WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,751–2,800 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 56 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium MK Google Directions Plugin google-distance-calculator Cross-Site Scripting ≤ 3.1.1 CVE-2026-39674 Patchstack
5.3 Medium iZooto Plugin izooto-web-push Broken Access Control No login needed ≤ 3.7.20 CVE-2026-39673 Patchstack
5.3 Medium ShipTime: Discounted Shipping Rates Plugin shiptime-discount-shipping Broken Access Control No login needed ≤ 1.1.1 CVE-2026-39672 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
6.0 Medium Visual Link Preview Plugin visual-link-preview Server-Side Request Forgery ≤ 2.3.0 CVE-2026-39670 Patchstack
5.3 Medium NitroPack Plugin nitropack Broken Access Control No login needed ≤ 1.19.3 Fixed in 1.19.4 CVE-2026-39669 Patchstack
5.3 Medium Book Previewer for Woocommerce Plugin book-previewer-for-woocommerce Broken Access Control No login needed ≤ 1.0.6 CVE-2026-39668 Patchstack
5.9 Medium Korea SNS Plugin korea-sns Cross-Site Scripting ≤ 1.7.0 CVE-2026-39667 Patchstack
6.5 Medium Hello Bar Popup Builder Plugin hellobar Cross-Site Scripting ≤ 1.5.1 CVE-2026-39666 Patchstack
6.5 Medium SEO Friendly Images Plugin seo-image Cross-Site Scripting ≤ 3.0.5 CVE-2026-39665 Patchstack
5.3 Medium Leadrebel Plugin leadrebel Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39664 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.5 CVE-2026-39663 Patchstack
5.3 Medium Product Price by Formula for WooCommerce Plugin product-price-by-formula-for-woocommerce Broken Access Control No login needed ≤ 2.5.6 CVE-2026-39662 Patchstack
5.3 Medium Panda Pods Repeater Field Plugin panda-pods-repeater-field Broken Access Control No login needed ≤ 1.5.12 CVE-2026-39658 Patchstack
5.3 Medium leadlovers forms Plugin leadlovers-forms Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39657 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control No login needed ≤ 4.8.2 CVE-2026-39656 Patchstack
5.9 Medium WP Simple HTML Sitemap Plugin wp-simple-html-sitemap Cross-Site Scripting ≤ 3.8 CVE-2026-39654 Patchstack
4.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Broken Access Control ≤ 4.6.6 CVE-2026-39653 Patchstack
5.3 Medium iGMS Direct Booking Plugin igms-direct-booking Broken Access Control No login needed ≤ 1.3 CVE-2026-39652 Patchstack
6.5 Medium Total Poll Lite Plugin totalpoll-lite Broken Access Control ≤ 4.12.0 CVE-2026-39651 Patchstack
5.3 Medium UnitechPay Plugin unitechpay-paiements-mobile-money Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39650 Patchstack
5.3 Medium Royale News Plugin royale-news Broken Access Control No login needed ≤ 2.2.4 CVE-2026-39649 Patchstack
5.3 Medium Cream Blog Plugin cream-blog Broken Access Control No login needed ≤ 2.1.7 CVE-2026-39648 Patchstack
5.4 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery No login needed ≤ 5.11 CVE-2026-39647 Patchstack
6.5 Medium Leaflet Map Plugin leaflet-map Cross-Site Scripting ≤ 3.4.4 CVE-2026-39646 Patchstack
5.4 Medium GlobalPayments WooCommerce Plugin global-payments-woocommerce Server-Side Request Forgery No login needed ≤ 1.18.0 CVE-2026-39645 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Broken Access Control No login needed ≤ 2.3.8 CVE-2026-39644 Patchstack
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control No login needed ≤ 2.0.13 CVE-2026-39643 Patchstack
6.5 Medium Blackfyre Theme blackfyre Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2026-39641 Patchstack
9.6 Critical Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Remote Code Execution No login needed ≤ 3.2 CVE-2026-39640 Patchstack
6.5 Medium RPS Include Content Plugin rps-include-content Broken Access Control ≤ 1.2.2 CVE-2026-39639 Patchstack
5.9 Medium Qubely Plugin qubely Cross-Site Scripting ≤ 1.8.14 CVE-2026-39638 Patchstack
5.3 Medium Mogi Theme mogi Arbitrary Shortcode Execution No login needed ≤ 1.2.3 CVE-2026-39637 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Cross-Site Scripting ≤ 9.0 CVE-2026-39636 Patchstack
5.4 Medium Grand Magazine Theme grandmagazine Cross-Site Request Forgery No login needed ≤ 3.5.5 CVE-2026-39635 Patchstack
5.4 Medium Grand Portfolio Theme grandportfolio Cross-Site Request Forgery No login needed ≤ 3.3 CVE-2026-39634 Patchstack
6.5 Medium Grand Car Rental Plugin grandcarrental Cross-Site Request Forgery No login needed ≤ 3.6.9 CVE-2026-39633 Patchstack
6.5 Medium Grand Blog Theme grandblog Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2026-39632 Patchstack
4.9 Medium WPSchoolPress Plugin wpschoolpress Broken Access Control ≤ 2.2.35 CVE-2026-39631 Patchstack
6.4 Medium Getty Images Plugin getty-images Server-Side Request Forgery ≤ 4.1.0 CVE-2026-39630 Patchstack
5.3 Medium Uminex Theme uminex Arbitrary Shortcode Execution No login needed ≤ 1.0.9 CVE-2026-39629 Patchstack
5.3 Medium DukaMarket Theme dukamarket Arbitrary Shortcode Execution No login needed ≤ 1.3.0 CVE-2026-39628 Patchstack
4.3 Medium Ashe Plugin ashe Broken Access Control ≤ 2.266 CVE-2026-39627 Patchstack
5.3 Medium Armania Theme armania Arbitrary Shortcode Execution No login needed ≤ 1.4.8 CVE-2026-39626 Patchstack
5.3 Medium TechOne Theme techone Arbitrary Shortcode Execution No login needed ≤ 3.0.3 CVE-2026-39625 Patchstack
5.3 Medium Biolife Theme biolife Arbitrary Shortcode Execution No login needed ≤ 3.2.3 CVE-2026-39624 Patchstack
7.5 High Biolife Theme biolife Local File Inclusion ≤ 3.2.3 CVE-2026-39623 Patchstack
5.3 Medium Education Base Plugin education-base Broken Access Control No login needed ≤ 3.0.8 CVE-2026-39622 Patchstack
8.8 High SpicePress Plugin spicepress Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.3.2.5 CVE-2026-39621 Patchstack
9.6 Critical Appointment Plugin appointment Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 3.5.5 CVE-2026-39620 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only