WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 4,201–4,250 of 16,970 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 85 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Innovio Theme innovio Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22404 Patchstack
7.5 High Triply Theme triply Local File Inclusion ≤ 2.4.7 CVE-2026-22402 Patchstack
7.5 High Freshio Theme freshio Local File Inclusion ≤ 2.4.2 CVE-2026-22401 Patchstack
5.4 Medium Holmes Theme holmes Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.7 CVE-2026-22400 Patchstack
5.4 Medium Fleur Theme fleur Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0 CVE-2026-22398 Patchstack
5.4 Medium Fiorello Theme fiorello Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0 CVE-2026-22396 Patchstack
5.4 Medium Curly Theme curly Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3 CVE-2026-22393 Patchstack
5.4 Medium Cocco Theme cocco Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.5.1 CVE-2026-22391 Patchstack
5.9 Medium Owl Carousel WP Plugin owl-carousel-wp Cross-Site Scripting ≤ 2.2.2 CVE-2026-22388 Patchstack
5.4 Medium PawFriends - Pet Shop and Veterinary Theme pawfriends Cross-Site Request Forgery Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2026-22382 Patchstack
4.3 Medium SearchAzon Plugin searchazon Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2026-22360 Patchstack
5.4 Medium Electrician - Electrical Service Plugin electrician Server-Side Request Forgery Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) No login needed ≤ 5.6 CVE-2026-22358 Patchstack
7.1 High Simple XML Sitemap Plugin simple-xml-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2026-22355 Patchstack
6.5 Medium teachPress Plugin teachpress Cross-Site Scripting ≤ 9.0.12 CVE-2026-22353 Patchstack
6.5 Medium Menu In Post Plugin menu-in-post Cross-Site Scripting ≤ 1.4.1 CVE-2026-22349 Patchstack
5.3 Medium Civic Cookie Control Plugin civic-cookie-control-8 Broken Access Control No login needed ≤ 1.53 Fixed in 1.54 CVE-2026-22348 Patchstack
6.5 Medium Carousel Horizontal Posts Content Slider Plugin carousel-horizontal-posts-content-slider Cross-Site Scripting ≤ 3.3.2 CVE-2026-22347 Patchstack
7.1 High Grand Spa Plugin grandspa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-69321 Patchstack
7.1 High Grand Magazine Theme grandmagazine Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-69320 Patchstack
7.5 High Beaver Builder Plugin beaver-builder-lite-version Remote Code Execution Arbitrary Code Execution ≤ 2.9.4.1 Fixed in 2.9.4.2 CVE-2025-69319 Patchstack
7.1 High JobWP Plugin jobwp Cross-Site Scripting No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-69318 Patchstack
7.1 High CarSpot Plugin carspot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.6 Fixed in 2.4.6 CVE-2025-69317 Patchstack
7.1 High TableOn Plugin posts-table-filterable Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4.2 Fixed in 1.0.4.3 CVE-2025-69316 Patchstack
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.9.15 Fixed in 1.6.9.17 CVE-2025-69315 Patchstack
8.1 High Werkstatt Plugin werkstatt Local File Inclusion No login needed ≤ 4.8.3 Fixed in 4.8.3 CVE-2025-69314 Patchstack
7.5 High PostX Plugin ultimate-post Broken Access Control No login needed ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-69313 Patchstack
9.1 Critical Xpro Elementor Addons Plugin xpro-elementor-addons Arbitrary File Upload ≤ 1.4.19.1 Fixed in 1.4.20 CVE-2025-69312 Patchstack
7.6 High Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.1 Fixed in 1.52.2 CVE-2025-69311 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control Settings Change ≤ 4.11.63 Fixed in 4.11.64 CVE-2025-69300 Patchstack
8.8 High Final User Plugin final-user Privilege Escalation ≤ 1.2.5 CVE-2025-69293 Patchstack
8.8 High WP Membership Plugin wp-membership Privilege Escalation ≤ 1.6.4 CVE-2025-69292 Patchstack
7.3 High WP Membership Plugin wp-membership Broken Access Control No login needed ≤ 1.6.4 CVE-2025-69193 Patchstack
7.3 High Real Estate Pro Plugin real-estate-pro Broken Access Control No login needed ≤ 2.1.5 CVE-2025-69192 Patchstack
7.3 High ListingHub Plugin listinghub Broken Access Control No login needed ≤ 1.2.7 CVE-2025-69191 Patchstack
7.3 High Listihub Theme listihub Broken Access Control No login needed ≤ 1.0.6 CVE-2025-69190 Patchstack
7.3 High fitness-trainer Plugin fitness-trainer Broken Access Control No login needed ≤ 1.7.1 CVE-2025-69188 Patchstack
7.3 High Final User Plugin final-user Broken Access Control No login needed ≤ 1.2.5 CVE-2025-69187 Patchstack
7.3 High Hospital Doctor Directory Plugin hospital-doctor-directory Broken Access Control No login needed ≤ 1.3.9 CVE-2025-69186 Patchstack
7.3 High Hotel Listing Plugin hotel-listing Broken Access Control No login needed ≤ 1.4.2 CVE-2025-69185 Patchstack
7.3 High Institutions Directory Plugin institutions-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69184 Patchstack
8.8 High Hospital Doctor Directory Plugin hospital-doctor-directory Privilege Escalation ≤ 1.3.9 CVE-2025-69183 Patchstack
8.8 High Institutions Directory Plugin institutions-directory Privilege Escalation ≤ 1.3.4 CVE-2025-69182 Patchstack
7.3 High Lawyer Directory Plugin lawyer-directory Broken Access Control No login needed ≤ 1.3.4 CVE-2025-69181 Patchstack
8.5 High Ultra Portfolio Plugin ultra-portfolio SQL Injection ≤ 6.7 CVE-2025-69180 Patchstack
7.1 High WP Test Email Plugin wp-test-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.7 CVE-2025-69102 Patchstack
9.8 Critical Workreap Core Plugin workreap_core Authentication Bypass Broken Authentication No login needed ≤ 3.4.1 CVE-2025-69101 Patchstack
8.1 High North Theme north-wp Local File Inclusion No login needed ≤ 5.7.5 CVE-2025-69100 Patchstack
8.8 High North Theme north-wp PHP Object Injection ≤ 5.7.5 CVE-2025-69099 Patchstack
7.1 High Hide My WP Plugin hide_my_wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.2.12 CVE-2025-69098 Patchstack
8.6 High WPLMS Plugin wplms_plugin Arbitrary File Deletion No login needed ≤ 1.9.9.5.4 CVE-2025-69097 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only