WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,101–3,150 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 63 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Sell BTC - Cryptocurrency Selling Calculator Plugin sell-btc-by-hayyatapps Cross-Site Scripting Cryptocurrency Selling Calculator <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'orderform_data' AJAX Action No login needed ≤ 1.5 CVE-2025-14554 Wordfence
8.1 High Custom Login Page Customizer Plugin login-customizer Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed 2.1.1 – < 2.5.4 Fixed in 2.5.4 CVE-2025-14975 WPScan
7.5 High Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter No login needed ≤ 23.5 CVE-2026-1280 Wordfence
8.8 High Simple User Registration Plugin wp-registration Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via profile_save_field ≤ 6.7 CVE-2026-0844 Wordfence
8.8 High Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization Plugin metasync Broken Access Control Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization 2.4.4 - 2.5.12 - Missing Authorization to Authenticated (Subscriber+) Authentication Bypass via Account Takeover 2.4.4 – 2.5.12 CVE-2025-14386 Wordfence
7.2 High AI Engine Plugin ai-engine Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint ≤ 3.3.2 CVE-2026-1400 Wordfence
7.5 High VidShop – Shoppable Videos for WooCommerce Plugin vidshop-for-woocommerce SQL Injection Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields' No login needed ≤ 1.1.4 CVE-2026-0702 Wordfence
7.3 High New User Approve Plugin new-user-approve Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure No login needed ≤ 3.2.2 CVE-2026-0832 Wordfence
7.2 High TableMaster for Elementor Plugin tablemaster-for-elementor Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter No login needed ≤ 1.3.6 CVE-2025-14610 Wordfence
7.1 High AhaChat Messenger Marketing Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2025-14316 WPScan
7.5 High Hustle Plugin wordpress-popup Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upoload via Module Import ≤ 7.8.9.2 CVE-2026-0911 Wordfence
7.2 High User Submitted Posts – Enable Users to Submit Posts from the Front End Plugin user-submitted-posts Cross-Site Scripting Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field No login needed ≤ 20251210 CVE-2026-0800 Wordfence
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.1.6 CVE-2026-0807 Wordfence
7.5 High Administrative Shortcodes Plugin administrative-shortcodes Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'slug' Shortcode Attribute ≤ 0.3.4 CVE-2026-1257 Wordfence
7.5 High EduBlink Core Plugin edublink-core Local File Inclusion ≤ 2.0.7 CVE-2026-24635 Patchstack
7.6 High Neoforum Plugin neoforum SQL Injection ≤ 1.0 CVE-2026-24624 Patchstack
7.1 High Neoforum Plugin neoforum Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2026-24623 Patchstack
7.5 High Laurent Theme laurent Local File Inclusion ≤ 3.1 CVE-2026-24609 Patchstack
7.5 High Laurent Core Plugin laurent-core Local File Inclusion ≤ 2.4.1 CVE-2026-24608 Patchstack
8.5 High Nelio Content Plugin nelio-content SQL Injection ≤ 4.2.0 Fixed in 4.2.1 CVE-2026-24572 Patchstack
7.5 High Omnipress Plugin omnipress Local File Inclusion ≤ 1.6.7 CVE-2026-24538 Patchstack
7.5 High Prowess Theme prowess Local File Inclusion ≤ 2.3 CVE-2026-24531 Patchstack
8.8 High Melapress Role Editor Plugin melapress-role-editor Privilege Escalation Improper Authorization to Authenticated (Subscriber+) Privilege Escalation via Secondary Role Assignment ≤ 1.1.1 CVE-2025-14866 Wordfence
7.3 High BuddyPress Plugin buddypress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 14.3.3 CVE-2024-11976 Wordfence
7.5 High Kentha Elementor Widgets Plugin kentha-elementor Local File Inclusion ≤ 3.1 Fixed in 3.1 CVE-2026-24390 Patchstack
8.5 High Traveler Plugin traveler SQL Injection ≤ 3.2.8 Fixed in 3.2.8 CVE-2026-24367 Patchstack
7.5 High Gyan Elements Plugin gyan-elements Local File Inclusion ≤ 2.2.1 Fixed in 2.2.2 CVE-2026-23978 Patchstack
7.5 High Golo Plugin golo Local File Inclusion ≤ 1.7.5 Fixed in 1.7.5 CVE-2026-23975 Patchstack
7.6 High FireStorm Professional Real Estate Plugin fs-real-estate-plugin SQL Injection ≤ 2.7.11 CVE-2026-22470 Patchstack
7.5 High My auctions allegro Plugin my-auctions-allegro-free-edition Local File Inclusion ≤ 3.6.33 Fixed in 3.6.34 CVE-2026-22464 Patchstack
7.5 High Triply Theme triply Local File Inclusion ≤ 2.4.7 CVE-2026-22402 Patchstack
7.5 High Freshio Theme freshio Local File Inclusion ≤ 2.4.2 CVE-2026-22401 Patchstack
7.1 High Simple XML Sitemap Plugin simple-xml-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2026-22355 Patchstack
7.1 High Grand Spa Plugin grandspa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-69321 Patchstack
7.1 High Grand Magazine Theme grandmagazine Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-69320 Patchstack
7.5 High Beaver Builder Plugin beaver-builder-lite-version Remote Code Execution Arbitrary Code Execution ≤ 2.9.4.1 Fixed in 2.9.4.2 CVE-2025-69319 Patchstack
7.1 High JobWP Plugin jobwp Cross-Site Scripting No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-69318 Patchstack
7.1 High CarSpot Plugin carspot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2025-69317 Patchstack
7.1 High TableOn Plugin posts-table-filterable Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4.2 Fixed in 1.0.4.3 CVE-2025-69316 Patchstack
8.1 High Werkstatt Plugin werkstatt Local File Inclusion No login needed ≤ 4.8.3 Fixed in 4.8.3 CVE-2025-69314 Patchstack
7.5 High PostX Plugin ultimate-post Broken Access Control No login needed ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-69313 Patchstack
7.6 High Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-69311 Patchstack
8.8 High Final User Plugin final-user Privilege Escalation ≤ 1.2.5 CVE-2025-69293 Patchstack
8.8 High WP Membership Plugin wp-membership Privilege Escalation ≤ 1.6.4 CVE-2025-69292 Patchstack
7.3 High WP Membership Plugin wp-membership Broken Access Control No login needed ≤ 1.6.4 CVE-2025-69193 Patchstack
7.3 High Real Estate Pro Plugin real-estate-pro Broken Access Control No login needed ≤ 2.1.5 CVE-2025-69192 Patchstack
7.3 High ListingHub Plugin listinghub Broken Access Control No login needed ≤ 1.2.7 CVE-2025-69191 Patchstack
7.3 High Listihub Theme listihub Broken Access Control No login needed ≤ 1.0.6 CVE-2025-69190 Patchstack
7.3 High fitness-trainer Plugin fitness-trainer Broken Access Control No login needed ≤ 1.7.1 CVE-2025-69188 Patchstack
7.3 High Final User Plugin final-user Broken Access Control No login needed ≤ 1.2.5 CVE-2025-69187 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only