WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 251–300 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium WpStream Plugin wpstream Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.11.2 Fixed in 4.11.2 CVE-2026-39526 Patchstack
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
7.2 High Gerador de Certificados – DevApps Plugin gerador-de-certificados-devapps Arbitrary File Upload DevApps <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload ≤ 1.3.6 CVE-2026-4808 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence
6.5 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ <= 3.0.3 Fixed in 3.0.4 CVE-2026-32535 Patchstack
6.5 Medium LatePoint Plugin latepoint Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ <= 5.2.6 Fixed in 5.2.7 CVE-2026-32533 Patchstack
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
5.3 Medium Build App Online Plugin build-app-online Broken Access Control Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action No login needed ≤ 1.0.23 CVE-2026-3651 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-32223 Patchstack
6.5 Medium Really Simple Security Pro Plugin really-simple-ssl-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 9.5.4.0 Fixed in 9.5.4.1 CVE-2026-27397 Patchstack
7.5 High Authorsy Plugin authorsy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-24950 Patchstack
7.5 High PawFriends - Pet Shop and Veterinary Theme pawfriends Broken Access Control Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) No login needed ≤ 1.3 CVE-2026-22383 Patchstack
7.5 High Cnvrse Plugin cnvrse Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 026.02.10.20 Fixed in 026.02.10.20 CVE-2025-69394 Patchstack
7.5 High VidoRev Theme vidorev Local File Inclusion ≤ 2.9.9.9.9.9.7 CVE-2025-69373 Patchstack
6.5 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.16.8 Fixed in 2.16.9 CVE-2025-68514 Patchstack
7.5 High Shiprocket Plugin shiprocket Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.8 CVE-2025-68051 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25324 Patchstack
5.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 23.5 Fixed in 23.6 CVE-2026-25005 Patchstack
4.4 Medium Slidorion Plugin slidorion Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Slidorion Settings ≤ 1.0.2 CVE-2026-2282 Wordfence
5.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation No login needed ≤ 3.7.0 CVE-2026-1722 Wordfence
4.3 Medium WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin wc-multivendor-membership Broken Access Control WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment ≤ 2.11.8 CVE-2025-15147 Wordfence
5.3 Medium Extensions For CF7 Plugin extensions-for-cf7 Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-24991 Patchstack
5.3 Medium Ultimate Reviews Plugin ultimate-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.16 Fixed in 3.2.17 CVE-2026-24634 Patchstack
5.4 Medium Rosebud Theme rosebud Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4 CVE-2026-24631 Patchstack
5.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2026-24599 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.4.3 Fixed in 2.4.4 CVE-2026-24379 Patchstack
5.4 Medium Verdure Theme verdure Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6 CVE-2026-22430 Patchstack
5.4 Medium Sweet Jane Theme sweetjane Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2 CVE-2026-22426 Patchstack
5.4 Medium Dolcino Theme dolcino Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6 CVE-2026-22411 Patchstack
5.4 Medium Justicia Theme justicia Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2 CVE-2026-22409 Patchstack
5.4 Medium Roam Plugin roam Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.1 CVE-2026-22407 Patchstack
5.4 Medium Overton Theme overton Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3 CVE-2026-22406 Patchstack
5.4 Medium Innovio Theme innovio Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22404 Patchstack
5.4 Medium Holmes Theme holmes Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22400 Patchstack
5.4 Medium Fleur Theme fleur Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0 CVE-2026-22398 Patchstack
5.4 Medium Fiorello Theme fiorello Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0 CVE-2026-22396 Patchstack
5.4 Medium Curly Theme curly Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3 CVE-2026-22393 Patchstack
5.4 Medium Cocco Theme cocco Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.5.1 CVE-2026-22391 Patchstack
7.1 High bidorbuy Store Integrator Plugin bidorbuystoreintegrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.12.0 CVE-2025-68883 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
4.3 Medium Image Slider Slideshow Plugin image-slider-slideshow Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8 CVE-2026-22489 Patchstack
6.5 Medium Woffice Core Plugin woffice-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67919 Patchstack
8.6 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-68044 Patchstack
4.3 Medium Order Cancellation & Returns for WooCommerce Plugin wc-order-cancellation-return Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.1.11 CVE-2025-49352 Patchstack
5.3 Medium MyD Delivery Plugin myd-delivery Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.1 CVE-2025-49334 Patchstack
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2025-63053 Patchstack
5.4 Medium FiveStar Theme fivestar Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2025-69032 Patchstack
5.4 Medium Backpack Traveler Theme backpacktraveler Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.3 CVE-2025-69030 Patchstack
5.4 Medium Struktur Theme struktur Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.1 CVE-2025-69029 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only