WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,201–4,250 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 85 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.2.5 Fixed in 5.2.2.6 CVE-2026-57361 Patchstack
7.1 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting No login needed ≤ 3.5.4 Fixed in 3.5.5 CVE-2026-57360 Patchstack
7.1 High ReviewX Plugin reviewx Cross-Site Scripting No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2026-57359 Patchstack
7.1 High Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.9 Fixed in 4.3.10 CVE-2026-57358 Patchstack
7.1 High Search Atlas SEO Plugin metasync Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.6 Fixed in 2.6.7 CVE-2026-57357 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.19 Fixed in 1.9.20 CVE-2026-57356 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 5.4.2 Fixed in 5.4.3 CVE-2026-57355 Patchstack
6.5 Medium JetReviews Plugin jet-reviews Cross-Site Scripting ≤ 3.0.0.1 Fixed in 3.0.0.2 CVE-2026-57354 Patchstack
6.5 Medium Link Whisper Premium Plugin link-whisper-premium Broken Access Control ≤ 2.9.0 Fixed in 2.9.1 CVE-2026-57353 Patchstack
4.8 Medium ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Plugin woo-alidropship Authentication Bypass Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57352 Patchstack
7.1 High HandL UTM Grabber Plugin handl-utm-grabber Cross-Site Scripting No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2026-57351 Patchstack
7.1 High WP Debugging Plugin wp-debugging Cross-Site Scripting No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2026-57350 Patchstack
7.1 High WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting No login needed ≤ 2.8.17 Fixed in 2.8.18 CVE-2026-57349 Patchstack
7.2 High Paid Member Subscriptions Plugin paid-member-subscriptions Server-Side Request Forgery No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-57348 Patchstack
6.5 Medium Hotel Booking Lite Plugin motopress-hotel-booking-lite Information Disclosure Sensitive Data Exposure ≤ 6.0.3 Fixed in 6.0.4 CVE-2026-57347 Patchstack
7.1 High Internal Links Manager Plugin seo-automated-link-building Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2026-57345 Patchstack
7.1 High Classified Listing Plugin classified-listing Cross-Site Scripting No login needed ≤ 5.4.2 Fixed in 5.4.3 CVE-2026-57344 Patchstack
7.1 High Real Estate 7 Theme realestate-7 Cross-Site Scripting No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2026-57343 Patchstack
6.5 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Cross-Site Scripting ≤ 3.11.3 Fixed in 3.11.4 CVE-2026-57342 Patchstack
6.5 Medium Tax Exempt for WooCommerce Plugin woocommerce-tax-exempt-plugin Path Traversal < 1.9.5 Fixed in 1.9.5 CVE-2026-49779 Patchstack
8.1 High Audrey Theme audrey Local File Inclusion No login needed ≤ 1.5 CVE-2026-42382 Patchstack
7.5 High NOWPayments for WooCommerce Plugin nowpayments-for-woocommerce Broken Access Control No login needed ≤ 1.4.0 CVE-2026-39448 Patchstack
9.1 Critical Five Star Business Profile and Schema Plugin business-profile Remote Code Execution Arbitrary Code Execution ≤ 2.3.19 CVE-2026-27436 Patchstack
6.5 Medium Motors Theme motors Broken Access Control No login needed ≤ 5.6.80 CVE-2026-27433 Patchstack
7.1 High TheFox Theme thefox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.76 CVE-2026-27430 Patchstack
7.1 High Automotive Car Dealership Business Theme automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.3.3 CVE-2026-27426 Patchstack
7.1 High Automotive Listings Plugin automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 18.6 CVE-2026-27425 Patchstack
9.9 Critical Zegen Theme zegen Arbitrary File Upload ≤ 1.1.9 CVE-2026-27419 Patchstack
8.8 High Werkstatt Theme werkstatt PHP Object Injection ≤ 4.8.3 CVE-2026-27414 Patchstack
8.1 High Pearl - Corporate Business Theme pearl Local File Inclusion Corporate Business theme <= 3.4.10 - Local File Inclusion No login needed ≤ 3.4.10 CVE-2026-27412 Patchstack
7.1 High NativeChurch Theme nativechurch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.8.2 CVE-2026-27408 Patchstack
7.1 High LMS Theme lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.7 CVE-2026-27404 Patchstack
7.1 High Kids Life | Children School Theme kidslife Cross-Site Scripting No login needed ≤ 5.2 CVE-2026-27402 Patchstack
8.8 High ARMember Premium Plugin armember PHP Object Injection < 7.6 Fixed in 7.6 CVE-2026-27060 Patchstack
7.1 High Kids Zone - Children Theme kidszone Cross-Site Scripting Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) No login needed ≤ 5.4 CVE-2025-69156 Patchstack
7.1 High Fitness Zone Theme fitnesszone Cross-Site Scripting No login needed ≤ 5.7 CVE-2025-69155 Patchstack
7.1 High SpaLab | Beauty Salon Theme spalab Cross-Site Scripting No login needed ≤ 6.7 CVE-2025-69154 Patchstack
7.1 High Trendy Travel Theme trendytravel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.7 CVE-2025-69153 Patchstack
7.1 High Artale | Wedding Photography Theme artale Cross-Site Scripting No login needed ≤ 2.2.2 CVE-2025-69152 Patchstack
7.5 High OpenAI Chatbot for WordPress – Helper Plugin helper Broken Access Control Helper plugin <= 1.1.4 - Arbitrary Content Deletion No login needed ≤ 1.1.4 CVE-2025-69134 Patchstack
7.5 High Tourmaster Plugin tourmaster Local File Inclusion ≤ 5.4.5 CVE-2025-69133 Patchstack
6.5 Medium Corpkit Theme corpkit Information Disclosure Sensitive Data Exposure ≤ 1.0.5 CVE-2025-69132 Patchstack
8.5 High Unicamp Theme unicamp SQL Injection ≤ 2.2.2 CVE-2025-69094 Patchstack
5.3 Medium Woostify Sites Library Plugin woostify-sites-library Broken Access Control No login needed ≤ 1.6.2 CVE-2025-66076 Patchstack
8.1 High Lighthouse Theme lighthouseschool Local File Inclusion No login needed ≤ 1.2.12 CVE-2025-58902 Patchstack
7.5 High Ninja Forms - File Uploads Plugin ninja-forms-uploads Arbitrary File Upload File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter No login needed ≤ 3.3.29 CVE-2026-13369 Wordfence
7.5 High WP Review Slider Pro Plugin SQL Injection Unauthenticated SQL Injection via 'notinstring' Parameter No login needed ≤ 12.7.2 CVE-2026-8441 Wordfence
7.5 High Perfmatters Plugin perfmatters Path Traversal Unauthenticated Arbitrary File Read via 's' Parameter No login needed ≤ 2.6.4 CVE-2026-13251 Wordfence
6.5 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Path Traversal Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' No login needed ≤ 1.5.1 CVE-2026-9145 Wordfence
6.5 Medium Groundhogg Plugin groundhogg SQL Injection Authenticated (Custom+) SQL Injection via 'select' Parameter ≤ 4.5.8 CVE-2026-14029 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only