WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,951–3,000 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 60 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High weForms Plugin weforms PHP Object Injection No login needed ≤ <= 1.6.26 Fixed in 1.6.27 CVE-2026-32484 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control ≤ <= 1.3.63 Fixed in 1.3.64 CVE-2026-32483 Patchstack
9.9 Critical Ona Plugin ona Arbitrary File Upload ≤ < 1.24 Fixed in 1.24 CVE-2026-32482 Patchstack
7.7 High Comments Import & Export Plugin comments-import-export-woocommerce Broken Access Control ≤ <= 2.4.9 Fixed in 2.5.0 CVE-2026-32441 Patchstack
8.2 High Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce Broken Access Control No login needed ≤ <= 1.2.2 CVE-2026-31921 Patchstack
9.3 Critical Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce SQL Injection No login needed ≤ <= 1.2.2 CVE-2026-31920 Patchstack
6.5 Medium WP Courses LMS Plugin wp-courses Cross-Site Scripting ≤ <= 3.2.26 Fixed in 3.2.27 CVE-2026-31914 Patchstack
8.6 High Scape Plugin scape Arbitrary File Deletion No login needed ≤ < 1.5.16 Fixed in 1.5.16 CVE-2026-31913 Patchstack
9.8 Critical Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation PHP Object Injection No login needed ≤ 5.6.0 CVE-2026-27095 Patchstack
7.1 High Darna Framework Plugin darna-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9 CVE-2026-27088 Patchstack
7.1 High Wolverine Framework Plugin wolverine-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2026-27087 Patchstack
9.8 Critical Buisson Theme buisson PHP Object Injection No login needed ≤ 1.1.11 CVE-2026-27084 Patchstack
9.8 Critical Work & Travel Company Theme work-travel-company PHP Object Injection No login needed ≤ 1.2 CVE-2026-27083 Patchstack
9.8 Critical Love Story Theme lovestory PHP Object Injection No login needed ≤ 1.3.12 CVE-2026-27082 Patchstack
8.1 High Rosebud Theme rosebud Local File Inclusion No login needed ≤ 1.4 CVE-2026-27081 Patchstack
8.1 High Deston Theme deston Local File Inclusion No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-27080 Patchstack
8.1 High Amfissa Theme amfissa Local File Inclusion No login needed ≤ 1.1 Fixed in 1.2.1 CVE-2026-27079 Patchstack
8.1 High Emaurri Theme emaurri Local File Inclusion No login needed ≤ 1.0.1 Fixed in 1.5 CVE-2026-27078 Patchstack
8.1 High MultiOffice Theme multioffice Local File Inclusion No login needed ≤ 1.2 CVE-2026-27077 Patchstack
8.1 High LuxeDrive Theme luxedrive Local File Inclusion No login needed ≤ 1.0 Fixed in 1.4 CVE-2026-27076 Patchstack
8.1 High Belfort Theme belfort Local File Inclusion No login needed ≤ 1.0 Fixed in 1.2 CVE-2026-27075 Patchstack
7.5 High Addi – Cuotas que se adaptan a ti Plugin buy-now-pay-later-addi Authentication Bypass Cuotas que se adaptan a ti plugin <= 2.0.4 - Broken Authentication No login needed ≤ 2.0.4 CVE-2026-27073 Patchstack
9.1 Critical WPCafe Plugin wp-cafe Broken Access Control No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-27071 Patchstack
7.1 High Penci Soledad Data Migrator Plugin penci-data-migrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 CVE-2026-27054 Patchstack
9.8 Critical Golo Plugin golo Privilege Escalation No login needed ≤ 1.7.0 CVE-2026-27051 Patchstack
9.8 Critical Jobica Core Plugin jobica-core Privilege Escalation Account Takeover No login needed ≤ 1.4.2 CVE-2026-27049 Patchstack
8.1 High The Aisle Core Plugin theaisle-core Local File Inclusion No login needed ≤ 2.0.5 CVE-2026-27048 Patchstack
8.1 High Curly Core Plugin curly-core Local File Inclusion No login needed ≤ 2.1.6 Fixed in 2.2.2 CVE-2026-27047 Patchstack
6.5 Medium StoreCustomizer Plugin woocustomizer Broken Access Control ≤ 2.6.3 Fixed in 2.6.5 CVE-2026-27046 Patchstack
8.8 High WooCommerce Infinite Scroll Plugin sb-woocommerce-infinite-scroll PHP Object Injection ≤ 1.6.2 CVE-2026-27045 Patchstack
9.9 Critical Total Poll Lite Plugin totalpoll-lite Remote Code Execution ≤ 4.12.0 CVE-2026-27044 Patchstack
8.8 High WZone Plugin woozone Arbitrary File Deletion ≤ 14.0.31 CVE-2026-27040 Patchstack
8.5 High WZone Plugin woozone SQL Injection ≤ 14.0.31 CVE-2026-27039 Patchstack
6.5 Medium ViaBill – WooCommerce Plugin viabill-woocommerce Broken Access Control WooCommerce plugin <= 1.1.53 - Settings Change No login needed ≤ 1.1.53 CVE-2026-25469 Patchstack
6.5 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Cross-Site Scripting ≤ 1.4.36 CVE-2026-25465 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2026-25464 Patchstack
6.5 Medium avalex Plugin avalex Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-25462 Patchstack
7.1 High Listeo Core Plugin listeo-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.21 CVE-2026-25461 Patchstack
6.3 Medium Ave Core Plugin ave-core Broken Access Control ≤ 2.9.1 CVE-2026-25460 Patchstack
8.1 High Moments Theme moments Local File Inclusion No login needed ≤ 2.2 CVE-2026-25458 Patchstack
8.1 High Mixtape Plugin mixtape Local File Inclusion No login needed ≤ 2.1 CVE-2026-25457 Patchstack
7.3 High Automated FedEx live/manual rates with shipping labels Plugin a2z-fedex-shipping Broken Access Control No login needed ≤ 5.1.9 CVE-2026-25456 Patchstack
6.5 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control ≤ 1.13.61 Fixed in 1.13.62 CVE-2026-25455 Patchstack
6.5 Medium The League Theme the-league Broken Access Control ≤ 4.4.1 CVE-2026-25454 Patchstack
7.1 High Remoji Plugin remoji Cross-Site Scripting No login needed ≤ 2.2 CVE-2026-25452 Patchstack
9.1 Critical Widget Wrangler Plugin widget-wrangler Remote Code Execution ≤ 2.3.9 Fixed in 2.4.0 CVE-2026-25447 Patchstack
6.5 Medium GZSEO Plugin gzseo Broken Access Control No login needed ≤ 2.0.14 CVE-2026-25437 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
6.5 Medium Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-25430 Patchstack
9.8 Critical Nexa Blocks Plugin nexa-blocks PHP Object Injection No login needed ≤ 1.1.1 CVE-2026-25429 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only