WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,401–2,450 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 49 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Penci Soledad Data Migrator Plugin penci-data-migrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 CVE-2026-27054 Patchstack
8.1 High The Aisle Core Plugin theaisle-core Local File Inclusion No login needed ≤ 2.0.5 CVE-2026-27048 Patchstack
8.1 High Curly Core Plugin curly-core Local File Inclusion No login needed ≤ 2.1.6 Fixed in 2.2.2 CVE-2026-27047 Patchstack
8.8 High WooCommerce Infinite Scroll Plugin sb-woocommerce-infinite-scroll PHP Object Injection ≤ 1.6.2 CVE-2026-27045 Patchstack
8.8 High WZone Plugin woozone Arbitrary File Deletion ≤ 14.0.31 CVE-2026-27040 Patchstack
8.5 High WZone Plugin woozone SQL Injection ≤ 14.0.31 CVE-2026-27039 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2026-25464 Patchstack
7.1 High Listeo Core Plugin listeo-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.21 CVE-2026-25461 Patchstack
8.1 High Moments Theme moments Local File Inclusion No login needed ≤ 2.2 CVE-2026-25458 Patchstack
8.1 High Mixtape Plugin mixtape Local File Inclusion No login needed ≤ 2.1 CVE-2026-25457 Patchstack
7.3 High Automated FedEx live/manual rates with shipping labels Plugin a2z-fedex-shipping Broken Access Control No login needed ≤ 5.1.9 CVE-2026-25456 Patchstack
7.1 High Remoji Plugin remoji Cross-Site Scripting No login needed ≤ 2.2 CVE-2026-25452 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
8.8 High WPBookit Pro Plugin wpbookit-pro Privilege Escalation ≤ 1.6.18 CVE-2026-25414 Patchstack
8.1 High Tutor LMS Pro Plugin tutor-pro Authentication Bypass Broken Authentication No login needed ≤ 3.9.4 CVE-2026-25406 Patchstack
7.5 High WPCargo Track & Trace Plugin wpcargo Broken Access Control No login needed ≤ 8.0.2 CVE-2026-25401 Patchstack
8.8 High Apicona Theme apicona PHP Object Injection ≤ 24.1.0 CVE-2026-25400 Patchstack
7.5 High File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Path Traversal No login needed ≤ 1.0.4 CVE-2026-25397 Patchstack
7.5 High Commerce Coinbase For WooCommerce Plugin commerce-coinbase-for-woocommerce Broken Access Control No login needed ≤ 1.6.6 CVE-2026-25396 Patchstack
7.1 High KiviCare Plugin kivicare-clinic-management-system Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.16 Fixed in 4.0.0 CVE-2026-25383 Patchstack
8.1 High IdealAuto Theme idealauto Local File Inclusion No login needed ≤ 3.8.6 Fixed in 3.8.6 CVE-2026-25382 Patchstack
8.1 High LoveDate Theme lovedate Local File Inclusion No login needed ≤ 3.8.6 Fixed in 3.8.6 CVE-2026-25381 Patchstack
8.1 High Feedy Theme feedy Local File Inclusion No login needed ≤ 2.1.5 Fixed in 2.1.5 CVE-2026-25380 Patchstack
8.1 High StreamVid Theme streamvid Local File Inclusion No login needed ≤ 6.8.6 Fixed in 6.8.6 CVE-2026-25379 Patchstack
7.1 High Addon Jobsearch Chat Plugin addon-jobsearch-chat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0 Fixed in 3.1 CVE-2026-25376 Patchstack
7.1 High Vayvo Theme vayvo-progression Cross-Site Scripting Media Streaming & Membership WordPress Theme theme < 6.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 6.8 Fixed in 6.8 CVE-2026-25373 Patchstack
7.1 High WpEvently Plugin mage-eventpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.4 Fixed in 5.1.5 CVE-2026-25361 Patchstack
8.8 High Vex Theme vex PHP Object Injection ≤ 1.2.9 Fixed in 1.2.9 CVE-2026-25360 Patchstack
8.8 High Pendulum Theme pendulum PHP Object Injection ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-25359 Patchstack
8.8 High Meloo Theme meloo PHP Object Injection ≤ 2.8.2 Fixed in 2.8.2 CVE-2026-25358 Patchstack
8.1 High Ultimate Membership Pro Plugin indeed-membership-pro Privilege Escalation Account Takeover No login needed ≤ 13.7 Fixed in 13.7.1 CVE-2026-25357 Patchstack
7.1 High Yobazar Theme yobazar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.7 CVE-2026-25356 Patchstack
7.1 High Reebox Theme reebox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2026-25354 Patchstack
7.1 High Nooni Theme nooni Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.1 CVE-2026-25353 Patchstack
7.1 High MyDecor Theme mydecor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.9 Fixed in 1.5.9 CVE-2026-25352 Patchstack
7.1 High MyMedi Theme mymedi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.7 Fixed in 1.7.7 CVE-2026-25351 Patchstack
7.1 High Miti Theme miti Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.3 CVE-2026-25350 Patchstack
7.1 High Loobek Theme loobek Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.2 CVE-2026-25349 Patchstack
7.1 High WP REST Cache Plugin wp-rest-cache Cross-Site Scripting No login needed ≤ 2026.1.0 Fixed in 2026.1.1 CVE-2026-25347 Patchstack
7.1 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-25346 Patchstack
7.1 High Boutique Theme kute-boutique Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2026-25342 Patchstack
7.1 High RSFirewall! Plugin rsfirewall Cross-Site Scripting No login needed ≤ 1.1.45 Fixed in 1.1.46 CVE-2026-25341 Patchstack
8.1 High Salon Booking System Pro Plugin salon-booking-plugin-pro Privilege Escalation Account Takeover No login needed ≤ 10.30.12 Fixed in 10.30.12 CVE-2026-25334 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-25317 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Broken Access Control No login needed ≤ 4.10.1 Fixed in 4.11.0 CVE-2026-25309 Patchstack
7.1 High XStore Core Plugin et-core-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-25306 Patchstack
7.1 High Jaroti Theme jaroti Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 Fixed in 1.4.8 CVE-2026-25304 Patchstack
7.1 High Motta Addons Plugin motta-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.1 CVE-2026-25033 Patchstack
7.5 High Team Plugin tlp-team Broken Access Control No login needed ≤ 5.0.11 Fixed in 5.0.12 CVE-2026-25026 Patchstack
7.1 High VikRestaurants Plugin vikrestaurants Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-25025 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only