WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,601–2,650 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 53 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High ProfilePress Plugin wp-user-avatar Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration ≤ 4.16.11 CVE-2026-3453 Wordfence
7.2 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Entry Fields No login needed ≤ 2.0.5 CVE-2026-2724 Wordfence
7.2 High MetForm Pro Plugin metform-pro Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.9.6 CVE-2026-1261 Wordfence
7.5 High The Events Calendar Plugin the-events-calendar Path Traversal Authenticated (Author+) Arbitrary File Read via ajax_create_import No login needed ≤ 6.15.17 CVE-2026-3585 Wordfence
7.2 High WP App Bar Plugin wp-app-bar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter No login needed ≤ 1.5 CVE-2026-1074 Wordfence
7.2 High Meta Box Plugin meta-box Arbitrary File Deletion Authenticated (Contributor+) Arbitrary File Deletion ≤ 5.11.1 CVE-2025-14675 Wordfence
8.8 High Paid Videochat Turnkey Site – HTML5 PPV Live Webcams Plugin ppv-live-webcams Privilege Escalation HTML5 PPV Live Webcams <= 7.3.20 - Authenticated (Author+) Privilege Escalation ≤ 7.3.20 CVE-2025-8899 Wordfence
7.2 High Easy PHP Settings Plugin easy-php-settings Remote Code Execution Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting ≤ 1.0.4 CVE-2026-3352 Wordfence
7.5 High JS Archive List Plugin jquery-archive-list-widget PHP Object Injection Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute ≤ 6.1.7 CVE-2026-2020 Wordfence
7.5 High ZIP Code Based Content Protection Plugin zip-code-based-content-protection SQL Injection Unauthenticated SQL Injection via 'zipcode' Parameter No login needed ≤ 1.0.2 CVE-2025-14353 Wordfence
7.5 High WooCommerce Plugin woocommerce Cross-Site Request Forgery Arbitrary Admin User Creation via CSRF No login needed 5.4.0 – < 5.4.4, 5.5.0 – < 5.4.5, 5.6.0 – < 5.6.3, … Fixed in 5.4.4 CVE-2026-3589 WPScan
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.9.5 CVE-2026-3459 Wordfence
8.8 High WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation Plugin optin Broken Access Control Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.4.24 CVE-2026-1720 Wordfence
8.1 High Membership Plugin – Restrict Content Plugin restrict-content Privilege Escalation Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level' No login needed ≤ 3.2.20 CVE-2026-1321 Wordfence
7.1 High MediCenter - Health Medical Clinic Plugin medicenter Cross-Site Scripting Health Medical Clinic WordPress Theme theme <= 14.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 14.9 CVE-2026-28137 Patchstack
8.2 High Royal Elementor Addons Plugin royal-elementor-addons Other Other vulnerability Type No login needed ≤ 1.7.1052 Fixed in 1.7.1053 CVE-2026-28135 Patchstack
8.5 High JetEngine Plugin jet-engine Remote Code Execution ≤ 3.7.2 Fixed in 3.8.1.2 CVE-2026-28134 Patchstack
8.5 High Filr Plugin filr-protection Arbitrary File Upload ≤ 1.2.14 CVE-2026-28133 Patchstack
7.1 High UDesign Plugin u-design Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.14.0 CVE-2026-28130 Patchstack
8.1 High Little Birdies Theme little-birdies Local File Inclusion No login needed ≤ 1.3.16 CVE-2026-28129 Patchstack
8.1 High Verse Theme verse Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-28128 Patchstack
7.1 High Lawyer Directory Plugin lawyer-directory Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2026-28127 Patchstack
7.1 High RH Frontend Publishing Pro Plugin rh-frontend Cross-Site Scripting No login needed ≤ 4.3.4 Fixed in 4.3.4 CVE-2026-28126 Patchstack
8.1 High Midi Theme midi Local File Inclusion No login needed ≤ 1.14 CVE-2026-28125 Patchstack
8.1 High Notarius Theme notarius Local File Inclusion No login needed ≤ 1.9 CVE-2026-28124 Patchstack
8.1 High Veil Theme veil Local File Inclusion No login needed ≤ 1.9 CVE-2026-28123 Patchstack
7.1 High ListingPro Plugin listingpro-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.8 CVE-2026-28122 Patchstack
8.1 High Anderson Theme andersonclinic Local File Inclusion No login needed ≤ 1.4.2 CVE-2026-28121 Patchstack
8.1 High Dr.Patterson Theme dr-patterson Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-28120 Patchstack
8.1 High Nirvana Theme nir-vana Local File Inclusion No login needed ≤ 2.6 CVE-2026-28119 Patchstack
8.1 High Welldone Theme welldone Local File Inclusion No login needed ≤ 2.4 CVE-2026-28118 Patchstack
8.1 High smart SEO Theme smartseo Local File Inclusion No login needed ≤ 2.9 CVE-2026-28117 Patchstack
7.1 High Ultimate Learning Pro Plugin indeed-learning-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.1 CVE-2026-28113 Patchstack
7.1 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator Cross-Site Scripting Banner Rotator plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28112 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist Cross-Site Scripting AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28110 Patchstack
7.1 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider Cross-Site Scripting AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28109 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner Cross-Site Scripting AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28108 Patchstack
8.1 High Muzicon Theme muzicon Local File Inclusion No login needed ≤ 1.9.0 CVE-2026-28107 Patchstack
7.1 High LBG Zoominoutslider Plugin lbg_zoominoutslider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.5 CVE-2026-28103 Patchstack
7.1 High UberSlider Classic Plugin uberslider_classic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2026-28102 Patchstack
7.1 High UberSlider MouseInteraction Plugin uberslider_mouseinteraction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28101 Patchstack
7.1 High UberSlider PerpetuumMobile Plugin uberslider_perpetuummobile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28100 Patchstack
7.1 High UberSlider Ultra Plugin uberslider_ultra Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28099 Patchstack
8.1 High Save Life Theme save-life Local File Inclusion No login needed ≤ 1.2.13 CVE-2026-28098 Patchstack
8.1 High Artrium Theme artrium Local File Inclusion No login needed ≤ 1.0.14 CVE-2026-28097 Patchstack
8.1 High WealthCo Theme wealthco Local File Inclusion No login needed ≤ 2.18 CVE-2026-28096 Patchstack
8.1 High Marcell Theme marcell Local File Inclusion No login needed ≤ 1.2.14 CVE-2026-28095 Patchstack
8.1 High RexCoin Theme rexcoin Local File Inclusion No login needed ≤ 1.2.6 CVE-2026-28094 Patchstack
8.1 High Ozisti Theme ozisti Local File Inclusion No login needed ≤ 1.1.10 CVE-2026-28093 Patchstack
8.1 High Sounder Theme sounder Local File Inclusion No login needed ≤ 1.3.11 CVE-2026-28092 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only