Wabi-Sabi Theme wabi-sabi Local File Inclusion No login needed ≤ 1.2 CVE-2026-22431 Patchstack
8.1 High Verdure Theme verdure Local File Inclusion No login needed ≤ 1.6 CVE-2026-22429 Patchstack
8.1 High Tooth Fairy Theme tooth-fairy Local File Inclusion No login needed ≤ 1.16 CVE-2026-22428 Patchstack
8.1 High GoTravel Theme gotravel Local File Inclusion No login needed ≤ 2.1 CVE-2026-22427 Patchstack
8.1 High Sweet Jane Theme sweetjane Local File Inclusion No login needed ≤ 1.2 CVE-2026-22425 Patchstack
8.1 High Shaha Theme shaha Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-22424 Patchstack
8.1 High SetSail Theme setsail Local File Inclusion No login needed ≤ 1.8 CVE-2026-22423 Patchstack
8.1 High Quantum Theme quantum Local File Inclusion No login needed ≤ 1.0 CVE-2026-22421 Patchstack
8.1 High Horizon Theme horizon Local File Inclusion No login needed ≤ 1.1 CVE-2026-22420 Patchstack
8.1 High Honor Theme honor Local File Inclusion No login needed ≤ 2.3 CVE-2026-22419 Patchstack
8.1 High Great Lotus Theme great-lotus Local File Inclusion No login needed ≤ 1.3.1 CVE-2026-22418 Patchstack
8.1 High FixTeam Theme fixteam Local File Inclusion No login needed ≤ 1.5.0 CVE-2026-22416 Patchstack
8.1 High The Mounty Theme the-mounty Local File Inclusion No login needed ≤ 1.1 CVE-2026-22415 Patchstack
8.1 High Marra Theme marra Local File Inclusion No login needed ≤ 1.2 CVE-2026-22414 Patchstack
8.1 High Malgré Theme malgre Local File Inclusion No login needed ≤ 1.0.3 CVE-2026-22413 Patchstack
8.1 High Eona Theme eona Local File Inclusion No login needed ≤ 1.3 CVE-2026-22412 Patchstack
8.1 High Dolcino Theme dolcino Local File Inclusion No login needed ≤ 1.6 CVE-2026-22410 Patchstack
8.1 High Justicia Theme justicia Local File Inclusion No login needed ≤ 1.2 CVE-2026-22408 Patchstack
8.1 High Overton Theme overton Local File Inclusion No login needed ≤ 1.3 CVE-2026-22405 Patchstack
8.1 High Innovio Theme innovio Local File Inclusion No login needed ≤ 1.9 Fixed in 1.9.1 CVE-2026-22403 Patchstack
8.1 High Holmes Theme holmes Local File Inclusion No login needed ≤ 1.7 CVE-2026-22399 Patchstack
8.1 High Fleur Theme fleur Local File Inclusion No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2026-22397 Patchstack
8.1 High Fiorello Theme fiorello Local File Inclusion No login needed ≤ 1.0 CVE-2026-22395 Patchstack
8.1 High Evently Theme evently Local File Inclusion No login needed ≤ 1.7 CVE-2026-22394 Patchstack
8.1 High Cortex Theme cortex Local File Inclusion No login needed ≤ 1.9 Fixed in 2.0 CVE-2026-22392 Patchstack
8.1 High Cocco Theme cocco Local File Inclusion No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-22389 Patchstack
8.1 High Aviana Theme aviana Local File Inclusion No login needed ≤ 2.1 CVE-2026-22387 Patchstack
8.1 High Wolmart Theme wolmart Local File Inclusion No login needed ≤ 1.9.6 CVE-2026-22385 Patchstack
7.5 High ionCube tester plus Plugin ioncube-tester-plus Path Traversal Arbitrary File Download No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-69411 Patchstack
7.5 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69340 Patchstack
8.1 High Molla Plugin molla Local File Inclusion No login needed ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-69339 Patchstack
8.1 High Remons Theme remons Local File Inclusion No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-69090 Patchstack
8.1 High Berger Theme berger Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-53335 Patchstack
7.2 High uListing Plugin ulisting PHP Object Injection ≤ 2.2.0 CVE-2026-28138 Patchstack
7.6 High WP SMS Plugin wp-sms SQL Injection ≤ 6.9.12 Fixed in 7.0 CVE-2026-28136 Patchstack
7.1 High PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) No login needed ≤ 11.2.0.1 Fixed in 11.2.0.2 CVE-2026-27072 Patchstack
8.5 High JS Help Desk Plugin js-support-ticket SQL Injection ≤ 3.0.1 Fixed in 3.0.2 CVE-2026-24959 Patchstack
7.1 High Whizz Plugins Plugin whizz-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 Fixed in 2.0.0 CVE-2026-24955 Patchstack
7.5 High Authorsy Plugin authorsy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-24950 Patchstack
7.1 High PhotoMe Theme photome Cross-Site Scripting No login needed ≤ 5.7.1 Fixed in 5.7.2 CVE-2026-24949 Patchstack
7.1 High Reflector Plugin reflector-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-24948 Patchstack
7.1 High Grand Conference Plugin grandconference Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-24943 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2026-24941 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only