WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,501–2,550 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 51 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Hypnotherapy Theme hypnotherapy Local File Inclusion No login needed ≤ 1.2.10 CVE-2026-22496 Patchstack
8.1 High Greenville Theme greenville Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-22495 Patchstack
8.1 High Good Homes Theme good-homes Local File Inclusion No login needed ≤ 1.3.13 CVE-2026-22494 Patchstack
8.1 High Gaspard Theme gaspard Local File Inclusion No login needed ≤ 1.3 CVE-2026-22493 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.35 CVE-2026-22491 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
7.5 High PitchPrint Plugin pitchprint Arbitrary File Deletion No login needed ≤ 11.1.2 Fixed in 11.2.0 CVE-2026-22448 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.2.6.0 Fixed in 4.2.7.0 CVE-2025-69358 Patchstack
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
7.1 High Zorka Theme zorka Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 CVE-2025-69096 Patchstack
7.5 High JetEngine Plugin jet-engine SQL Injection Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter No login needed ≤ 3.8.6.1 CVE-2026-4662 Wordfence
8.1 High Contest Gallery Plugin contest-gallery Privilege Escalation Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion No login needed ≤ 28.1.5 CVE-2026-4021 Wordfence
8.8 High JupiterX Core Plugin jupiterx-core Broken Access Control Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import ≤ 4.14.1 CVE-2026-3533 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal SQL Injection Unauthenticated SQL Injection via 'radius' Parameter No login needed ≤ 2.4.8 CVE-2026-4306 Wordfence
7.3 High ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Remote Code Execution WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution No login needed ≤ 2.2.12 CVE-2025-10679 Wordfence
7.5 High WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Plugin wp-google-map-plugin SQL Injection Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter No login needed ≤ 4.9.1 CVE-2026-2580 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Privilege Escalation WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module ≤ 3.2.4 CVE-2026-4314 Wordfence
8.1 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Privilege Escalation to Administrator via save_extra_user_profile_fields No login needed ≤ 1.29.7 CVE-2026-3629 Wordfence
7.5 High JetFormBuilder Plugin jetformbuilder Path Traversal Unauthenticated Arbitrary File Read via Media Field No login needed ≤ 3.5.6.2 CVE-2026-4373 Wordfence
7.2 High Content Syndication Toolkit Plugin content-syndication-toolkit Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.3 CVE-2026-3478 Wordfence
8.8 High Expire Users Plugin expire-users Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via save_extra_user_profile_fields ≤ 1.2.2 CVE-2026-4261 Wordfence
7.2 High Performance Monitor Plugin performance-monitor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.0.6 CVE-2026-1648 Wordfence
8.1 High Invelity Products Feeds Plugin invelity-products-feeds Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion ≤ 1.2.6 CVE-2025-14037 Wordfence
8.3 High MimeTypes Link Icons Plugin mimetypes-link-icons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Crafted Links in Post Content No login needed ≤ 3.2.20 CVE-2026-1313 Wordfence
7.2 High Vagaro Booking Widget Plugin vagaro-booking-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' No login needed ≤ 0.3 CVE-2026-3003 Wordfence
7.5 High Quentn WP Plugin quentn-wp SQL Injection Unauthenticated SQL Injection via 'qntn_wp_access' Cookie No login needed ≤ 1.2.12 CVE-2026-2468 Wordfence
8.8 High Linksy Search and Replace Plugin linksy-search-and-replace Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Update via linksy_search_and_replace_item_details ≤ 1.0.4 CVE-2026-2941 Wordfence
7.2 High SurveyJS: Drag & Drop Form Builder Plugin surveyjs Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.5.3 CVE-2026-2440 Wordfence
7.5 High Fonts Manager | Custom Fonts Plugin fonts-manager-custom-fonts SQL Injection Unauthenticated SQL Injection via fmcfIdSelectedFnt parameter No login needed ≤ 1.2 CVE-2026-1800 Wordfence
8.8 High CMS Commander Plugin cms-commander-client SQL Injection Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter ≤ 2.288 CVE-2026-3334 Wordfence
7.2 High myLinksDump Plugin mylinksdump SQL Injection Authenticated (Administrator+) SQL Injection via 'sort_by' and 'sort_order' Parameters ≤ 1.6 CVE-2026-2279 Wordfence
7.2 High WowOptin: Next-Gen Popup Maker Plugin optin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API No login needed ≤ 1.4.29 CVE-2026-4302 Wordfence
7.2 High Injection Guard Plugin injection-guard Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Query Parameter Name No login needed ≤ 1.2.9 CVE-2026-3368 Wordfence
8.1 High Melania Theme melania Local File Inclusion No login needed ≤ 2.5.0 CVE-2026-22324 Patchstack
7.1 High Flash Video Player Plugin flash-video-player Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.0.4 CVE-2024-32537 Patchstack
7.2 High Photography Theme photography Arbitrary File Upload < 7.7.6 Fixed in 7.7.6 CVE-2026-27043 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
7.1 High Everest Forms Pro Plugin everest-forms-pro Cross-Site Scripting No login needed ≤ 1.9.10 CVE-2026-27070 Patchstack
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
8.8 High WishList Member X Plugin wishlist-member-x PHP Object Injection ≤ 3.29.0 CVE-2026-25445 Patchstack
7.5 High Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-25443 Patchstack
7.1 High Kentha Theme kentha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.2 CVE-2026-25442 Patchstack
7.1 High Gutenberg Blocks Plugin unlimited-blocks Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2026-25438 Patchstack
7.1 High Table of Contents Creator Plugin table-of-contents-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.4.1 CVE-2025-68836 Patchstack
7.1 High Brookside Theme brookside Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-67618 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-53222 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50001 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Payment Bypass No login needed ≤ 4.2.8.3 Fixed in 4.2.8.4 CVE-2026-25312 Patchstack
8.1 High Admin Safety Guard Plugin admin-safety-guard Authentication Bypass Broken Authentication No login needed ≤ 1.2.6 CVE-2026-25471 Patchstack
8.1 High Tripgo Theme tripgo Local File Inclusion No login needed ≤ 1.5.6 Fixed in 1.5.6 CVE-2026-27093 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only