WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 401–450 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Leyka Plugin leyka Authentication Bypass Broken Authentication ≤ 3.32.3 CVE-2026-66677 Patchstack
7.1 High Flatastic Theme flatastic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2026-66673 Patchstack
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting No login needed ≤ 1.15.49 CVE-2026-66616 Patchstack
7.1 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2026-66615 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.2 Fixed in 14.2.3 CVE-2026-66614 Patchstack
7.1 High Aora Theme aora Cross-Site Scripting No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2026-66612 Patchstack
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
7.1 High Advance Product Search Plugin th-advance-product-search Cross-Site Scripting No login needed ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-66607 Patchstack
7.1 High SmartSMTP Plugin smart-smtp Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-66606 Patchstack
7.1 High Swatchly – WooCommerce Variation Swatches for Products Plugin swatchly Cross-Site Scripting WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2026-66605 Patchstack
7.1 High GeoDirectory Plugin geodirectory Cross-Site Scripting No login needed ≤ 2.8.173 Fixed in 2.8.174 CVE-2026-66604 Patchstack
7.1 High B2BKing Premium Plugin b2bking Cross-Site Scripting No login needed ≤ 5.6.07 Fixed in 5.6.08 CVE-2026-66598 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.4 Fixed in 6.5.1.5 CVE-2026-66597 Patchstack
8.5 High WordPress Persistent Login Plugin wp-persistent-login SQL Injection ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-66594 Patchstack
7.1 High Tagembed Plugin tagembed-widget Cross-Site Scripting No login needed ≤ 7.4 Fixed in 7.5 CVE-2026-66590 Patchstack
7.1 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-66582 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.14.1 Fixed in 3.8.14.2 CVE-2026-66581 Patchstack
8.1 High Golo Framework Plugin golo-framework Local File Inclusion No login needed < 1.7.5 Fixed in 1.7.5 CVE-2026-28150 Patchstack
8.1 High Shuffle Theme shuffle Local File Inclusion No login needed ≤ 1.8 Fixed in 1.9 CVE-2025-15637 Patchstack
7.5 High Chaplin Theme chaplin Broken Access Control No login needed ≤ 2.6.8 CVE-2026-74021 Patchstack
8.1 High Resido Theme resido Local File Inclusion No login needed ≤ 1.5 CVE-2026-73387 Patchstack
7.5 High Track Geolocation Of Users Using Contact Form 7 Plugin track-geolocation-of-users-using-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.2 CVE-2026-73386 Patchstack
7.5 High Outranking Plugin Options Plugin outranking Broken Access Control No login needed ≤ 1.1.3 CVE-2026-73385 Patchstack
7.5 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 CVE-2026-73384 Patchstack
7.1 High SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Scripting No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-73354 Patchstack
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting No login needed ≤ 11.1.2 CVE-2026-73184 Patchstack
7.1 High BBQ Pro Plugin bbq-pro Cross-Site Scripting No login needed ≤ 3.9 Fixed in 3.9.1 CVE-2026-73182 Patchstack
8.5 High Community by PeepSo Plugin peepso-core SQL Injection ≤ 9.0.5.2 Fixed in 9.0.5.3 CVE-2026-66668 Patchstack
7.1 High Newsletter Plugin newsletter Cross-Site Scripting No login needed ≤ 9.3.3 Fixed in 9.3.4 CVE-2026-66596 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.5 Fixed in 30.0.6 CVE-2026-61986 Patchstack
8.5 High YITH WooCommerce Membership Premium Plugin yith-woocommerce-membership-premium SQL Injection ≤ 2.33.0 Fixed in 2.33.1 CVE-2026-32552 Patchstack
7.5 High Stitch Express Plugin stitch-express Broken Access Control No login needed ≤ 1.9.0 CVE-2026-73394 Patchstack
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
7.5 High Starter Templates by Kadence WP Plugin kadence-starter-templates Denial of Service Denial of Service Attack No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-73997 Patchstack
7.5 High Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.11.3 Fixed in 1.8.12 CVE-2026-73994 Patchstack
8.1 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion No login needed ≤ 2.4.11 CVE-2026-73400 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
7.1 High Subscribe2 Plugin subscribe2 Cross-Site Scripting No login needed ≤ 10.46 CVE-2026-73393 Patchstack
7.1 High Site Reviews Plugin site-reviews Cross-Site Scripting No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2026-73382 Patchstack
7.1 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73378 Patchstack
7.5 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73377 Patchstack
7.1 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Cross-Site Scripting No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73375 Patchstack
7.2 High Easy Google Maps Plugin google-maps-easy Local File Inclusion Remote File Inclusion No login needed < 1.14.2 Fixed in 1.14.2 CVE-2026-73367 Patchstack
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-73362 Patchstack
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.1 High Chaty Pro Plugin chaty-pro Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-73360 Patchstack
7.1 High Affiliates Manager Plugin affiliates-manager Cross-Site Scripting No login needed ≤ 2.9.53 Fixed in 2.9.54 CVE-2026-73358 Patchstack
8.2 High Breeze Plugin breeze Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.5.12 Fixed in 2.5.13 CVE-2026-73356 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-73351 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only