WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,951–2,000 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 40 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Hustle Plugin wordpress-popup Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upoload via Module Import ≤ 7.8.9.2 CVE-2026-0911 Wordfence
7.5 High EduBlink Core Plugin edublink-core Local File Inclusion ≤ 2.0.7 CVE-2026-24635 Patchstack
7.6 High Neoforum Plugin neoforum SQL Injection ≤ 1.0 CVE-2026-24624 Patchstack
7.1 High Neoforum Plugin neoforum Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2026-24623 Patchstack
7.5 High Laurent Theme laurent Local File Inclusion ≤ 3.1 CVE-2026-24609 Patchstack
7.5 High Laurent Core Plugin laurent-core Local File Inclusion ≤ 2.4.1 CVE-2026-24608 Patchstack
8.5 High Nelio Content Plugin nelio-content SQL Injection ≤ 4.2.0 Fixed in 4.2.1 CVE-2026-24572 Patchstack
7.5 High Omnipress Plugin omnipress Local File Inclusion ≤ 1.6.7 CVE-2026-24538 Patchstack
7.5 High Prowess Theme prowess Local File Inclusion ≤ 2.3 CVE-2026-24531 Patchstack
7.5 High Kentha Elementor Widgets Plugin kentha-elementor Local File Inclusion ≤ 3.1 Fixed in 3.1 CVE-2026-24390 Patchstack
8.5 High Traveler Plugin traveler SQL Injection ≤ 3.2.8 Fixed in 3.2.8 CVE-2026-24367 Patchstack
7.5 High Gyan Elements Plugin gyan-elements Local File Inclusion ≤ 2.2.1 Fixed in 2.2.2 CVE-2026-23978 Patchstack
7.5 High Golo Plugin golo Local File Inclusion ≤ 1.7.5 Fixed in 1.7.5 CVE-2026-23975 Patchstack
7.6 High FireStorm Professional Real Estate Plugin fs-real-estate-plugin SQL Injection ≤ 2.7.11 CVE-2026-22470 Patchstack
7.5 High My auctions allegro Plugin my-auctions-allegro-free-edition Local File Inclusion ≤ 3.6.33 Fixed in 3.6.34 CVE-2026-22464 Patchstack
7.5 High Triply Theme triply Local File Inclusion ≤ 2.4.7 CVE-2026-22402 Patchstack
7.5 High Freshio Theme freshio Local File Inclusion ≤ 2.4.2 CVE-2026-22401 Patchstack
7.1 High Simple XML Sitemap Plugin simple-xml-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2026-22355 Patchstack
7.1 High Grand Spa Plugin grandspa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-69321 Patchstack
7.1 High Grand Magazine Theme grandmagazine Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-69320 Patchstack
7.5 High Beaver Builder Plugin beaver-builder-lite-version Remote Code Execution Arbitrary Code Execution ≤ 2.9.4.1 Fixed in 2.9.4.2 CVE-2025-69319 Patchstack
7.1 High JobWP Plugin jobwp Cross-Site Scripting No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-69318 Patchstack
7.1 High CarSpot Plugin carspot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2025-69317 Patchstack
7.1 High TableOn Plugin posts-table-filterable Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4.2 Fixed in 1.0.4.3 CVE-2025-69316 Patchstack
8.1 High Werkstatt Plugin werkstatt Local File Inclusion No login needed ≤ 4.8.3 Fixed in 4.8.3 CVE-2025-69314 Patchstack
7.5 High PostX Plugin ultimate-post Broken Access Control No login needed ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-69313 Patchstack
7.6 High Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-69311 Patchstack
8.8 High Final User Plugin final-user Privilege Escalation ≤ 1.2.5 CVE-2025-69293 Patchstack
8.8 High WP Membership Plugin wp-membership Privilege Escalation ≤ 1.6.4 CVE-2025-69292 Patchstack
7.3 High WP Membership Plugin wp-membership Broken Access Control No login needed ≤ 1.6.4 CVE-2025-69193 Patchstack
7.3 High Real Estate Pro Plugin real-estate-pro Broken Access Control No login needed ≤ 2.1.5 CVE-2025-69192 Patchstack
7.3 High ListingHub Plugin listinghub Broken Access Control No login needed ≤ 1.2.7 CVE-2025-69191 Patchstack
7.3 High Listihub Theme listihub Broken Access Control No login needed ≤ 1.0.6 CVE-2025-69190 Patchstack
7.3 High fitness-trainer Plugin fitness-trainer Broken Access Control No login needed ≤ 1.7.1 CVE-2025-69188 Patchstack
7.3 High Final User Plugin final-user Broken Access Control No login needed ≤ 1.2.5 CVE-2025-69187 Patchstack
7.3 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control No login needed ≤ 1.3.9 CVE-2025-69186 Patchstack
7.3 High Hotel Listing Plugin hotel-listing Broken Access Control No login needed ≤ 1.4.2 CVE-2025-69185 Patchstack
7.3 High Institutions Directory Plugin institutions-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69184 Patchstack
8.8 High Hospital Doctor Directory Plugin hospital-doctor-directory Privilege Escalation ≤ 1.3.9 CVE-2025-69183 Patchstack
8.8 High Institutions Directory Plugin institutions-directory Privilege Escalation ≤ 1.3.4 CVE-2025-69182 Patchstack
7.3 High Lawyer Directory Plugin lawyer-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69181 Patchstack
8.5 High Ultra Portfolio Plugin ultra-portfolio SQL Injection ≤ 6.7 CVE-2025-69180 Patchstack
7.1 High WP Test Email Plugin wp-test-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.7 CVE-2025-69102 Patchstack
8.1 High North Theme north-wp Local File Inclusion No login needed ≤ 5.7.5 CVE-2025-69100 Patchstack
8.8 High North Theme north-wp PHP Object Injection ≤ 5.7.5 CVE-2025-69099 Patchstack
7.1 High Hide My WP Plugin hide_my_wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.2.12 CVE-2025-69098 Patchstack
8.6 High WPLMS Plugin wplms_plugin Arbitrary File Deletion No login needed ≤ 1.9.9.5.4 CVE-2025-69097 Patchstack
8.1 High Malta Theme malta Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-69078 Patchstack
8.1 High Hobo Theme hobo Local File Inclusion No login needed ≤ 1.0.10 CVE-2025-69077 Patchstack
8.1 High Modern Housewife Theme modernhousewife Local File Inclusion No login needed ≤ 1.0.12 CVE-2025-69076 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only