WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,451–3,500 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 70 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Cyr to Lat reloaded – transliteration of links and file names Plugin cyr-and-lat Broken Access Control transliteration of links and file names plugin <= 1.3.3 - Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-65537 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Request Forgery No login needed ≤ 4.4.5 CVE-2026-65536 Patchstack
4.3 Medium TinyMCE Templates Plugin tinymce-templates Information Disclosure Sensitive Data Exposure ≤ 4.8.1 CVE-2026-65535 Patchstack
5.9 Medium Custom links in Elementor Image Carousel Plugin custom-links-in-elementor-image-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2026-65534 Patchstack
6.5 Medium Smart SEO Tool Plugin smart-seo-tool Cross-Site Scripting ≤ 4.1.2 CVE-2026-65533 Patchstack
7.6 High Persian Woocommerce SMS Plugin persian-woocommerce-sms SQL Injection ≤ 7.2.2 CVE-2026-65532 Patchstack
4.8 Medium Qubely Plugin qubely Broken Access Control No login needed ≤ 1.8.14 CVE-2026-65531 Patchstack
4.3 Medium TemplateSpare Plugin templatespare Broken Access Control ≤ 4.2.2 CVE-2026-65530 Patchstack
5.3 Medium Graphina Plugin graphina-elementor-charts-and-graphs Broken Access Control No login needed ≤ 3.1.12 CVE-2026-65529 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.8 CVE-2026-65528 Patchstack
6.5 Medium LIQUID SPEECH BALLOON Plugin liquid-speech-balloon Cross-Site Scripting ≤ 1.2.5 CVE-2026-65527 Patchstack
8.5 High Visualizer Plugin visualizer SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2026-65526 Patchstack
5.3 Medium Civi Framework Plugin civi-framework Broken Access Control No login needed ≤ 2.2.0 CVE-2026-65525 Patchstack
4.3 Medium Avada Custom Branding Plugin fusion-white-label-branding Broken Access Control ≤ 1.2 CVE-2026-65524 Patchstack
6.5 Medium Manual - Documentation, Knowledge Base & Education Theme manual Cross-Site Scripting Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) ≤ 7.5.4 CVE-2026-65522 Patchstack
5.3 Medium WP Social Ninja Plugin wp-social-reviews Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-65521 Patchstack
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting ≤ 2.7.7.29 Fixed in 2.7.7.30 CVE-2026-65519 Patchstack
6.5 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-65518 Patchstack
7.2 High PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Server-Side Request Forgery No login needed ≤ 2.2.6 CVE-2026-65516 Patchstack
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting ≤ 1.5.86 Fixed in 1.5.87 CVE-2026-65514 Patchstack
5.4 Medium WP Activity Log Plugin wp-security-audit-log Cross-Site Request Forgery No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-65512 Patchstack
7.1 High Manual - Documentation, Knowledge Base & Education Theme manual Cross-Site Scripting Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) No login needed ≤ 7.5.4 CVE-2026-65511 Patchstack
7.1 High PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Cross-Site Scripting No login needed ≤ 2.2.6 CVE-2026-65510 Patchstack
5.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control No login needed ≤ 5.12 Fixed in 5.13 CVE-2026-65506 Patchstack
5.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65505 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65503 Patchstack
5.3 Medium Shiptastic for WooCommerce Plugin shiptastic-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65501 Patchstack
7.5 High Manual - Documentation, Knowledge Base & Education Theme manual Broken Access Control Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Broken Access Control No login needed ≤ 7.5.4 CVE-2026-65500 Patchstack
6.5 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control No login needed ≤ 2.2.6 CVE-2026-65499 Patchstack
5.3 Medium Complianz Plugin complianz-gdpr Information Disclosure Sensitive Data Exposure No login needed ≤ 7.5.0 CVE-2026-65498 Patchstack
7.2 High Complianz Plugin complianz-gdpr PHP Object Injection ≤ 7.5.0 CVE-2026-65497 Patchstack
4.4 Medium Complianz Plugin complianz-gdpr Server-Side Request Forgery ≤ 7.5.0 CVE-2026-65496 Patchstack
7.5 High Dokan Pro Plugin dokan-pro Broken Access Control No login needed ≤ 5.0.3 CVE-2026-65495 Patchstack
7.1 High Dokan Pro Plugin dokan-pro SQL Injection ≤ 5.0.2 CVE-2026-65494 Patchstack
7.5 High Dokan Pro Plugin dokan-pro PHP Object Injection ≤ 5.0.2 CVE-2026-65493 Patchstack
7.1 High Dokan Pro Plugin dokan-pro Cross-Site Scripting No login needed < 5.0.7 Fixed in 5.0.7 CVE-2026-65492 Patchstack
4.3 Medium Query Wrangler Plugin query-wrangler Broken Access Control ≤ 1.5.57 CVE-2026-65491 Patchstack
5.3 Medium Create Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-65490 Patchstack
5.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65489 Patchstack
7.1 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65488 Patchstack
5.3 Medium Photography Theme photography Broken Access Control No login needed ≤ 7.7.6 CVE-2026-65487 Patchstack
5.3 Medium Event post Plugin event-post Broken Access Control No login needed ≤ 6.0.1 CVE-2026-65486 Patchstack
5.3 Medium Content Control Plugin content-control Broken Access Control No login needed ≤ 2.6.5 CVE-2026-65485 Patchstack
6.3 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 CVE-2026-65484 Patchstack
5.9 Medium HashThemes Demo Importer Plugin hashthemes-demo-importer Cross-Site Scripting ≤ 1.4.2 CVE-2026-65483 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.6.3 CVE-2026-65482 Patchstack
7.5 High Vino Theme vino Local File Inclusion ≤ 1.9 CVE-2026-65481 Patchstack
6.5 Medium TheGem Theme thegem Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-65480 Patchstack
5.4 Medium Reviewer Plugin reviewer Broken Access Control ≤ 3.14.2 CVE-2026-65479 Patchstack
5.4 Medium ListingPro Plugin listingpro-plugin Broken Access Control ≤ 2.9.10 CVE-2026-65478 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only