WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,101–3,150 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 63 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High WoodMart Theme woodmart PHP Object Injection No login needed ≤ 8.3.8 Fixed in 8.3.9 CVE-2026-23971 Patchstack
7.1 High WP Telegram Widget and Join Link Plugin wptelegram-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.13 Fixed in 2.2.14 CVE-2026-23807 Patchstack
7.5 High Jobs Plugin job-postings Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-23806 Patchstack
7.1 High Legacy Admin Plugin legacy-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.5 CVE-2026-22524 Patchstack
7.1 High Ultra WordPress Admin Plugin ultra-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.7 CVE-2026-22523 Patchstack
7.1 High Handmade Framework Plugin handmade-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9 CVE-2026-22520 Patchstack
8.1 High Wizor's Theme wizors-investments Local File Inclusion No login needed ≤ 2.12 CVE-2026-22516 Patchstack
8.1 High VegaDays Theme vegadays Local File Inclusion No login needed ≤ 1.2.0 CVE-2026-22515 Patchstack
8.1 High Unica Theme unica Local File Inclusion No login needed ≤ 1.4.1 CVE-2026-22514 Patchstack
8.1 High Triompher Theme triompher Local File Inclusion No login needed ≤ 1.1.0 CVE-2026-22513 Patchstack
8.1 High Roisin Theme roisin Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.4 CVE-2026-22512 Patchstack
8.1 High NeoBeat Theme neobeat Local File Inclusion No login needed ≤ 1.2 Fixed in 1.7 CVE-2026-22511 Patchstack
8.1 High Melody Theme melodyschool PHP Object Injection No login needed ≤ 1.6.3 CVE-2026-22510 Patchstack
8.1 High Gioia Theme gioia Local File Inclusion No login needed ≤ 1.4 CVE-2026-22509 Patchstack
8.1 High Dentalux Theme dentalux Local File Inclusion No login needed ≤ 3.3 CVE-2026-22508 Patchstack
9.8 Critical Beelove Theme beelove PHP Object Injection No login needed ≤ 1.2.6 CVE-2026-22507 Patchstack
8.1 High Amoli Theme amoli Local File Inclusion No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-22506 Patchstack
8.1 High Morning Records Theme morning-records PHP Object Injection No login needed ≤ 1.2 CVE-2026-22505 Patchstack
8.1 High ProLingua Theme prolingua Local File Inclusion No login needed ≤ 1.1.12 CVE-2026-22504 Patchstack
8.1 High Nelson Theme nelson Local File Inclusion No login needed ≤ 1.2.0 CVE-2026-22503 Patchstack
8.1 High Mr. Cobbler Theme mr-cobbler Local File Inclusion No login needed ≤ 1.1.9 CVE-2026-22502 Patchstack
9.8 Critical m2 | Construction and Tools Store Theme m2-ce PHP Object Injection No login needed ≤ 1.1.2 CVE-2026-22500 Patchstack
8.1 High Lella Theme lella Local File Inclusion No login needed ≤ 1.2 CVE-2026-22499 Patchstack
8.1 High Laurent Theme laurent Local File Inclusion No login needed ≤ 3.1 CVE-2026-22498 Patchstack
8.1 High Hypnotherapy Theme hypnotherapy Local File Inclusion No login needed ≤ 1.2.10 CVE-2026-22496 Patchstack
8.1 High Greenville Theme greenville Local File Inclusion No login needed ≤ 1.3.2 CVE-2026-22495 Patchstack
8.1 High Good Homes Theme good-homes Local File Inclusion No login needed ≤ 1.3.13 CVE-2026-22494 Patchstack
8.1 High Gaspard Theme gaspard Local File Inclusion No login needed ≤ 1.3 CVE-2026-22493 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.35 CVE-2026-22491 Patchstack
6.5 Medium My Album Gallery Plugin my-album-gallery Arbitrary File Deletion ≤ 1.0.4 CVE-2026-22485 Patchstack
9.3 Critical Lisfinity Core Plugin lisfinity-core SQL Injection No login needed ≤ 1.5.0 CVE-2026-22484 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
7.5 High PitchPrint Plugin pitchprint Arbitrary File Deletion No login needed ≤ 11.1.2 Fixed in 11.2.0 CVE-2026-22448 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.2.6.0 Fixed in 4.2.7.0 CVE-2025-69358 Patchstack
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
7.1 High Zorka Theme zorka Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 CVE-2025-69096 Patchstack
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute ≤ 27.1.1 CVE-2026-3427 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Privilege Escalation WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module ≤ 3.2.4 CVE-2026-4314 Wordfence
6.4 Medium WordPress PayPal Donation Plugin wordpress-paypal-donation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'amount' Shortcode Attribute ≤ 1.01 CVE-2026-4072 Wordfence
6.4 Medium Go Night Pro | WordPress Dark Mode Plugin go-night-pro Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'margin' Shortcode Attribute ≤ 1.1.0 CVE-2026-1886 Wordfence
4.4 Medium Reward Video Ad Plugin applixir Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings ≤ 1.6 CVE-2026-2424 Wordfence
8.1 High Melania Theme melania Local File Inclusion No login needed ≤ 2.5.0 CVE-2026-22324 Patchstack
6.3 Medium TotalContest Lite Plugin totalcontest-lite PHP Object Injection ≤ 2.9.1 CVE-2026-0677 Patchstack
7.1 High Flash Video Player Plugin flash-video-player Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.0.4 CVE-2024-32537 Patchstack
5.9 Medium Special Box for Content Plugin special-box-for-content Cross-Site Scripting ≤ 1 CVE-2024-31119 Patchstack
7.2 High Photography Theme photography Arbitrary File Upload < 7.7.6 Fixed in 7.7.6 CVE-2026-27043 Patchstack
7.1 High Everest Forms Pro Plugin everest-forms-pro Cross-Site Scripting No login needed ≤ 1.9.10 CVE-2026-27070 Patchstack
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
9.1 Critical Mobile App Editor Plugin mobile-app-editor Arbitrary File Upload ≤ 1.3.1 CVE-2026-27067 Patchstack
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only