WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.0 Critical SigmaForms Pro – AI Generated Forms Plugin sigmaforms-pro Arbitrary File Upload AI Generated Forms plugin <= 1.4.5 - Arbitrary File Upload No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-52705 Patchstack
9.8 Critical wpForo Forum Plugin wpforo Authentication Bypass Broken Authentication No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-49767 Patchstack
9.8 Critical Thrive Apprentice Plugin thrive-apprentice PHP Object Injection No login needed < 10.8.10.2 Fixed in 10.8.10.2 CVE-2026-49107 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed < 3.8.9.1 Fixed in 3.8.9.1 CVE-2026-49084 Patchstack
9.3 Critical JetSearch Plugin jet-search SQL Injection No login needed ≤ 3.5.17 Fixed in 3.5.17.1 CVE-2026-49079 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed ≤ 3.8.9.1 Fixed in 3.8.10 CVE-2026-49076 Patchstack
9.8 Critical JetEngine Plugin jet-engine PHP Object Injection No login needed ≤ 3.8.9.1 Fixed in 3.8.10 CVE-2026-49075 Patchstack
9.8 Critical LoginPress Pro Plugin loginpress-pro Privilege Escalation No login needed ≤ 6.2.2 Fixed in 6.2.3 CVE-2026-49058 Patchstack
9.3 Critical JetSmartFilters Plugin jet-smart-filters SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.1.1 CVE-2026-48875 Patchstack
9.8 Critical AI Lab Theme ailab PHP Object Injection No login needed < 5.4.2 Fixed in 5.4.2 CVE-2026-42380 Patchstack
9.9 Critical Blocksy Companion Pro Plugin blocksy-companion-pro Remote Code Execution ≤ 2.1.37 Fixed in 2.1.38 CVE-2026-40783 Patchstack
9.9 Critical Charity Zone Theme charity-zone Arbitrary File Upload ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-40749 Patchstack
9.9 Critical Kids Gift Shop Theme kids-gift-shop Arbitrary File Upload ≤ 0.5.4 Fixed in 0.5.5 CVE-2026-40748 Patchstack
9.9 Critical Ecommerce Zone Theme ecommerce-zone Arbitrary File Upload ≤ 0.9.7 Fixed in 0.9.8 CVE-2026-40747 Patchstack
9.9 Critical Restaurant Zone Theme restaurant-zone Arbitrary File Upload ≤ 0.7.8 Fixed in 0.7.9 CVE-2026-40746 Patchstack
9.8 Critical WooCommerce Product Filters Plugin woocommerce-product-filters PHP Object Injection No login needed < 2.0.6 Fixed in 2.0.6 CVE-2026-40725 Patchstack
9.3 Critical Blocksy Companion Pro Plugin blocksy-companion-pro SQL Injection No login needed < 2.1.29 Fixed in 2.1.29 CVE-2026-39596 Patchstack
9.9 Critical Webenvo Theme webenvo Arbitrary File Upload ≤ 0.0.6 Fixed in 0.0.7 CVE-2026-39589 Patchstack
9.9 Critical Unlimited Elements for Elementor (Premium) Plugin unlimited-elements-for-elementor-premium Arbitrary File Upload ≤ 2.0.6 CVE-2026-27041 Patchstack
9.9 Critical WishList Member X Plugin wishlist-member-x Arbitrary File Upload ≤ 3.29.0 CVE-2026-25446 Patchstack
9.1 Critical MetForm Pro Plugin metform-pro Broken Access Control No login needed ≤ 3.9.1 CVE-2026-24611 Patchstack
9.3 Critical WPJobster Theme wpjobster SQL Injection No login needed ≤ 6.3.5 CVE-2026-22340 Patchstack
9.3 Critical Tutor LMS Pro Plugin tutor-pro SQL Injection No login needed ≤ 3.9.6 Fixed in 3.9.7 CVE-2026-22332 Patchstack
9.9 Critical Restaurt Theme restaurt Arbitrary File Upload ≤ 1.0.4 CVE-2026-22327 Patchstack
9.8 Critical Support Ticket Management System Plugin support_ticket Privilege Escalation No login needed ≤ 1.9 CVE-2025-69179 Patchstack
10.0 Critical WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Arbitrary File Upload No login needed ≤ 1.0.7 CVE-2025-69129 Patchstack
9.9 Critical PT Luxa Addons Plugin pt-luxa-addons Arbitrary File Upload ≤ 1.2.2 CVE-2025-60218 Patchstack
9.8 Critical ThemeREX Addons Plugin trx_addons PHP Object Injection No login needed ≤ 2.36.1.1 Fixed in 2.36.2 CVE-2025-60205 Patchstack
9.9 Critical Grip Theme grip Remote Code Execution Arbitrary Plugin Activation/Deactivation to RCE ≤ 1.0.9 CVE-2024-52488 Patchstack
10.0 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Remote Code Execution Custom Post Types plugin for WordPress plugin < 2.0.52 - Remote Code Execution (RCE) No login needed < 2.0.52 Fixed in 2.0.52 CVE-2026-25470 Patchstack
9.3 Critical wpDataTables Plugin wpdatatables SQL Injection No login needed ≤ 7.3.6 Fixed in 7.4 CVE-2026-49080 Patchstack
9.8 Critical Elementra Theme elementra PHP Object Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-39529 Patchstack
9.3 Critical ListingPro Plugin listingpro-plugin SQL Injection No login needed ≤ 2.9.10 Fixed in 2.9.11 CVE-2026-39438 Patchstack
9.8 Critical Nifty Theme nifty PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-27429 Patchstack
9.8 Critical Support Board Plugin supportboard Privilege Escalation No login needed < 3.8.9 Fixed in 3.8.9 CVE-2026-27395 Patchstack
9.8 Critical SeaFood Company Theme seafood-company PHP Object Injection No login needed ≤ 1.4 CVE-2025-69122 Patchstack
9.8 Critical Hot Coffee Theme hot-coffee PHP Object Injection No login needed ≤ 1.7 CVE-2025-69108 Patchstack
9.8 Critical Fusion Builder Plugin fusion-builder PHP Object Injection No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-54194 Patchstack
9.9 Critical Kids Online Store Theme kids-online-store Arbitrary File Upload ≤ 0.8.9 Fixed in 0.9.0 CVE-2026-40750 Patchstack
9.3 Critical The Events Calendar Plugin the-events-calendar SQL Injection No login needed 6.15.12 – 6.16.2 Fixed in 6.16.3 CVE-2026-49772 Patchstack
9.9 Critical RD Station Plugin integracao-rd-station Remote Code Execution ≤ 5.6.0 Fixed in 5.7.0 CVE-2026-49774 Patchstack
9.3 Critical GEO my Plugin geo-my-wp SQL Injection No login needed ≤ 4.5.5 Fixed in 4.5.5.1 CVE-2026-52715 Patchstack
9.3 Critical InPost Gallery Plugin inpost-gallery SQL Injection No login needed ≤ 2.1.4.6 Fixed in 2.1.5 CVE-2026-39574 Patchstack
9.6 Critical FastDup Plugin fastdup Path Traversal No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2026-52703 Patchstack
9.3 Critical eCommerce Product Catalog Plugin ecommerce-product-catalog SQL Injection No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2026-52693 Patchstack
9.8 Critical OttoKit Plugin suretriggers PHP Object Injection No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2026-49781 Patchstack
9.3 Critical GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites Plugin gptranslate SQL Injection Multilingual AI Translation for WordPress: Automatically Translate Websites plugin <= 2.32.6 - SQL Injection No login needed ≤ 2.32.6 Fixed in 2.32.7 CVE-2026-49776 Patchstack
9.8 Critical WP Travel Engine Plugin wp-travel-engine PHP Object Injection No login needed ≤ 6.7.12 Fixed in 6.8.0 CVE-2026-49770 Patchstack
9.8 Critical wpForo Forum Plugin wpforo PHP Object Injection No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-49769 Patchstack
9.8 Critical Happyforms Plugin happyforms PHP Object Injection No login needed ≤ 1.26.13 Fixed in 1.26.14 CVE-2026-49768 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only