WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,801–2,850 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 57 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Felizia Theme felizia Local File Inclusion No login needed ≤ 1.3.4 CVE-2026-22477 Patchstack
8.1 High Etchy Theme etchy Local File Inclusion No login needed ≤ 1.0 CVE-2026-22476 Patchstack
8.8 High Dental Clinic Theme dental PHP Object Injection ≤ 3.7 CVE-2026-22473 Patchstack
8.8 High Secudeal Payments for Ecommerce Plugin secudeal-payments-for-ecommerce PHP Object Injection ≤ 1.1 CVE-2026-22471 Patchstack
7.1 High DeepDigital Theme deepdigital Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2026-22467 Patchstack
7.1 High BuddyApp Theme buddyapp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2026-22465 Patchstack
8.6 High FormGent Plugin formgent Arbitrary File Deletion No login needed ≤ 1.7.0 CVE-2026-22460 Patchstack
8.1 High Wanderland Plugin wanderland Local File Inclusion No login needed ≤ 1.5 CVE-2026-22457 Patchstack
8.1 High Askka Theme askka Local File Inclusion No login needed ≤ 1.0 CVE-2026-22456 Patchstack
7.1 High Thebe Theme thebe Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2026-22455 Patchstack
8.1 High Hoverex Theme hoverex Local File Inclusion No login needed ≤ 1.5.10 CVE-2026-22452 Patchstack
8.1 High Don Peppe Theme donpeppe Local File Inclusion No login needed ≤ 1.3 CVE-2026-22449 Patchstack
8.1 High Prowess Theme prowess Local File Inclusion No login needed ≤ 1.8.1 CVE-2026-22446 Patchstack
8.1 High Alliance Theme alliance Local File Inclusion No login needed ≤ 3.1.1 CVE-2026-22443 Patchstack
8.1 High Tribe Theme tribe Local File Inclusion No login needed ≤ 1.7.3 CVE-2026-22442 Patchstack
8.1 High Zentrum Theme zentrum Local File Inclusion No login needed ≤ 1.0 CVE-2026-22441 Patchstack
7.1 High Thecs Theme thecs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.7 CVE-2026-22440 Patchstack
8.1 High Green Planet Theme green-planet Local File Inclusion No login needed ≤ 1.1.14 CVE-2026-22439 Patchstack
7.1 High TheBi Theme thebi Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2026-22438 Patchstack
8.1 High Playa Theme playa Local File Inclusion No login needed ≤ 1.3.9 CVE-2026-22437 Patchstack
8.1 High Helvig Theme helvig Local File Inclusion No login needed ≤ 1.0 CVE-2026-22436 Patchstack
8.1 High ElectroServ Theme electroserv Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-22435 Patchstack
8.1 High Crown Art Theme crown-art Local File Inclusion No login needed ≤ 1.2.11 CVE-2026-22434 Patchstack
8.1 High CloudMe Theme cloudme Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22433 Patchstack
8.1 High Woopy Theme woopy Local File Inclusion No login needed ≤ 1.2 CVE-2026-22432 Patchstack
8.1 High Wabi-Sabi Theme wabi-sabi Local File Inclusion No login needed ≤ 1.2 CVE-2026-22431 Patchstack
8.1 High Verdure Theme verdure Local File Inclusion No login needed ≤ 1.6 CVE-2026-22429 Patchstack
8.1 High Tooth Fairy Theme tooth-fairy Local File Inclusion No login needed ≤ 1.16 CVE-2026-22428 Patchstack
8.1 High GoTravel Theme gotravel Local File Inclusion No login needed ≤ 2.1 CVE-2026-22427 Patchstack
8.1 High Sweet Jane Theme sweetjane Local File Inclusion No login needed ≤ 1.2 CVE-2026-22425 Patchstack
8.1 High Shaha Theme shaha Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-22424 Patchstack
8.1 High SetSail Theme setsail Local File Inclusion No login needed ≤ 1.8 CVE-2026-22423 Patchstack
8.1 High Quantum Theme quantum Local File Inclusion No login needed ≤ 1.0 CVE-2026-22421 Patchstack
8.1 High Horizon Theme horizon Local File Inclusion No login needed ≤ 1.1 CVE-2026-22420 Patchstack
8.1 High Honor Theme honor Local File Inclusion No login needed ≤ 2.3 CVE-2026-22419 Patchstack
8.1 High Great Lotus Theme great-lotus Local File Inclusion No login needed ≤ 1.3.1 CVE-2026-22418 Patchstack
8.1 High FixTeam Theme fixteam Local File Inclusion No login needed ≤ 1.5.0 CVE-2026-22416 Patchstack
8.1 High The Mounty Theme the-mounty Local File Inclusion No login needed ≤ 1.1 CVE-2026-22415 Patchstack
8.1 High Marra Theme marra Local File Inclusion No login needed ≤ 1.2 CVE-2026-22414 Patchstack
8.1 High Malgré Theme malgre Local File Inclusion No login needed ≤ 1.0.3 CVE-2026-22413 Patchstack
8.1 High Eona Theme eona Local File Inclusion No login needed ≤ 1.3 CVE-2026-22412 Patchstack
8.1 High Dolcino Theme dolcino Local File Inclusion No login needed ≤ 1.6 CVE-2026-22410 Patchstack
8.1 High Justicia Theme justicia Local File Inclusion No login needed ≤ 1.2 CVE-2026-22408 Patchstack
8.1 High Overton Theme overton Local File Inclusion No login needed ≤ 1.3 CVE-2026-22405 Patchstack
8.1 High Innovio Theme innovio Local File Inclusion No login needed ≤ 1.9 Fixed in 1.9.1 CVE-2026-22403 Patchstack
8.1 High Holmes Theme holmes Local File Inclusion No login needed ≤ 1.7 CVE-2026-22399 Patchstack
8.1 High Fleur Theme fleur Local File Inclusion No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2026-22397 Patchstack
8.1 High Fiorello Theme fiorello Local File Inclusion No login needed ≤ 1.0 CVE-2026-22395 Patchstack
8.1 High Evently Theme evently Local File Inclusion No login needed ≤ 1.7 CVE-2026-22394 Patchstack
8.1 High Cortex Theme cortex Local File Inclusion No login needed ≤ 1.9 Fixed in 2.0 CVE-2026-22392 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only