WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical Widget Wrangler Plugin widget-wrangler Remote Code Execution ≤ 2.3.9 Fixed in 2.4.0 CVE-2026-25447 Patchstack
9.8 Critical Nexa Blocks Plugin nexa-blocks PHP Object Injection No login needed ≤ 1.1.1 CVE-2026-25429 Patchstack
9.9 Critical WPBookit Pro Plugin wpbookit-pro Arbitrary File Upload ≤ 1.6.18 CVE-2026-25413 Patchstack
9.3 Critical Addon Jobsearch Chat Plugin addon-jobsearch-chat SQL Injection No login needed ≤ 3.0 Fixed in 3.1 CVE-2026-25377 Patchstack
9.3 Critical Lumise Product Designer Plugin lumise SQL Injection No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2026-25371 Patchstack
9.9 Critical Woody ad snippets Plugin insert-php Remote Code Execution ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-25366 Patchstack
9.9 Critical SimpLy Gallery Plugin simply-gallery-block Remote Code Execution Arbitrary Code Execution ≤ 3.3.2 Fixed in 3.3.2.1 CVE-2026-25345 Patchstack
9.3 Critical Jobmonster Theme noo-jobmonster SQL Injection No login needed ≤ 4.8.4 Fixed in 4.8.4 CVE-2026-25340 Patchstack
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Account Takeover No login needed ≤ 28.1.2.2 Fixed in 28.1.3 CVE-2026-25035 Patchstack
9.8 Critical Ricky Theme ricky PHP Object Injection No login needed ≤ 2.31 Fixed in 2.31 CVE-2026-25032 Patchstack
9.8 Critical Tasty Daily Theme tastydaily PHP Object Injection No login needed ≤ 1.27 Fixed in 1.27 CVE-2026-25031 Patchstack
9.8 Critical Goldish Theme goldish PHP Object Injection No login needed ≤ 3.47 Fixed in 3.47 CVE-2026-25030 Patchstack
9.8 Critical KIDZ Theme kidz PHP Object Injection No login needed ≤ 5.24 Fixed in 5.25 CVE-2026-25029 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2026-24993 Patchstack
9.8 Critical SUMO Affiliates Pro Plugin affs PHP Object Injection No login needed ≤ 11.4.0 Fixed in 11.4.0 CVE-2026-24989 Patchstack
9.8 Critical Search & Go Theme searchgo Privilege Escalation No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-24971 Patchstack
9.8 Critical Xagio SEO Plugin xagio-seo Privilege Escalation No login needed ≤ 7.1.0.30 Fixed in 7.1.0.31 CVE-2026-24968 Patchstack
9.8 Critical EventPrime Plugin eventprime-event-calendar-management PHP Object Injection No login needed ≤ 4.2.8.0 Fixed in 4.2.8.1 CVE-2026-24378 Patchstack
9.8 Critical Beelove Theme beelove PHP Object Injection No login needed ≤ 1.2.6 CVE-2026-22507 Patchstack
9.8 Critical m2 | Construction and Tools Store Theme m2-ce PHP Object Injection No login needed ≤ 1.1.2 CVE-2026-22500 Patchstack
9.3 Critical Lisfinity Core Plugin lisfinity-core SQL Injection No login needed ≤ 1.5.0 CVE-2026-22484 Patchstack
9.1 Critical Mobile App Editor Plugin mobile-app-editor Arbitrary File Upload ≤ 1.3.1 CVE-2026-27067 Patchstack
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack
9.8 Critical Finag Theme finag PHP Object Injection No login needed ≤ 1.5.0 CVE-2025-60237 Patchstack
9.8 Critical Zuut Theme zuut PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-60233 Patchstack
9.3 Critical Profile Builder Pro Plugin profile-builder-pro SQL Injection No login needed < 3.14.0 Fixed in 3.14.0 CVE-2026-27413 Patchstack
9.0 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Arbitrary File Upload No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27540 Patchstack
9.8 Critical Woocommerce Wholesale Lead Capture Plugin woocommerce-wholesale-lead-capture Privilege Escalation No login needed ≤ 2.0.3.1 Fixed in 2.0.3.2 CVE-2026-27542 Patchstack
9.8 Critical Traveler Plugin traveler PHP Object Injection No login needed ≤ 3.2.8.1 Fixed in 3.2.8.1 CVE-2026-25449 Patchstack
9.1 Critical Modal Dialog Plugin modal-dialog Remote Code Execution ≤ 3.5.16 Fixed in 3.5.17 CVE-2026-32367 Patchstack
9.3 Critical WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem SQL Injection Easy Stripe & Paypal donations plugin <= 1.25 - SQL Injection No login needed ≤ 1.25 CVE-2026-28115 Patchstack
9.1 Critical WooCommerce License Manager Plugin fs-license-manager Arbitrary File Upload ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-28114 Patchstack
9.8 Critical Good Energy Theme goodenergy PHP Object Injection No login needed ≤ 1.7.7 CVE-2026-28105 Patchstack
9.8 Critical Pizza House Theme pizzahouse PHP Object Injection No login needed ≤ 1.4.0 CVE-2026-28074 Patchstack
9.8 Critical Healer - Doctor, Clinic & Medical Theme healer Local File Inclusion Doctor, Clinic & Medical WordPress Theme theme <= 1.0.0 - Local File Inclusion No login needed ≤ 1.0.0 CVE-2026-28043 Patchstack
9.0 Critical Widget Options Plugin widget-options Remote Code Execution ≤ 4.1.3 Fixed in 4.2.0 CVE-2026-27984 Patchstack
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
9.8 Critical Dentario Theme dentario PHP Object Injection No login needed ≤ 1.5 CVE-2026-27439 Patchstack
9.8 Critical Kingler Theme kingler PHP Object Injection No login needed ≤ 1.7 CVE-2026-27438 Patchstack
9.8 Critical Tennis Club Theme tennis-sportclub PHP Object Injection No login needed ≤ 1.2.3 CVE-2026-27437 Patchstack
9.8 Critical Sweet Date Theme sweetdate PHP Object Injection No login needed ≤ 4.0.1 Fixed in 4.0.1 CVE-2026-27417 Patchstack
9.8 Critical WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2026-27389 Patchstack
9.0 Critical W3 Total Cache Plugin w3-total-cache Remote Code Execution Arbitrary Code Execution No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-27384 Patchstack
9.9 Critical Charety Theme charety Arbitrary File Upload ≤ 2.0.2 Fixed in 2.0.2 CVE-2026-24960 Patchstack
9.1 Critical AI Engine Plugin ai-engine Arbitrary File Upload ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-23802 Patchstack
9.8 Critical Mounthood Theme mounthood PHP Object Injection No login needed ≤ 1.3.2 CVE-2026-22501 Patchstack
9.8 Critical Jardi Theme jardi PHP Object Injection No login needed ≤ 1.7.2 CVE-2026-22497 Patchstack
9.8 Critical Estate Plugin estate PHP Object Injection No login needed ≤ 1.3.4 CVE-2026-22475 Patchstack
9.8 Critical Equestrian Centre Theme equestrian-centre PHP Object Injection No login needed ≤ 1.5 CVE-2026-22474 Patchstack
9.8 Critical Solaris Theme solaris PHP Object Injection No login needed ≤ 2.5 CVE-2026-22454 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only