WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,651–4,700 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 94 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Plugin themeisle-companion Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter ≤ 3.0.6 CVE-2026-11358 Wordfence
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook No login needed ≤ 4.7.5 CVE-2026-12093 Wordfence
4.3 Medium Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization Plugin optimole-wp Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed ≤ 4.2.6 CVE-2026-11784 Wordfence
4.9 Medium Advanced Order Export For WooCommerce Plugin woo-order-export-lite SQL Injection Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter ≤ 4.0.10 CVE-2026-11360 Wordfence
4.9 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Administrator+) SQL Injection via 'data' Parameter ≤ 3.9.11 CVE-2026-10736 Wordfence
4.3 Medium PressPrimer Quiz Plugin pressprimer-quiz Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' Parameters ≤ 2.3.0 CVE-2026-10623 Wordfence
4.3 Medium Kadence Blocks Plugin kadence-blocks Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization ≤ 3.7.5 CVE-2026-11357 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter ≤ 1.15.43 CVE-2026-11776 Wordfence
5.3 Medium Event Koi Lite Plugin eventkoi-lite Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints No login needed ≤ 1.3.13.1 CVE-2026-10029 Wordfence
5.3 Medium FireBox Popups Plugin firebox Information Disclosure Unauthenticated Sensitive Information Exposure in 'form_id' Parameter No login needed ≤ 3.1.7 CVE-2026-12120 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Administrator+) SQL Injection via 'name' Parameter ≤ 1.15.43 CVE-2026-11777 Wordfence
8.8 High Offload, AI & Optimize with Cloudflare Images Plugin cf-images Remote Code Execution Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action ≤ 1.10.2 CVE-2026-9860 Wordfence
4.3 Medium Equalize Digital Accessibility Checker Plugin accessibility-checker Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' Parameter ≤ 1.42.1 CVE-2026-9199 Wordfence
8.8 High E2Pdf Plugin e2pdf Broken Access Control Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter ≤ 1.32.26 CVE-2026-12407 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers ≤ 5.0.3 CVE-2026-10023 Wordfence
9.3 Critical Motors Plugin motors-car-dealership-classified-listings SQL Injection No login needed ≤ 1.4.109 Fixed in 1.4.110 CVE-2026-54812 Patchstack
7.5 High Nexi XPay Plugin cartasi-x-pay Broken Access Control No login needed ≤ 8.3.1 Fixed in 8.3.2 CVE-2026-54810 Patchstack
9.3 Critical GIFT4U Plugin gift4u-gift-cards-all-in-one-for-woo SQL Injection No login needed ≤ 1.0.10 Fixed in 1.1.0 CVE-2026-54809 Patchstack
9.3 Critical WP Travel Gutenberg Blocks Plugin wp-travel-blocks SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2026-54808 Patchstack
7.3 High JobBank Plugin jobbank Broken Access Control No login needed ≤ 1.2.3 CVE-2025-69189 Patchstack
8.6 High JobCareer Theme jobcareer Arbitrary File Deletion No login needed ≤ 7.3 CVE-2025-69128 Patchstack
9.8 Critical Creatify Theme creatify PHP Object Injection No login needed ≤ 1.5 CVE-2025-60236 Patchstack
9.8 Critical The Hospital Theme nrghospital PHP Object Injection No login needed ≤ 1.8.1 CVE-2025-60231 Patchstack
8.5 High SureDash Plugin suredash SQL Injection ≤ 1.8.0 Fixed in 1.8.1 CVE-2026-54813 Patchstack
8.1 High Motors Plugin motors-car-dealership-classified-listings Local File Inclusion No login needed ≤ 1.4.109 Fixed in 1.4.110 CVE-2026-54814 Patchstack
9.3 Critical Cargo Shipping Location for WooCommerce Plugin cargo-shipping-location-for-woocommerce SQL Injection No login needed ≤ 5.6 Fixed in 5.7 CVE-2026-54815 Patchstack
7.5 High Advanced Ads Plugin advanced-ads Remote Code Execution ≤ 2.0.21 Fixed in 2.0.22 CVE-2026-54816 Patchstack
6.5 Medium MStore API Plugin mstore-api Authentication Bypass Broken Authentication No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-54817 Patchstack
8.5 High Slimstat Analytics Plugin wp-slimstat SQL Injection ≤ 5.4.11 Fixed in 5.4.12 CVE-2026-54818 Patchstack
9.3 Critical Listdom Plugin listdom SQL Injection No login needed ≤ 5.4.0 Fixed in 5.5.0 CVE-2026-54819 Patchstack
9.8 Critical The Barber Shop Theme nrgbarbershop PHP Object Injection No login needed ≤ 1.9 CVE-2025-60230 Patchstack
9.8 Critical Lagom Theme lagom PHP Object Injection No login needed ≤ 2.0 CVE-2025-60229 Patchstack
6.5 Medium WorkScout-Core Plugin workscout-core Arbitrary File Deletion No login needed ≤ 1.7.11 Fixed in 1.7.12 CVE-2026-52716 Patchstack
8.1 High Kastell Theme kastell Local File Inclusion No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-52707 Patchstack
9.8 Critical Moderno Theme moderno PHP Object Injection No login needed < 1.43 Fixed in 1.43 CVE-2026-49108 Patchstack
8.1 High Château Theme chateau PHP Object Injection No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2026-40757 Patchstack
8.1 High Zoya Theme zoya PHP Object Injection No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-40756 Patchstack
8.1 High Manufaktur Solutions Theme manufaktursolutions PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.2 CVE-2026-40752 Patchstack
8.1 High Eldon Theme eldon PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.5 CVE-2026-40738 Patchstack
8.1 High ShiftUp Theme shiftup PHP Object Injection No login needed ≤ 1.3 Fixed in 1.4 CVE-2026-40733 Patchstack
7.1 High Royal Elementor Addons Pro Plugin wpr-addons-pro Cross-Site Scripting No login needed < 1.7.1041 Fixed in 1.7.1041 CVE-2026-40720 Patchstack
8.1 High Atomlab Theme atomlab Local File Inclusion No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2026-39590 Patchstack
8.1 High SingleMalt Theme singlemalt PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2026-39576 Patchstack
8.1 High Hiroshi Theme hiroshi PHP Object Injection No login needed ≤ 1.5.1 Fixed in 1.6 CVE-2026-39560 Patchstack
8.1 High Uppercase Theme uppercase Local File Inclusion No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-39559 Patchstack
8.1 High Konsept Theme konsept PHP Object Injection No login needed ≤ 1.9 Fixed in 2.0 CVE-2026-39556 Patchstack
8.1 High Solene Core Plugin solene-core Local File Inclusion No login needed ≤ 2.3.2 Fixed in 2.3.4 CVE-2026-39523 Patchstack
8.1 High Alukas Theme alukas PHP Object Injection No login needed < 3.0.0 Fixed in 3.0.0 CVE-2026-39445 Patchstack
8.1 High PressMart Theme presssmart PHP Object Injection No login needed ≤ 1.2.26 Fixed in 1.2.27 CVE-2026-39442 Patchstack
8.1 High Line Agency Theme lineagency Local File Inclusion No login needed ≤ 1.3.1 CVE-2025-69175 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only