WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,801–3,850 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 77 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Brook Plugin brook Local File Inclusion ≤ 2.9.0 CVE-2026-57791 Patchstack
7.5 High Billey Theme billey Local File Inclusion ≤ 2.1.8 CVE-2026-57790 Patchstack
7.5 High Aqua Theme aqua Local File Inclusion ≤ 5.1.2 CVE-2026-57789 Patchstack
7.5 High Aalto Theme aalto Local File Inclusion ≤ 1.8 CVE-2026-57788 Patchstack
8.5 High CWS SVGicons Plugin cws-svgicons SQL Injection ≤ 1.5.5 CVE-2026-57787 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Broken Authentication No login needed ≤ 1.7.08 CVE-2026-57786 Patchstack
6.5 Medium Speaker Plugin speaker Cross-Site Scripting ≤ 4.1.13 CVE-2026-57783 Patchstack
5.3 Medium Universal Clocks Plugin universal-clocks Broken Access Control No login needed ≤ 1.2.0 CVE-2026-57782 Patchstack
5.3 Medium MeetingHub Plugin meetinghub Broken Access Control No login needed ≤ 1.25.10 CVE-2026-57781 Patchstack
6.5 Medium Envision Page Builder Plugin envision-page-builder Cross-Site Scripting ≤ 0.22 CVE-2026-57780 Patchstack
5.3 Medium Fascinate Plugin fascinate Broken Access Control No login needed ≤ 1.1.5 CVE-2026-57779 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.36 CVE-2026-57778 Patchstack
5.3 Medium VW Wedding Plugin vw-wedding Broken Access Control No login needed ≤ 1.3.7 CVE-2026-57776 Patchstack
5.3 Medium VW Food Corner Plugin vw-food-corner Broken Access Control No login needed ≤ 1.1.0 CVE-2026-57774 Patchstack
7.6 High Advanced Shipment Tracking for WooCommerce Plugin woo-advanced-shipment-tracking SQL Injection ≤ 4.0 Fixed in 4.0.1 CVE-2026-57773 Patchstack
8.5 High WP Inventory Manager Plugin wp-inventory-manager SQL Injection ≤ 2.4.0 CVE-2026-57772 Patchstack
8.5 High GD Rating System Plugin gd-rating-system SQL Injection ≤ 3.7 CVE-2026-57771 Patchstack
9.8 Critical Grand Photography Theme grandphotography PHP Object Injection No login needed ≤ 5.7.8 CVE-2026-57770 Patchstack
8.2 High Houzez Login Register Plugin houzez-login-register Privilege Escalation No login needed ≤ 3.3.3 CVE-2026-57768 Patchstack
7.1 High RT-Theme 18 | Extensions Plugin rt18-extensions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2026-57745 Patchstack
9.8 Critical RT-Theme 18 | Extensions Plugin rt18-extensions PHP Object Injection No login needed ≤ 2.5 CVE-2026-57744 Patchstack
8.1 High RT-Theme 18 | Extensions Plugin rt18-extensions Local File Inclusion No login needed ≤ 2.5 CVE-2026-57743 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Cross-Site Scripting No login needed ≤ 10.11.0 Fixed in 10.11.1 CVE-2026-57741 Patchstack
7.1 High AcyMailing SMTP Newsletter Plugin acymailing Broken Access Control ≤ 10.11.1 CVE-2026-57740 Patchstack
9.3 Critical AcyMailing SMTP Newsletter Plugin acymailing SQL Injection No login needed ≤ 10.11.0 Fixed in 10.11.1 CVE-2026-57739 Patchstack
9.8 Critical 777 Theme triple-seven PHP Object Injection No login needed ≤ 1.13.0 CVE-2026-57738 Patchstack
7.1 High tagDiv Composer Plugin td-composer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.3 CVE-2026-57734 Patchstack
7.1 High tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2026-57733 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2026-57732 Patchstack
7.5 High Flatsome Plugin flatsome Broken Access Control No login needed ≤ 3.20.5 CVE-2026-57729 Patchstack
7.1 High Flatsome Plugin flatsome Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.20.5 CVE-2026-57728 Patchstack
7.5 High Kirki Plugin kirki Broken Access Control No login needed ≤ 6.0.13 CVE-2026-57727 Patchstack
9.3 Critical Kirki Plugin kirki SQL Injection No login needed ≤ 6.0.12 Fixed in 6.0.13 CVE-2026-57726 Patchstack
7.1 High Kirki Plugin kirki Cross-Site Scripting No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57725 Patchstack
9.8 Critical Kirki Plugin kirki PHP Object Injection No login needed ≤ 6.0.12 Fixed in 6.0.13 CVE-2026-57724 Patchstack
10.0 Critical Aimogen Pro Plugin aimogen-pro Arbitrary File Upload No login needed ≤ 2.8.3 Fixed in 2.8.3.1 CVE-2026-57719 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.12 Fixed in 2.0.13 CVE-2026-57718 Patchstack
7.1 High Fluent CRM Plugin fluent-crm Cross-Site Scripting No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-57715 Patchstack
9.3 Critical LatePoint Plugin latepoint SQL Injection No login needed ≤ 5.6.3 Fixed in 5.6.4 CVE-2026-57714 Patchstack
8.8 High Events Manager Plugin events-manager PHP Object Injection No login needed ≤ 7.3.6 Fixed in 7.3.7 CVE-2026-57713 Patchstack
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.29 Fixed in 1.4.30 CVE-2026-57712 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.4.8 Fixed in 3.4.9 CVE-2026-57711 Patchstack
9.9 Critical WoowBot Pro Max Plugin woowbot-pro-max Arbitrary File Upload ≤ 14.1.7 Fixed in 14.1.8 CVE-2026-57710 Patchstack
8.6 High Membership For WooCommerce Plugin membership-for-woocommerce Arbitrary File Deletion No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-57709 Patchstack
7.1 High Contact Form Entries Plugin contact-form-entries Cross-Site Scripting No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-57708 Patchstack
9.3 Critical Simple Business Directory Pro Plugin simple-business-directory-pro SQL Injection No login needed ≤ 15.9.4 Fixed in 15.9.5 CVE-2026-57707 Patchstack
7.1 High Dokan Plugin dokan-lite Cross-Site Scripting No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2026-57706 Patchstack
7.5 High Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.28.5 Fixed in 5.28.5.1 CVE-2026-57705 Patchstack
9.3 Critical Amelia Plugin ameliabooking SQL Injection No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-57702 Patchstack
6.5 Medium Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Authentication Bypass Broken Authentication No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2026-57698 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only