WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,251–3,300 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 66 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium KuteShop Theme kuteshop Arbitrary Shortcode Execution No login needed ≤ 4.2.9 CVE-2026-39612 Patchstack
5.3 Medium WpXmas-Snow Plugin wpxmas-snow Broken Access Control No login needed ≤ 1.1 CVE-2026-39610 Patchstack
5.3 Medium Wava Payment Plugin wava-payment Broken Access Control No login needed ≤ 0.3.7 CVE-2026-39609 Patchstack
5.3 Medium iPOSpays Gateways WC Plugin ipospays-gateways-wc Broken Access Control No login needed ≤ 1.3.7 CVE-2026-39608 Patchstack
5.4 Medium Filter Plus Plugin filter-plus Broken Access Control ≤ 1.1.17 CVE-2026-39607 Patchstack
5.3 Medium BizReview Plugin bizreview Broken Access Control No login needed ≤ 1.5.13 CVE-2026-39606 Patchstack
5.3 Medium Super Custom Login Plugin super-custom-login Broken Access Control No login needed ≤ 1.1 CVE-2026-39605 Patchstack
5.9 Medium MyBookTable Bookstore Plugin mybooktable Cross-Site Scripting ≤ 3.6.0 CVE-2026-39604 Patchstack
5.4 Medium Grand Photography Theme grandphotography Cross-Site Request Forgery No login needed ≤ 5.7.8 CVE-2026-39603 Patchstack
5.3 Medium Order Tracking Plugin order-tracking Broken Access Control No login needed ≤ 3.4.3 CVE-2026-39602 Patchstack
4.3 Medium DEPART Plugin depart-deposit-and-part-payment-for-woo Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-39592 Patchstack
5.3 Medium NM Gift Registry and Wishlist Lite Plugin nm-gift-registry-and-wishlist-lite Broken Access Control No login needed ≤ 5.13 Fixed in 5.14 CVE-2026-39588 Patchstack
5.3 Medium RepairBuddy Plugin computer-repair-shop Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1132 Fixed in 4.1133 CVE-2026-39586 Patchstack
5.3 Medium Booktics Plugin booktics Broken Access Control No login needed ≤ 1.0.16 Fixed in 1.0.17 CVE-2026-39585 Patchstack
6.5 Medium Custom Query Blocks Plugin post-type-archive-mapping Cross-Site Scripting ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-39575 Patchstack
4.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Information Disclosure Sensitive Data Exposure ≤ 5.6.5 Fixed in 5.6.5 CVE-2026-39572 Patchstack
5.3 Medium Instantio Plugin instantio Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.30 Fixed in 3.3.31 CVE-2026-39571 Patchstack
5.3 Medium 12 Step Meeting List Plugin 12-step-meeting-list Information Disclosure Sensitive Data Exposure No login needed ≤ 3.19.9 Fixed in 3.19.10 CVE-2026-39570 Patchstack
6.5 Medium 12 Step Meeting List Plugin 12-step-meeting-list Broken Access Control ≤ 3.19.9 Fixed in 3.19.10 CVE-2026-39569 Patchstack
4.3 Medium DirectoryPress Plugin directorypress Information Disclosure Sensitive Data Exposure ≤ 3.6.26 Fixed in 3.6.27 CVE-2026-39566 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-39565 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Sensitive Data Exposure No login needed ≤ 3.6.2 Fixed in 3.6.2 CVE-2026-39564 Patchstack
5.3 Medium Share This Image Plugin share-this-image Broken Access Control No login needed ≤ 2.12 Fixed in 2.13 CVE-2026-39563 Patchstack
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control No login needed ≤ 20.8.10 Fixed in 20.8.11 CVE-2026-39562 Patchstack
5.3 Medium Revive.so Plugin revive-so Broken Access Control No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2026-39561 Patchstack
5.3 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.21.4 Fixed in 2.21.5 CVE-2026-39543 Patchstack
5.3 Medium Doofinder for WooCommerce Plugin doofinder-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.10.13 Fixed in 2.10.14 CVE-2026-39542 Patchstack
5.9 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting ≤ 1.1.38 Fixed in 1.1.39 CVE-2026-39541 Patchstack
5.3 Medium RSVP and Event Management Plugin rsvp Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.16 Fixed in 2.7.17 CVE-2026-39536 Patchstack
5.3 Medium Display Eventbrite Events Plugin widget-for-eventbrite-api Broken Access Control No login needed ≤ 6.5.6 Fixed in 6.5.7 CVE-2026-39535 Patchstack
5.3 Medium WP Delicious Plugin delicious-recipes Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-39528 Patchstack
5.4 Medium WpStream Plugin wpstream Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.11.2 Fixed in 4.11.2 CVE-2026-39526 Patchstack
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-39521 Patchstack
5.3 Medium weDocs Plugin wedocs Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.2.1 CVE-2026-39520 Patchstack
6.5 Medium Blog Filter Plugin blog-filter Cross-Site Scripting ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-39517 Patchstack
5.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.0 Fixed in 4.7.1 CVE-2026-39516 Patchstack
5.3 Medium Directorist Plugin directorist Broken Access Control No login needed ≤ 8.5.10 Fixed in 8.6.1 CVE-2026-39509 Patchstack
6.5 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Cross-Site Scripting ≤ 4.7.1.1 Fixed in 4.7.2 CVE-2026-39508 Patchstack
4.3 Medium AI Engine (Pro) Plugin ai-engine-pro Broken Access Control ≤ 3.4.2 Fixed in 3.4.2 CVE-2026-39506 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Broken Access Control No login needed ≤ 3.14.2 Fixed in 3.14.3 CVE-2026-39505 Patchstack
5.4 Medium InstaWP Connect Plugin instawp-connect Broken Access Control ≤ 0.1.2.5 Fixed in 0.1.2.7 CVE-2026-39504 Patchstack
5.3 Medium FOX Plugin woocommerce-currency-switcher Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39501 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-39500 Patchstack
6.5 Medium SureCart Plugin surecart Broken Access Control ≤ 4.0.2 Fixed in 4.0.3 CVE-2026-39488 Patchstack
4.3 Medium Youtube Embed Plus Plugin youtube-embed-plus Broken Access Control ≤ 14.2.4 Fixed in 14.2.5 CVE-2026-39485 Patchstack
4.7 Medium Hide My WP Ghost Plugin hide-my-wp Open Redirect No login needed ≤ 7.0.00 Fixed in 7.0.00 CVE-2026-39484 Patchstack
6.5 Medium VK All in One Expansion Unit Plugin vk-all-in-one-expansion-unit Cross-Site Scripting ≤ 9.113.3 Fixed in 9.113.4 CVE-2026-39483 Patchstack
6.5 Medium Post Expirator Plugin post-expirator Cross-Site Scripting ≤ 4.9.4 Fixed in 4.10.0 CVE-2026-39482 Patchstack
4.3 Medium CartFlows Plugin cartflows Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2026-39477 Patchstack
4.3 Medium User Feedback Plugin userfeedback-lite Broken Access Control ≤ 1.10.1 Fixed in 1.11.0 CVE-2026-39476 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only