WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,151–3,200 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 64 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Good Homes Theme good-homes Local File Inclusion No login needed ≤ 1.3.13 CVE-2026-22494 Patchstack
8.1 High Gaspard Theme gaspard Local File Inclusion No login needed ≤ 1.3 CVE-2026-22493 Patchstack
7.1 High My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting No login needed ≤ 3.6.35 CVE-2026-22491 Patchstack
6.5 Medium My Album Gallery Plugin my-album-gallery Arbitrary File Deletion ≤ 1.0.4 CVE-2026-22485 Patchstack
9.3 Critical Lisfinity Core Plugin lisfinity-core SQL Injection No login needed ≤ 1.5.0 CVE-2026-22484 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
7.5 High PitchPrint Plugin pitchprint Arbitrary File Deletion No login needed ≤ 11.1.2 Fixed in 11.2.0 CVE-2026-22448 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.2.6.0 Fixed in 4.2.7.0 CVE-2025-69358 Patchstack
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
7.1 High Zorka Theme zorka Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 CVE-2025-69096 Patchstack
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute ≤ 27.1.1 CVE-2026-3427 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Privilege Escalation WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module ≤ 3.2.4 CVE-2026-4314 Wordfence
6.4 Medium WordPress PayPal Donation Plugin wordpress-paypal-donation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'amount' Shortcode Attribute ≤ 1.01 CVE-2026-4072 Wordfence
6.4 Medium Go Night Pro | WordPress Dark Mode Plugin go-night-pro Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'margin' Shortcode Attribute ≤ 1.1.0 CVE-2026-1886 Wordfence
4.4 Medium Reward Video Ad Plugin applixir Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings ≤ 1.6 CVE-2026-2424 Wordfence
8.1 High Melania Theme melania Local File Inclusion No login needed ≤ 2.5.0 CVE-2026-22324 Patchstack
6.3 Medium TotalContest Lite Plugin totalcontest-lite PHP Object Injection ≤ 2.9.1 CVE-2026-0677 Patchstack
7.1 High Flash Video Player Plugin flash-video-player Cross-Site Request Forgery CSRF to XSS No login needed ≤ 5.0.4 CVE-2024-32537 Patchstack
5.9 Medium Special Box for Content Plugin special-box-for-content Cross-Site Scripting ≤ 1 CVE-2024-31119 Patchstack
7.2 High Photography Theme photography Arbitrary File Upload < 7.7.6 Fixed in 7.7.6 CVE-2026-27043 Patchstack
7.1 High Everest Forms Pro Plugin everest-forms-pro Cross-Site Scripting No login needed ≤ 1.9.10 CVE-2026-27070 Patchstack
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
9.1 Critical Mobile App Editor Plugin mobile-app-editor Arbitrary File Upload ≤ 1.3.1 CVE-2026-27067 Patchstack
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack
8.8 High WishList Member X Plugin wishlist-member-x PHP Object Injection ≤ 3.29.0 CVE-2026-25445 Patchstack
7.5 High Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-25443 Patchstack
7.1 High Kentha Theme kentha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.2 CVE-2026-25442 Patchstack
7.1 High Gutenberg Blocks Plugin unlimited-blocks Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2026-25438 Patchstack
7.1 High Table of Contents Creator Plugin table-of-contents-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.4.1 CVE-2025-68836 Patchstack
7.1 High Brookside Theme brookside Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-67618 Patchstack
6.5 Medium WPCasa Plugin wpcasa Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.2 CVE-2025-62043 Patchstack
9.8 Critical Finag Theme finag PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60237 Patchstack
9.8 Critical Zuut Theme zuut PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-60233 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-53222 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.2 Fixed in 5.4.3 CVE-2025-50001 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-32223 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Payment Bypass No login needed ≤ 4.2.8.3 Fixed in 4.2.8.4 CVE-2026-25312 Patchstack
8.1 High Admin Safety Guard Plugin admin-safety-guard Authentication Bypass Broken Authentication No login needed ≤ 1.2.6 CVE-2026-25471 Patchstack
6.3 Medium UiPress lite Plugin uipress-lite Broken Access Control ≤ 3.5.09 CVE-2026-27091 Patchstack
8.1 High Tripgo Theme tripgo Local File Inclusion No login needed ≤ 1.5.6 Fixed in 1.5.6 CVE-2026-27093 Patchstack
8.1 High ColorFolio - Freelance Designer Theme colorfolio PHP Object Injection Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data No login needed ≤ 1.3 CVE-2026-27096 Patchstack
6.5 Medium Really Simple Security Pro Plugin really-simple-ssl-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 9.5.4.0 Fixed in 9.5.4.1 CVE-2026-27397 Patchstack
9.3 Critical Profile Builder Pro Plugin profile-builder-pro SQL Injection No login needed < 3.14.0 Fixed in 3.14.0 CVE-2026-27413 Patchstack
9.0 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Arbitrary File Upload No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27540 Patchstack
9.8 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Privilege Escalation No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27542 Patchstack
5.9 Medium WP Rocket Plugin wp-rocket Cross-Site Scripting ≤ 3.19.4 Fixed in 3.20.0.2 CVE-2026-28044 Patchstack
5.3 Medium WP eMember Plugin wp-emember Broken Access Control No login needed ≤ v10.2.2 CVE-2026-28070 Patchstack
7.1 High WP eMember Plugin wp-emember Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v10.2.2 CVE-2026-28073 Patchstack
9.8 Critical Traveler Plugin traveler PHP Object Injection No login needed ≤ 3.2.8.1 Fixed in 3.2.8.1 CVE-2026-25449 Patchstack
5.3 Medium Contextual Related Posts Plugin contextual-related-posts Broken Access Control No login needed ≤ 4.2.2 Fixed in 4.2.2 CVE-2026-32565 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only