WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,801–2,850 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 57 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.6 Critical Busiprof Plugin busiprof Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2026-39619 Patchstack
4.3 Medium NewsExo Plugin newsexo Cross-Site Request Forgery No login needed ≤ 7.1 CVE-2026-39618 Patchstack
9.6 Critical Bluestreet Plugin bluestreet Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation No login needed ≤ 1.7.3 CVE-2026-39617 Patchstack
5.3 Medium Download Attachments Plugin download-attachments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.0 CVE-2026-39616 Patchstack
5.9 Medium Download Manager Plugin download-manager Cross-Site Scripting ≤ 3.3.53 CVE-2026-39615 Patchstack
5.4 Medium JW Player Plugin jw-player-7-for-wp Broken Access Control ≤ 2.3.6 CVE-2026-39614 Patchstack
7.5 High Boutique Theme kute-boutique Local File Inclusion ≤ 2.3.3 CVE-2026-39613 Patchstack
5.3 Medium KuteShop Theme kuteshop Arbitrary Shortcode Execution No login needed ≤ 4.2.9 CVE-2026-39612 Patchstack
7.5 High KuteShop Theme kuteshop Local File Inclusion ≤ 4.2.9 CVE-2026-39611 Patchstack
5.3 Medium WpXmas-Snow Plugin wpxmas-snow Broken Access Control No login needed ≤ 1.1 CVE-2026-39610 Patchstack
5.3 Medium Wava Payment Plugin wava-payment Broken Access Control No login needed ≤ 0.3.7 CVE-2026-39609 Patchstack
5.3 Medium iPOSpays Gateways WC Plugin ipospays-gateways-wc Broken Access Control No login needed ≤ 1.3.7 CVE-2026-39608 Patchstack
5.4 Medium Filter Plus Plugin filter-plus Broken Access Control ≤ 1.1.17 CVE-2026-39607 Patchstack
5.3 Medium BizReview Plugin bizreview Broken Access Control No login needed ≤ 1.5.13 CVE-2026-39606 Patchstack
5.3 Medium Super Custom Login Plugin super-custom-login Broken Access Control No login needed ≤ 1.1 CVE-2026-39605 Patchstack
5.9 Medium MyBookTable Bookstore Plugin mybooktable Cross-Site Scripting ≤ 3.6.0 CVE-2026-39604 Patchstack
5.4 Medium Grand Photography Theme grandphotography Cross-Site Request Forgery No login needed ≤ 5.7.8 CVE-2026-39603 Patchstack
5.3 Medium Order Tracking Plugin order-tracking Broken Access Control No login needed ≤ 3.4.3 CVE-2026-39602 Patchstack
4.3 Medium DEPART Plugin depart-deposit-and-part-payment-for-woo Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-39592 Patchstack
5.3 Medium NM Gift Registry and Wishlist Lite Plugin nm-gift-registry-and-wishlist-lite Broken Access Control No login needed ≤ 5.13 Fixed in 5.14 CVE-2026-39588 Patchstack
5.3 Medium RepairBuddy Plugin computer-repair-shop Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1132 Fixed in 4.1133 CVE-2026-39586 Patchstack
5.3 Medium Booktics Plugin booktics Broken Access Control No login needed ≤ 1.0.16 Fixed in 1.0.17 CVE-2026-39585 Patchstack
6.5 Medium Custom Query Blocks Plugin post-type-archive-mapping Cross-Site Scripting ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-39575 Patchstack
4.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Information Disclosure Sensitive Data Exposure ≤ 5.6.5 Fixed in 5.6.5 CVE-2026-39572 Patchstack
5.3 Medium Instantio Plugin instantio Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.30 Fixed in 3.3.31 CVE-2026-39571 Patchstack
5.3 Medium 12 Step Meeting List Plugin 12-step-meeting-list Information Disclosure Sensitive Data Exposure No login needed ≤ 3.19.9 Fixed in 3.19.10 CVE-2026-39570 Patchstack
6.5 Medium 12 Step Meeting List Plugin 12-step-meeting-list Broken Access Control ≤ 3.19.9 Fixed in 3.19.10 CVE-2026-39569 Patchstack
4.3 Medium DirectoryPress Plugin directorypress Information Disclosure Sensitive Data Exposure ≤ 3.6.26 Fixed in 3.6.27 CVE-2026-39566 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-39565 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Sensitive Data Exposure No login needed ≤ 3.6.2 Fixed in 3.6.2 CVE-2026-39564 Patchstack
5.3 Medium Share This Image Plugin share-this-image Broken Access Control No login needed ≤ 2.12 Fixed in 2.13 CVE-2026-39563 Patchstack
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control No login needed ≤ 20.8.10 Fixed in 20.8.11 CVE-2026-39562 Patchstack
5.3 Medium Revive.so Plugin revive-so Broken Access Control No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2026-39561 Patchstack
7.5 High LabtechCO Theme labtechco Local File Inclusion ≤ 8.3 Fixed in 8.4 CVE-2026-39544 Patchstack
5.3 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.21.4 Fixed in 2.21.5 CVE-2026-39543 Patchstack
5.3 Medium Doofinder for WooCommerce Plugin doofinder-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.10.13 Fixed in 2.10.14 CVE-2026-39542 Patchstack
5.9 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting ≤ 1.1.38 Fixed in 1.1.39 CVE-2026-39541 Patchstack
7.5 High Mikado Core Plugin mikado-core Local File Inclusion ≤ 1.6 Fixed in 2.2.2 CVE-2026-39538 Patchstack
5.3 Medium RSVP and Event Management Plugin rsvp Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.16 Fixed in 2.7.17 CVE-2026-39536 Patchstack
5.3 Medium Display Eventbrite Events Plugin widget-for-eventbrite-api Broken Access Control No login needed ≤ 6.5.6 Fixed in 6.5.7 CVE-2026-39535 Patchstack
5.3 Medium WP Delicious Plugin delicious-recipes Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-39528 Patchstack
5.4 Medium WpStream Plugin wpstream Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.11.2 Fixed in 4.11.2 CVE-2026-39526 Patchstack
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-39521 Patchstack
5.3 Medium weDocs Plugin wedocs Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.2.1 CVE-2026-39520 Patchstack
6.5 Medium Blog Filter Plugin blog-filter Cross-Site Scripting ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-39517 Patchstack
5.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.0 Fixed in 4.7.1 CVE-2026-39516 Patchstack
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
5.3 Medium Directorist Plugin directorist Broken Access Control No login needed ≤ 8.5.10 Fixed in 8.6.1 CVE-2026-39509 Patchstack
6.5 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Cross-Site Scripting ≤ 4.7.1.1 Fixed in 4.7.2 CVE-2026-39508 Patchstack
4.3 Medium AI Engine (Pro) Plugin ai-engine-pro Broken Access Control ≤ 3.4.2 Fixed in 3.4.2 CVE-2026-39506 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only