WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,751–2,800 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 56 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Quanzo Theme quanzo Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-27989 Patchstack
8.1 High Equadio Theme equadio Local File Inclusion No login needed ≤ 1.1.3 CVE-2026-27988 Patchstack
8.1 High The Qlean Theme the-qlean Local File Inclusion No login needed ≤ 2.12 CVE-2026-27987 Patchstack
8.1 High OsTende Theme ostende Local File Inclusion No login needed ≤ 1.4.3 CVE-2026-27986 Patchstack
8.1 High Humanum Theme humanum Local File Inclusion No login needed ≤ 1.1.4 CVE-2026-27985 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.6 Fixed in 2.2.7 CVE-2026-27541 Patchstack
8.5 High Eagle Booking Plugin eagle-booking SQL Injection ≤ 1.3.4.3 CVE-2026-27428 Patchstack
7.5 High My Tickets Plugin my-tickets Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2026-27406 Patchstack
7.3 High Directory Pro Plugin directory-pro Broken Access Control No login needed ≤ 2.5.6 CVE-2026-27396 Patchstack
8.8 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2026-27390 Patchstack
7.5 High DesignThemes Booking Manager Plugin designthemes-booking-manager Broken Access Control No login needed ≤ 2.0 CVE-2026-27388 Patchstack
7.5 High DesignThemes Directory Addon Plugin designthemes-directory-addon Broken Access Control No login needed ≤ 1.8 CVE-2026-27386 Patchstack
7.1 High DesignThemes Portfolio Plugin designthemes-portfolio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2026-27385 Patchstack
8.1 High Metro Plugin metro Local File Inclusion No login needed ≤ 2.13 CVE-2026-27383 Patchstack
7.1 High Metro Plugin metro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13 CVE-2026-27382 Patchstack
8.1 High Aora Theme aora Local File Inclusion No login needed ≤ 1.3.15 CVE-2026-27381 Patchstack
8.8 High NextScripts Plugin social-networks-auto-poster-facebook-twitter-g PHP Object Injection ≤ 4.4.7 CVE-2026-27379 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
7.1 High Gecko Theme gecko Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.8 CVE-2026-27375 Patchstack
7.5 High WooCommerce Order Details Plugin woocommerce-order-details Broken Access Control No login needed ≤ 3.1 CVE-2026-27374 Patchstack
8.5 High Tablesome Plugin tablesome SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-27373 Patchstack
7.5 High Chaty Plugin chaty Information Disclosure Sensitive Data Exposure No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-27370 Patchstack
8.1 High Celeste Theme celeste PHP Object Injection No login needed ≤ 1.3.6 CVE-2026-27369 Patchstack
7.1 High Musico Theme musico Cross-Site Scripting No login needed ≤ 3.4.5 Fixed in 3.4.5 CVE-2026-27367 Patchstack
7.1 High WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2026-27363 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
7.1 High Awa Plugins Plugin awa-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2026-27359 Patchstack
7.1 High Architecturer Theme architecturer Cross-Site Scripting No login needed ≤ 3.9.5 Fixed in 3.9.5 CVE-2026-27358 Patchstack
7.1 High Grand News Theme grandnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.3 CVE-2026-27353 Patchstack
7.1 High Starto Theme starto Cross-Site Scripting No login needed ≤ 2.2.5 Fixed in 2.2.5 CVE-2026-27352 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.6 Fixed in 7.7.6 CVE-2026-27348 Patchstack
8.1 High TopFit - Fitness and Gym Theme topfit Local File Inclusion Fitness and Gym WordPress Theme theme <= 1.9 - Local File Inclusion No login needed ≤ 1.9 CVE-2026-27342 Patchstack
8.1 High TopScorer - Sports Theme topscorer Local File Inclusion Sports WordPress Theme theme <= 1.2 - Local File Inclusion No login needed ≤ 1.2 CVE-2026-27341 Patchstack
8.1 High Apollo | Night Club, DJ Event Theme apollo Local File Inclusion No login needed ≤ 1.3.1 CVE-2026-27340 Patchstack
8.1 High Buzz Stone | Magazine & Viral Blog Theme buzzstone Local File Inclusion No login needed ≤ 1.0.2 CVE-2026-27339 Patchstack
8.8 High Car Zone Theme carzone PHP Object Injection Deserialization of untrusted data ≤ 3.7 CVE-2026-27338 Patchstack
8.1 High Chronicle - Lifestyle Magazine & Blog Theme chronicle Local File Inclusion Lifestyle Magazine & Blog WordPress Theme theme <= 1.0 - Local File Inclusion No login needed ≤ 1.0 CVE-2026-27337 Patchstack
8.1 High Consultor | Consulting, Accounting & Legal Counsel Theme consultor Local File Inclusion No login needed ≤ 1.2.4 CVE-2026-27336 Patchstack
8.1 High Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra Local File Inclusion NonProfit, Green Energy & Ecology Theme theme <= 1.0.0 - Local File Inclusion No login needed ≤ 1.0.0 CVE-2026-27335 Patchstack
8.1 High Alchemists Theme alchemists Local File Inclusion No login needed ≤ 4.6.0 CVE-2026-27334 Patchstack
7.1 High Agrofood Theme agrofood Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.0 CVE-2026-27332 Patchstack
8.1 High AC Services | HVAC, Air Conditioning & Heating Company Theme window-ac-services Local File Inclusion No login needed ≤ 1.2.5 CVE-2026-27326 Patchstack
8.1 High Au Pair Agency - Babysitting & Nanny Theme au-pair-agency PHP Object Injection Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data No login needed ≤ 1.2.2 CVE-2026-27098 Patchstack
8.1 High CasaMia | Property Rental Real Estate Theme casamia Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-27097 Patchstack
7.2 High Amelia Plugin ameliabooking Privilege Escalation ≤ 1.2.38 Fixed in 2.0 CVE-2026-24963 Patchstack
7.5 High Podlove Web Player Plugin podlove-web-player PHP Object Injection ≤ 5.9.1 Fixed in 5.9.2 CVE-2026-24385 Patchstack
8.1 High The Issue Theme theissue Local File Inclusion No login needed ≤ 1.6.11 Fixed in 1.6.12 CVE-2026-23801 Patchstack
8.8 High PowerPress Podcasting Plugin powerpress PHP Object Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-23798 Patchstack
7.5 High Easy Post Submission Plugin easy-post-submission Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.5.0 CVE-2026-22479 Patchstack
8.1 High FindAll Theme findall Local File Inclusion No login needed ≤ 1.4 CVE-2026-22478 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only