WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,601–3,650 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 73 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Fiorello Theme fiorello Local File Inclusion No login needed ≤ 1.0 CVE-2026-22395 Patchstack
8.1 High Evently Theme evently Local File Inclusion No login needed ≤ 1.7 CVE-2026-22394 Patchstack
8.1 High Cortex Theme cortex Local File Inclusion No login needed ≤ 1.9 Fixed in 2.0 CVE-2026-22392 Patchstack
9.9 Critical Builderall Builder Plugin builderall-cheetah-for-wp Remote Code Execution ≤ 3.0.1 CVE-2026-22390 Patchstack
8.1 High Cocco Theme cocco Local File Inclusion No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-22389 Patchstack
8.1 High Aviana Theme aviana Local File Inclusion No login needed ≤ 2.1 CVE-2026-22387 Patchstack
8.1 High Wolmart Theme wolmart Local File Inclusion No login needed ≤ 1.9.6 CVE-2026-22385 Patchstack
7.5 High ionCube tester plus Plugin ioncube-tester-plus Path Traversal Arbitrary File Download No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-69411 Patchstack
6.5 Medium Theater Plugin theatre Cross-Site Scripting ≤ 0.19 Fixed in 0.19.1 CVE-2025-69343 Patchstack
7.5 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69340 Patchstack
8.1 High Molla Plugin molla Local File Inclusion No login needed ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-69339 Patchstack
9.3 Critical Riode Core Plugin riode-core SQL Injection No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2025-69338 Patchstack
8.1 High Remons Theme remons Local File Inclusion No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-69090 Patchstack
9.9 Critical Nutrie Theme nutrie Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68555 Patchstack
9.9 Critical Keenarch Theme keenarch Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68554 Patchstack
9.9 Critical Lendiz Theme lendiz Arbitrary File Upload ≤ 2.0.1 Fixed in 2.0.1 CVE-2025-68553 Patchstack
5.8 Medium WP Booking System Plugin wp-booking-system Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.19.12 Fixed in 2.0.19.13 CVE-2025-68515 Patchstack
9.8 Critical Classter Theme classter PHP Object Injection No login needed ≤ 2.5 CVE-2025-54001 Patchstack
8.1 High Berger Theme berger Local File Inclusion No login needed ≤ 1.1.1 CVE-2025-53335 Patchstack
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API ≤ 1.12.3 CVE-2026-1236 Wordfence
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action Fields ≤ 13.4 CVE-2025-14040 Wordfence
7.2 High uListing Plugin ulisting PHP Object Injection ≤ 2.2.0 CVE-2026-28138 Patchstack
7.6 High WP SMS Plugin wp-sms SQL Injection ≤ 6.9.12 Fixed in 7.0 CVE-2026-28136 Patchstack
5.3 Medium WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Content Injection No login needed ≤ 1.4.4 CVE-2026-28132 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
6.5 Medium Flatsome Plugin flatsome Cross-Site Scripting ≤ 3.20.5 Fixed in 3.20.6 CVE-2026-28083 Patchstack
5.3 Medium Simple Ajax Chat Plugin simple-ajax-chat Information Disclosure Sensitive Data Exposure No login needed ≤ 20251121 Fixed in 20260217 CVE-2026-3075 Patchstack
7.1 High PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) No login needed ≤ 11.2.0.1 Fixed in 11.2.0.2 CVE-2026-27072 Patchstack
8.5 High JS Help Desk Plugin js-support-ticket SQL Injection ≤ 3.0.1 Fixed in 3.0.2 CVE-2026-24959 Patchstack
9.3 Critical Download Manager Addons for Elementor Plugin wpdm-elementor SQL Injection No login needed ≤ 1.3.0 Fixed in 2.0.0 CVE-2026-24956 Patchstack
7.1 High Whizz Plugins Plugin whizz-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 Fixed in 2.0.0 CVE-2026-24955 Patchstack
6.5 Medium Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download ≤ 6.1.15 Fixed in 6.1.16 CVE-2026-24953 Patchstack
7.5 High Authorsy Plugin authorsy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-24950 Patchstack
7.1 High PhotoMe Theme photome Cross-Site Scripting No login needed ≤ 5.7.1 Fixed in 5.7.2 CVE-2026-24949 Patchstack
7.1 High Reflector Plugin reflector-plugins Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-24948 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
6.5 Medium Subscribe2 Plugin subscribe2 Broken Access Control No login needed ≤ 10.44 Fixed in 10.45 CVE-2026-24944 Patchstack
7.1 High Grand Conference Plugin grandconference Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-24943 Patchstack
7.5 High WP Job Portal Plugin wp-job-portal Broken Access Control No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2026-24941 Patchstack
9.8 Critical Applay - Shortcodes Plugin applay-shortcodes PHP Object Injection Shortcodes plugin <= 3.7 - PHP Object Injection No login needed ≤ 3.7 CVE-2026-22384 Patchstack
7.5 High PawFriends - Pet Shop and Veterinary Theme pawfriends Broken Access Control Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) No login needed ≤ 1.3 CVE-2026-22383 Patchstack
8.1 High PawFriends - Pet Shop and Veterinary Theme pawfriends Local File Inclusion Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Local File Inclusion No login needed ≤ 1.3 CVE-2026-22381 Patchstack
8.1 High UnlimHost Theme unlimhost Local File Inclusion No login needed ≤ 1.2.3 CVE-2026-22380 Patchstack
8.1 High Netmix Theme netmix Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-22379 Patchstack
8.1 High Blabber Theme blabber Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-22378 Patchstack
8.1 High Saveo Theme saveo Local File Inclusion No login needed ≤ 1.1.2 CVE-2026-22377 Patchstack
8.1 High Parkivia Theme parkivia Local File Inclusion No login needed ≤ 1.1.9 CVE-2026-22376 Patchstack
8.1 High Impacto Patronus Theme impacto-patronus Local File Inclusion No login needed ≤ 1.2.3 CVE-2026-22375 Patchstack
8.1 High Zio Alberto Theme zioalberto Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22374 Patchstack
8.1 High Fooddy Theme fooddy Local File Inclusion No login needed ≤ 1.3.10 CVE-2026-22373 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only