WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 4,551–4,600 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 92 of 342
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Speed Kit Plugin baqend Broken Access Control ≤ 2.0.2 CVE-2026-22487 Patchstack
5.3 Medium Dashboard Welcome for Beaver Builder Plugin dashboard-welcome-for-beaver-builder Broken Access Control No login needed ≤ 1.0.8 CVE-2026-22488 Patchstack
4.3 Medium Image Slider Slideshow Plugin image-slider-slideshow Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8 CVE-2026-22489 Patchstack
5.4 Medium Bulk Landing Page Creator for WordPress LPagery Plugin lpagery Broken Access Control ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-22490 Patchstack
4.3 Medium Docket Cache Plugin docket-cache Broken Access Control ≤ 24.07.04 Fixed in 24.07.05 CVE-2026-22492 Patchstack
5.4 Medium GA4WP: Google Analytics Plugin ga-for-wp Broken Access Control ≤ 2.10.0 CVE-2026-22517 Patchstack
6.5 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting ≤ 1.0.23 CVE-2026-22518 Patchstack
6.5 Medium MediaPress Plugin mediapress Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-22519 Patchstack
7.5 High Handmade Framework Plugin handmade-framework Local File Inclusion ≤ 3.9 CVE-2026-22521 Patchstack
6.5 Medium Block Slider Plugin block-slider Broken Access Control ≤ 2.2.3 CVE-2026-22522 Patchstack
5.3 Medium Zorka Theme zorka Broken Access Control No login needed ≤ 1.5.7 CVE-2026-0676 Patchstack
4.3 Medium Campaign Monitor Plugin forms-for-campaign-monitor Broken Access Control ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-0674 Patchstack
5.4 Medium Easy Media Download Plugin easy-media-download Content Injection CSS Injection ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-69169 Patchstack
7.1 High Scroll rss excerpt Plugin scroll-rss-excerpt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.0 CVE-2025-68892 Patchstack
7.1 High WP App Bar Plugin wp-app-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-68891 Patchstack
7.1 High e-shops Plugin e-shops-cart2 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-68890 Patchstack
7.1 High Pinpoll Plugin pinpoll Cross-Site Scripting No login needed ≤ 4.0.0 CVE-2025-68889 Patchstack
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-68887 Patchstack
6.5 Medium Flaming Password Reset Plugin flaming-password-reset Cross-Site Scripting ≤ 1.0.3 CVE-2025-68875 Patchstack
7.1 High Visitor Stats Widget Plugin visitor-stats-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.0 CVE-2025-68874 Patchstack
7.1 High PRIMER by chloédigital Plugin primer-by-chloedigital Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.25 CVE-2025-68873 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Cross-Site Scripting ≤ 1.2.1 CVE-2025-68867 Patchstack
8.1 High Hendon Theme hendon Local File Inclusion No login needed ≤ 1.7 Fixed in 1.7 CVE-2025-67937 Patchstack
8.1 High Curly Theme curly Local File Inclusion No login needed ≤ 3.3 Fixed in 3.3 CVE-2025-67936 Patchstack
8.1 High Optimize Theme optimizewp Local File Inclusion No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-67935 Patchstack
8.1 High Wellspring Theme wellspring Local File Inclusion No login needed ≤ 2.8 Fixed in 2.8 CVE-2025-67934 Patchstack
7.1 High Taskbuilder Plugin taskbuilder Cross-Site Scripting No login needed ≤ 4.0.9 Fixed in 5.0.0 CVE-2025-67933 Patchstack
7.1 High Listeo Core Plugin listeo-core Cross-Site Scripting No login needed ≤ 2.0.19 Fixed in 2.0.19 CVE-2025-67932 Patchstack
7.5 High BulletProof Security Plugin bulletproof-security Information Disclosure Sensitive Data Exposure No login needed ≤ 6.9 Fixed in 7.0 CVE-2025-67931 Patchstack
7.1 High eHive Search Plugin ehive-search Cross-Site Scripting No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2025-67930 Patchstack
9.3 Critical Automotive Listings Plugin automotive SQL Injection No login needed ≤ 18.6 Fixed in 18.7 CVE-2025-67928 Patchstack
7.1 High Link Whisper Free Plugin link-whisper Cross-Site Scripting No login needed ≤ 0.8.8 Fixed in 0.8.9 CVE-2025-67927 Patchstack
6.5 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 1.10.4 Fixed in 1.10.5 CVE-2025-67926 Patchstack
7.5 High Corpkit Theme corpkit Local File Inclusion ≤ 2.0 Fixed in 2.0.1 CVE-2025-67925 Patchstack
9.9 Critical Corpkit Theme corpkit Arbitrary File Upload ≤ 2.0 Fixed in 2.0.1 CVE-2025-67924 Patchstack
7.1 High Grand Restaurant Plugin grandrestaurant Cross-Site Scripting No login needed ≤ 7.0.9 Fixed in 7.0.9 CVE-2025-67922 Patchstack
8.5 High Lobo Theme lobo SQL Injection ≤ 2.8.6 Fixed in 2.8.6 CVE-2025-67921 Patchstack
8.1 High Neo Ocular Theme neoocular Local File Inclusion No login needed ≤ 1.2 Fixed in 1.2 CVE-2025-67920 Patchstack
6.5 Medium Woffice Core Plugin woffice-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67919 Patchstack
7.1 High Woffice Plugin woffice Cross-Site Scripting No login needed ≤ 5.4.30 Fixed in 5.4.31 CVE-2025-67918 Patchstack
6.5 Medium Traveler Plugin traveler Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2025-67917 Patchstack
7.1 High Jobify Theme jobify Cross-Site Scripting No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2025-67916 Patchstack
8.8 High Timetics Plugin timetics Authentication Bypass Broken Authentication ≤ 1.0.46 Fixed in 1.0.48 CVE-2025-67915 Patchstack
7.7 High VidMov Theme vidmov Path Traversal ≤ 2.3.8 Fixed in 2.3.9 CVE-2025-67914 Patchstack
6.5 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control No login needed ≤ 3.0.3 Fixed in 3.0.3 CVE-2025-67913 Patchstack
9.8 Critical Newsletters Plugin newsletters-lite PHP Object Injection No login needed ≤ 4.11 Fixed in 4.12 CVE-2025-67911 Patchstack
9.1 Critical Contentstudio Plugin contentstudio Arbitrary File Upload ≤ 1.3.7 Fixed in 1.4.0 CVE-2025-67910 Patchstack
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
7.1 High CountDown With Image or Video Background Plugin countdown-with-background Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-27002 Patchstack
9.3 Critical Felan Framework Plugin felan-framework SQL Injection No login needed ≤ 1.1.3 CVE-2025-23993 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only