WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,151–4,200 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 84 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Themify Popup Plugin themify-popup PHP Object Injection ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-56037 Patchstack
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.0 CVE-2026-57765 Patchstack
6.5 Medium Surbma | Yoast SEO Breadcrumb Shortcode Plugin surbma-yoast-breadcrumb-shortcode Cross-Site Scripting ≤ 1.2 CVE-2026-57764 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.7.0 CVE-2026-57763 Patchstack
5.9 Medium Simple URLs Plugin simple-urls Cross-Site Scripting ≤ 151 CVE-2026-57762 Patchstack
7.1 High SEOWP Theme seowp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.12.2 CVE-2026-57761 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
7.1 High Permalink Manager for WooCommerce Plugin permalink-manager-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.8.2 CVE-2026-57758 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.5 High nicen-localize-image Plugin nicen-localize-image SQL Injection ≤ 1.4.9 CVE-2026-57756 Patchstack
6.5 Medium Mosaic Gallery – Advanced Gallery Plugin mosaic-gallery-advanced-gallery Cross-Site Scripting Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2026-57755 Patchstack
6.5 Medium Livemesh Addons for WPBakery Page Builder Plugin addons-for-visual-composer Cross-Site Scripting ≤ 3.9.4 CVE-2026-57754 Patchstack
5.3 Medium Kit (formerly ConvertKit) for WooCommerce Plugin convertkit-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.5 CVE-2026-57753 Patchstack
8.5 High iNET Webkit Plugin inet-webkit SQL Injection 1.2.4 CVE-2026-57752 Patchstack
8.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2026-57751 Patchstack
5.3 Medium ez Form Calculator Premium Plugin ez-form-calculator-premium Broken Access Control No login needed ≤ 2.14.1.2 CVE-2026-57750 Patchstack
7.5 High SportsPress Pro Plugin sportspress-pro Local File Inclusion ≤ 2.7.29 CVE-2026-57749 Patchstack
7.5 High Shopify Plugin shopify-plugin Local File Inclusion ≤ 1.0.0 CVE-2026-57748 Patchstack
6.5 Medium Booked Plugin booked Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-57747 Patchstack
7.1 High Booked Plugin booked Broken Access Control ≤ 3.0.0 CVE-2026-57746 Patchstack
6.5 Medium Flatsome Theme flatsome Broken Access Control ≤ 3.20.5 CVE-2026-57731 Patchstack
4.3 Medium Flatsome Theme flatsome Broken Access Control ≤ 3.20.5 CVE-2026-57730 Patchstack
4.3 Medium Werkstatt Theme werkstatt Cross-Site Request Forgery No login needed ≤ 4.7.2 CVE-2026-57690 Patchstack
4.3 Medium Werkstatt Theme werkstatt Broken Access Control ≤ 4.7.2 CVE-2026-57689 Patchstack
8.2 High POS Entegratör Plugin pos-entegrator Broken Access Control No login needed ≤ 3.7.103 Fixed in 3.8.0 CVE-2026-57688 Patchstack
8.5 High Custom Field Template Plugin custom-field-template SQL Injection ≤ 2.7.8 Fixed in 2.8 CVE-2026-57687 Patchstack
7.1 High WowAddons Plugin product-addons Cross-Site Scripting No login needed ≤ 1.6.14 Fixed in 1.6.15 CVE-2026-57686 Patchstack
4.3 Medium Martfury - WooCommerce Marketplace Theme martfury Broken Access Control WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control ≤ 3.2.8 CVE-2026-57685 Patchstack
6.5 Medium TheFox Theme thefox Cross-Site Scripting ≤ 3.9.70 CVE-2026-57684 Patchstack
9.3 Critical WP Fast Total Search Plugin fulltext-search SQL Injection No login needed ≤ 1.80.280 Fixed in 1.81.282 CVE-2026-57683 Patchstack
7.1 High Simple Link Directory Plugin qc-simple-link-directory Cross-Site Scripting No login needed ≤ 15.0.5 Fixed in 15.0.6 CVE-2026-57682 Patchstack
6.4 Medium GeoDirectory Plugin geodirectory Server-Side Request Forgery ≤ 2.8.161 Fixed in 2.8.162 CVE-2026-57681 Patchstack
6.5 Medium Kirki Plugin kirki Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57680 Patchstack
9.3 Critical GeekyBot Plugin geeky-bot SQL Injection No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-57679 Patchstack
9.8 Critical Novalnet Payment Gateway for WooCommerce Plugin woocommerce-novalnet-gateway PHP Object Injection No login needed ≤ 12.10.3 Fixed in 12.10.4 CVE-2026-57677 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.2.02.004 Fixed in 9.2.03.001 CVE-2026-57675 Patchstack
7.1 High Timetics Plugin timetics Cross-Site Scripting No login needed ≤ 1.0.58 Fixed in 1.0.59 CVE-2026-57674 Patchstack
7.1 High Optimole Plugin optimole-wp Cross-Site Scripting No login needed ≤ 4.2.7 Fixed in 4.2.8 CVE-2026-57673 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.1 Fixed in 6.5.1.2 CVE-2026-57672 Patchstack
7.1 High perfmatters Plugin perfmatters Cross-Site Scripting No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2026-57671 Patchstack
7.1 High Google Maps CP Plugin codepeople-post-map Cross-Site Scripting No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2026-57670 Patchstack
6.5 Medium Advanced Contact form 7 DB Plugin advanced-cf7-db Broken Access Control ≤ 2.0.9 Fixed in 2.1.0 CVE-2026-57669 Patchstack
9.6 Critical Admin and Site Enhancements (ASE) Pro Plugin admin-site-enhancements-pro Cross-Site Scripting No login needed ≤ 8.8.5 Fixed in 8.8.6 CVE-2026-57625 Patchstack
10.0 Critical Blocksy Companion Pro Plugin blocksy-companion-pro Remote Code Execution No login needed ≤ 2.1.46 Fixed in 2.1.47 CVE-2026-57624 Patchstack
9.0 Critical W3 Total Cache Plugin w3-total-cache Remote Code Execution Arbitrary Code Execution No login needed ≤ 2.9.4 Fixed in 2.10.0 CVE-2026-57623 Patchstack
9.8 Critical Booktics Plugin booktics PHP Object Injection No login needed ≤ 1.0.21 Fixed in 1.0.22 CVE-2026-57621 Patchstack
7.1 High Modula - PRO Plugin modula Cross-Site Scripting PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) No login needed ≤ 2.10.8 Fixed in 2.10.9 CVE-2026-57426 Patchstack
7.1 High WPAdverts Plugin wpadverts Cross-Site Scripting No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-57366 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.3.2 Fixed in 8.3.3 CVE-2026-57362 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only