WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,501–3,550 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 71 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Metro Plugin metro Local File Inclusion No login needed ≤ 2.13 CVE-2026-27383 Patchstack
7.1 High Metro Plugin metro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.13 CVE-2026-27382 Patchstack
8.1 High Aora Theme aora Local File Inclusion No login needed ≤ 1.3.15 CVE-2026-27381 Patchstack
8.8 High NextScripts Plugin social-networks-auto-poster-facebook-twitter-g PHP Object Injection ≤ 4.4.7 CVE-2026-27379 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
7.1 High Gecko Theme gecko Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.8 CVE-2026-27375 Patchstack
7.5 High WooCommerce Order Details Plugin woocommerce-order-details Broken Access Control No login needed ≤ 3.1 CVE-2026-27374 Patchstack
8.5 High Tablesome Plugin tablesome SQL Injection ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-27373 Patchstack
7.5 High Chaty Plugin chaty Information Disclosure Sensitive Data Exposure No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-27370 Patchstack
8.1 High Celeste Theme celeste PHP Object Injection No login needed ≤ 1.3.6 CVE-2026-27369 Patchstack
7.1 High Musico Theme musico Cross-Site Scripting No login needed ≤ 3.4.5 Fixed in 3.4.5 CVE-2026-27367 Patchstack
7.1 High WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2026-27363 Patchstack
6.5 Medium WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Broken Access Control No login needed ≤ 1.0.6 CVE-2026-27362 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
7.1 High Awa Plugins Plugin awa-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.4 CVE-2026-27359 Patchstack
7.1 High Architecturer Theme architecturer Cross-Site Scripting No login needed ≤ 3.9.5 Fixed in 3.9.5 CVE-2026-27358 Patchstack
6.5 Medium WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Cross-Site Scripting ≤ 5.0 CVE-2026-27354 Patchstack
7.1 High Grand News Theme grandnews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.3 CVE-2026-27353 Patchstack
7.1 High Starto Theme starto Cross-Site Scripting No login needed ≤ 2.2.5 Fixed in 2.2.5 CVE-2026-27352 Patchstack
7.1 High Photography Plugin photography Cross-Site Scripting No login needed ≤ 7.7.6 Fixed in 7.7.6 CVE-2026-27348 Patchstack
5.9 Medium inseri core Plugin inseri-core Broken Access Control No login needed ≤ 1.0.5 CVE-2026-27344 Patchstack
8.1 High TopFit - Fitness and Gym Theme topfit Local File Inclusion Fitness and Gym WordPress Theme theme <= 1.9 - Local File Inclusion No login needed ≤ 1.9 CVE-2026-27342 Patchstack
8.1 High TopScorer - Sports Theme topscorer Local File Inclusion Sports WordPress Theme theme <= 1.2 - Local File Inclusion No login needed ≤ 1.2 CVE-2026-27341 Patchstack
8.1 High Apollo | Night Club, DJ Event Theme apollo Local File Inclusion No login needed ≤ 1.3.1 CVE-2026-27340 Patchstack
8.1 High Buzz Stone | Magazine & Viral Blog Theme buzzstone Local File Inclusion No login needed ≤ 1.0.2 CVE-2026-27339 Patchstack
8.8 High Car Zone Theme carzone PHP Object Injection Deserialization of untrusted data ≤ 3.7 CVE-2026-27338 Patchstack
8.1 High Chronicle - Lifestyle Magazine & Blog Theme chronicle Local File Inclusion Lifestyle Magazine & Blog WordPress Theme theme <= 1.0 - Local File Inclusion No login needed ≤ 1.0 CVE-2026-27337 Patchstack
8.1 High Consultor | Consulting, Accounting & Legal Counsel Theme consultor Local File Inclusion No login needed ≤ 1.2.4 CVE-2026-27336 Patchstack
8.1 High Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra Local File Inclusion NonProfit, Green Energy & Ecology Theme theme <= 1.0.0 - Local File Inclusion No login needed ≤ 1.0.0 CVE-2026-27335 Patchstack
8.1 High Alchemists Theme alchemists Local File Inclusion No login needed ≤ 4.6.0 CVE-2026-27334 Patchstack
7.1 High Agrofood Theme agrofood Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.0 CVE-2026-27332 Patchstack
8.1 High AC Services | HVAC, Air Conditioning & Heating Company Theme window-ac-services Local File Inclusion No login needed ≤ 1.2.5 CVE-2026-27326 Patchstack
8.1 High Au Pair Agency - Babysitting & Nanny Theme au-pair-agency PHP Object Injection Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data No login needed ≤ 1.2.2 CVE-2026-27098 Patchstack
8.1 High CasaMia | Property Rental Real Estate Theme casamia Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-27097 Patchstack
7.2 High Amelia Plugin ameliabooking Privilege Escalation ≤ 1.2.38 Fixed in 2.0 CVE-2026-24963 Patchstack
9.9 Critical Charety Theme charety Arbitrary File Upload ≤ 2.0.2 Fixed in 2.0.2 CVE-2026-24960 Patchstack
7.5 High Podlove Web Player Plugin podlove-web-player PHP Object Injection ≤ 5.9.1 Fixed in 5.9.2 CVE-2026-24385 Patchstack
9.1 Critical AI Engine Plugin ai-engine Arbitrary File Upload ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-23802 Patchstack
8.1 High The Issue Theme theissue Local File Inclusion No login needed ≤ 1.6.11 Fixed in 1.6.12 CVE-2026-23801 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2026-23799 Patchstack
8.8 High PowerPress Podcasting Plugin powerpress PHP Object Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-23798 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Information Disclosure Sensitive Data Exposure ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-23546 Patchstack
9.8 Critical Mounthood Theme mounthood PHP Object Injection No login needed ≤ 1.3.2 CVE-2026-22501 Patchstack
9.8 Critical Jardi Theme jardi PHP Object Injection No login needed ≤ 1.7.2 CVE-2026-22497 Patchstack
7.5 High Easy Post Submission Plugin easy-post-submission Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.5.0 CVE-2026-22479 Patchstack
8.1 High FindAll Theme findall Local File Inclusion No login needed ≤ 1.4 CVE-2026-22478 Patchstack
8.1 High Felizia Theme felizia Local File Inclusion No login needed ≤ 1.3.4 CVE-2026-22477 Patchstack
8.1 High Etchy Theme etchy Local File Inclusion No login needed ≤ 1.0 CVE-2026-22476 Patchstack
9.8 Critical Estate Plugin estate PHP Object Injection No login needed ≤ 1.3.4 CVE-2026-22475 Patchstack
9.8 Critical Equestrian Centre Theme equestrian-centre PHP Object Injection No login needed ≤ 1.5 CVE-2026-22474 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only