WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,401–2,450 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 49 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
7.1 High WP Mail Log Plugin wp-mail-log Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.1.1 CVE-2023-33999 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
9.8 Critical Woody Code Snippets Plugin insert-php Remote Code Execution WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API No login needed < 3.3.1 Fixed in 3.3.1 CVE-2017-20251 VulnCheck
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
8.2 High KittyCatfish Plugin SQL Injection KittyCatfish 2.2 Plugin for WordPress SQL Injection No login needed 2.2 CVE-2017-20246 VulnCheck
8.2 High Wow Viral Signups Plugin mwp-viral-signup SQL Injection Wow Viral Signups 2.1 WordPress Plugin SQL Injection No login needed 2.1 CVE-2017-20245 VulnCheck
8.2 High Wow Forms Plugin mwp-forms SQL Injection Wow Forms WordPress Plugin 2.1 SQL Injection No login needed 2.1 CVE-2017-20244 VulnCheck
8.2 High Product Catalog 8 Plugin product-catalog-8 SQL Injection Product Catalog 8 1.2 Plugin WordPress SQL Injection No login needed 1.2.0 CVE-2016-20065 VulnCheck
7.1 High Single Personal Message Plugin simple-personal-message SQL Injection Single Personal Message 1.0.3 WordPress Plugin SQL Injection 1.0.3 CVE-2016-20063 VulnCheck
8.2 High Simply Poll Plugin simply-poll SQL Injection Simply Poll 1.4.1 Plugin for WordPress SQL Injection No login needed 1.4.1 CVE-2016-20062 VulnCheck
7.2 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Text No login needed ≤ 7.5.49.7212 CVE-2026-7556 Wordfence
9.8 Critical Travelscape Theme travelscape Arbitrary File Upload WordPress Theme Travelscape 1.0.3 Arbitrary File Upload No login needed 1.0.3 CVE-2024-58349 VulnCheck
9.8 Critical Background Image Cropper Plugin background-image-cropper Remote Code Execution WordPress Background Image Cropper 1.2 Remote Code Execution No login needed 1.2 CVE-2024-58348 VulnCheck
6.2 Medium admin-word-count-column Plugin admin-word-count-column Path Traversal WordPress Plugin admin-word-count-column 2.2 Local File Read No login needed 2.2 CVE-2022-50953 VulnCheck
6.4 Medium WP24 Domain Check Plugin wp24-domain-check Cross-Site Scripting WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS 1.6.2 CVE-2021-47984 VulnCheck
6.4 Medium Accept Stripe Payments Plugin stripe-payments Cross-Site Scripting WordPress Plugin Stripe Payments < 2.0.40 Stored XSS via currency_code < 2.0.40 Fixed in 2.0.40 CVE-2021-47983 VulnCheck
6.4 Medium WP-Paginate Plugin wp-paginate Cross-Site Scripting WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset 2.1.3 CVE-2021-47982 VulnCheck
5.3 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Broken Access Control Unauthenticated Insecure Direct Object Reference via REST API Endpoints No login needed ≤ 2.96.6 CVE-2026-8839 Wordfence
10.0 Critical Product Slider Pro for WooCommerce Plugin woo-product-slider-pro Other Backdoor No login needed < 3.5.4 Fixed in 3.5.4 CVE-2026-49777 Patchstack
8.2 High Google Review Slider Plugin wp-google-places-review-slider SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed 6.1 CVE-2019-25745 VulnCheck
5.4 Medium Popup Builder Plugin popup-builder Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting 3.49 CVE-2019-25744 VulnCheck
5.4 Medium Soliloquy Lite Plugin soliloquy-lite Cross-Site Scripting WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting 2.5.6 CVE-2019-25743 VulnCheck
5.4 Medium Zoner Real Estate Theme Cross-Site Scripting WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS 4.1.1 CVE-2019-25742 VulnCheck
9.8 Critical Ad Manager WD Plugin Path Traversal WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download No login needed 1.0.11 CVE-2019-25727 VulnCheck
5.3 Medium WP eMember Plugin wp-emember Information Disclosure Sensitive Data Exposure No login needed ≤ v10.2.2 CVE-2026-49077 Patchstack
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
8.8 High School Management Plugin school-management Privilege Escalation ≤ 93.2.0 CVE-2025-15656 Patchstack
7.6 High School Management Plugin school-management SQL Injection ≤ 93.2.0 CVE-2025-15655 Patchstack
7.1 High Prague Plugin prague-plugins Cross-Site Scripting No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-15654 Patchstack
7.5 High BookIt Plugin bookit Authentication Bypass Broken Authentication No login needed < 2.5.4.1 Fixed in 2.5.4.1 CVE-2026-40780 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
5.4 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2026-49782 Patchstack
5.4 Medium Crew HRM Plugin hr-management Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-27351 Patchstack
5.9 Medium Progress Planner Plugin progress-planner Cross-Site Scripting ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-28116 Patchstack
8.1 High Cookiteer Theme cookiteer Local File Inclusion No login needed ≤ 1.4.8 CVE-2025-68886 Patchstack
8.1 High Racquet Theme racquet Local File Inclusion No login needed ≤ 1.12.0 CVE-2025-69369 Patchstack
8.1 High Fermentio Theme fermentio Local File Inclusion No login needed ≤ 1.5.0 CVE-2025-58897 Patchstack
8.1 High Spin Theme spin Local File Inclusion No login needed ≤ 1.8 CVE-2025-58707 Patchstack
8.1 High Askka Theme askka PHP Object Injection No login needed ≤ 1.3.1 Fixed in 1.4 CVE-2026-39555 Patchstack
8.1 High WaveRide Theme waveride Local File Inclusion No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-39553 Patchstack
8.1 High Blueprint Theme blueprint Local File Inclusion No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-39552 Patchstack
8.1 High Töbel Theme tobel PHP Object Injection No login needed ≤ 1.8.1 Fixed in 1.9 CVE-2026-39551 Patchstack
8.1 High Aperitif Theme aperitif PHP Object Injection No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-39550 Patchstack
7.1 High WP Job Portal Plugin wp-job-portal Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42685 Patchstack
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42684 Patchstack
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Payment Bypass No login needed ≤ 2.7.14 Fixed in 2.7.15 CVE-2026-42670 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only