WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,851–2,900 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 58 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Cocco Theme cocco Local File Inclusion No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-22389 Patchstack
8.1 High Aviana Theme aviana Local File Inclusion No login needed ≤ 2.1 CVE-2026-22387 Patchstack
8.1 High Wolmart Theme wolmart Local File Inclusion No login needed ≤ 1.9.6 CVE-2026-22385 Patchstack
7.5 High ionCube tester plus Plugin ioncube-tester-plus Path Traversal Arbitrary File Download No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-69411 Patchstack
7.5 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69340 Patchstack
8.1 High Molla Plugin molla Local File Inclusion No login needed ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-69339 Patchstack
8.1 High Remons Theme remons Local File Inclusion No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-69090 Patchstack
8.1 High Berger Theme berger Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-53335 Patchstack
7.2 High Fluent Forms Pro Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Draft Form Submission No login needed ≤ 6.1.17 CVE-2026-2365 Wordfence
7.5 High JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket SQL Injection AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie No login needed ≤ 2.8.2 CVE-2023-7337 Wordfence
7.5 High Mail Mint Plugin mail-mint Information Disclosure Unauthenticated Emails Disclosure No login needed < 1.19.5 Fixed in 1.19.5 CVE-2026-2025 WPScan
7.2 High PostX Plugin ultimate-post Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints No login needed ≤ 5.0.8 CVE-2026-1273 Wordfence
7.2 High WPBookit Plugin wpbookit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters No login needed ≤ 1.0.8 CVE-2026-1945 Wordfence
7.2 High WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1.5 CVE-2026-2568 Wordfence
8.8 High Page Builder by SiteOrigin Plugin siteorigin-panels Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 2.33.5 CVE-2026-2448 Wordfence
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
8.8 High LatePoint Plugin Privilege Escalation Authenticated (Agent+) Privilege Escalation ≤ 5.2.7 CVE-2026-1566 Wordfence
7.5 High Contest Gallery Plugin contest-gallery SQL Injection Unauthenticated SQL Injection No login needed ≤ 28.1.4 CVE-2026-3180 Wordfence
8.8 High Master Addons for Elementor Premium Plugin master-addons Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via render_preview ≤ 2.1.3 CVE-2026-3132 Wordfence
8.2 High wpForo Forum Plugin wpforo SQL Injection wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter No login needed 2.4 – < 2.4.15 Fixed in 2.4.15 CVE-2026-28562 VulnCheck
7.5 High Tutor LMS Plugin tutor SQL Injection Unauthenticated SQL Injection via coupon_code No login needed ≤ 3.9.6 CVE-2025-13673 Wordfence
7.5 High WP Mail Logging Plugin wp-mail-logging PHP Object Injection Unauthenticated PHP Object Injection via Email Log Message Field No login needed ≤ 1.15.0 CVE-2026-2471 Wordfence
7.5 High Fluent Forms Pro Add On Pack Plugin Broken Access Control Missing Authorization to Unauthenticated Payment Status modification No login needed ≤ 6.1.17 CVE-2026-2428 Wordfence
8.8 High User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 4.2.8 CVE-2026-1565 Wordfence
7.2 High uListing Plugin ulisting PHP Object Injection ≤ 2.2.0 CVE-2026-28138 Patchstack
7.6 High WP SMS Plugin wp-sms SQL Injection ≤ 6.9.12 Fixed in 7.0 CVE-2026-28136 Patchstack
8.8 High Worry Proof Backup Plugin worry-proof-backup Path Traversal Authenticated (Subscriber+) Path Traversal via Backup Upload ≤ 0.2.4 CVE-2026-1311 Wordfence
8.1 High User Registration & Membership Plugin user-registration Authentication Bypass No login needed ≤ 5.1.2 CVE-2026-1779 Wordfence
7.5 High WP Responsive Images Plugin wp-responsive-images Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via src No login needed ≤ 1.0 CVE-2026-1557 Wordfence
7.5 High Geo Mashup Plugin geo-mashup SQL Injection Unauthenticated SQL Injection via 'sort' Parameter No login needed ≤ 1.13.17 CVE-2026-2416 Wordfence
8.8 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter ≤ 2.36 CVE-2026-1929 Wordfence
7.5 High WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token No login needed ≤ 3.8.3 CVE-2026-1916 Wordfence
8.8 High Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored XSS No login needed 1.7.0 – < 2.6.1 Fixed in 2.6.1 CVE-2025-15386 WPScan
7.1 High PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) No login needed ≤ 11.2.0.1 Fixed in 11.2.0.2 CVE-2026-27072 Patchstack
8.5 High JS Help Desk Plugin js-support-ticket SQL Injection ≤ 3.0.1 Fixed in 3.0.2 CVE-2026-24959 Patchstack
7.1 High Whizz Plugins Plugin whizz-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 Fixed in 2.0.0 CVE-2026-24955 Patchstack
7.5 High Authorsy Plugin authorsy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-24950 Patchstack
7.1 High PhotoMe Theme photome Cross-Site Scripting No login needed ≤ 5.7.1 Fixed in 5.7.2 CVE-2026-24949 Patchstack
7.1 High Reflector Plugin reflector-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-24948 Patchstack
7.1 High Grand Conference Plugin grandconference Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-24943 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2026-24941 Patchstack
7.5 High PawFriends - Pet Shop and Veterinary Theme pawfriends Broken Access Control Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) No login needed ≤ 1.3 CVE-2026-22383 Patchstack
8.1 High PawFriends - Pet Shop and Veterinary Theme pawfriends Local File Inclusion Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Local File Inclusion No login needed ≤ 1.3 CVE-2026-22381 Patchstack
8.1 High UnlimHost Theme unlimhost Local File Inclusion No login needed ≤ 1.2.3 CVE-2026-22380 Patchstack
8.1 High Netmix Theme netmix Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-22379 Patchstack
8.1 High Blabber Theme blabber Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-22378 Patchstack
8.1 High Saveo Theme saveo Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-22377 Patchstack
8.1 High Parkivia Theme parkivia Local File Inclusion No login needed ≤ 1.1.9 CVE-2026-22376 Patchstack
8.1 High Impacto Patronus Theme impacto-patronus Local File Inclusion No login needed ≤ 1.2.3 CVE-2026-22375 Patchstack
8.1 High Zio Alberto Theme zioalberto Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22374 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only