WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103066 Patchstack
8.8 High VK Google Job Posting Manager Plugin vk-google-job-posting-manager PHP Object Injection ≤ 1.3.1 Fixed in 1.3.2 CVE-2026-100511 Patchstack
7.2 High WP Spell Check Plugin wp-spell-check PHP Object Injection ≤ 12.1 Fixed in 12.2 CVE-2026-100506 Patchstack
8.8 High Simple Event Planner Plugin simple-event-planner PHP Object Injection ≤ 1.5.7 Fixed in 1.5.8 CVE-2026-97257 Patchstack
7.2 High WP Ultimate Exporter Plugin wp-ultimate-exporter PHP Object Injection ≤ 3.0 Fixed in 3.1 CVE-2026-103348 Patchstack
6.5 Medium WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control ≤ 1.23.2 Fixed in 1.23.3 CVE-2026-103337 Patchstack
7.2 High Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection ≤ 3.7.1 Fixed in 3.7.2 CVE-2026-93617 Patchstack
7.2 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro PHP Object Injection ≤ 13.5.7 Fixed in 13.5.8 CVE-2026-103349 Patchstack
7.6 High Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Broken Access Control Giveaways and Contests plugin <= 3.0.2 - Broken Access Control ≤ 3.0.2 Fixed in 3.1.0 CVE-2026-97303 Patchstack
9.3 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection No login needed ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103352 Patchstack
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.24 Fixed in 2.8.0 CVE-2026-103334 Patchstack
7.1 High RepairBuddy Plugin computer-repair-shop Information Disclosure Sensitive Data Exposure ≤ 4.1226 Fixed in 4.1227 CVE-2026-97309 Patchstack
6.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Broken Access Control Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-97305 Patchstack
9.8 Critical Advanced Post Manager Plugin advanced-post-manager PHP Object Injection No login needed ≤ 4.5.5 Fixed in 4.5.6 CVE-2026-97283 Patchstack
5.3 Medium BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder Other Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - Bypass Vulnerability No login needed ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-97275 Patchstack
6.9 Medium Cozy Blocks Plugin cozy-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.23 Fixed in 2.2.24 CVE-2026-97070 Patchstack
6.5 Medium UsersWP Plugin userswp Broken Access Control ≤ 1.2.74 Fixed in 1.2.76 CVE-2026-103086 Patchstack
6.5 Medium WP User Manager Plugin wp-user-manager Privilege Escalation No login needed ≤ 2.9.20 Fixed in 2.9.21 CVE-2026-103085 Patchstack
6.5 Medium Lookzy Plugin woo-lookbook Broken Access Control No login needed ≤ 1.1.14 Fixed in 1.1.15 CVE-2026-102383 Patchstack
7.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Cross-Site Scripting No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100515 Patchstack
6.5 Medium RepairBuddy Plugin computer-repair-shop Cross-Site Scripting ≤ 4.1225 Fixed in 4.1227 CVE-2026-100509 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.63 Fixed in 1.0.64 CVE-2026-97304 Patchstack
7.1 High Adsmonetizer Plugin adsensei-b30 Cross-Site Scripting No login needed ≤ 3.2.4 CVE-2025-15643 Patchstack
6.5 Medium Image Slider Widget Plugin image-slider-widget Cross-Site Scripting ≤ 1.1.130 CVE-2026-42700 Patchstack
5.4 Medium LearnPress Plugin learnpress Cross-Site Scripting LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation ≤ 4.4.9.1 CVE-2026-105397 VulnCheck
5.3 Medium Kit (formerly ConvertKit) for WooCommerce Plugin convertkit-for-woocommerce Broken Access Control No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-105421 Patchstack
4.3 Medium Polylang Plugin polylang Information Disclosure Sensitive Data Exposure ≤ 3.8.7 Fixed in 3.8.8 CVE-2026-39783 Patchstack
5.3 Medium WP Event Solution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.25 Fixed in 4.1.26 CVE-2026-103684 Patchstack
5.3 Medium WP Event Solution Plugin wp-event-solution Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.25 Fixed in 4.1.26 CVE-2026-105073 Patchstack
5.3 Medium Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.13 Fixed in 6.2.14 CVE-2026-94669 Patchstack
4.3 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control ≤ 4.0.0 CVE-2026-39763 Patchstack
5.4 Medium Starter Templates Plugin astra-sites Broken Access Control ≤ 4.7.7 Fixed in 4.7.8 CVE-2026-39721 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.22 Fixed in 2.0.23 CVE-2026-105064 Patchstack
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Other Other vulnerability Type No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-103351 Patchstack
8.5 High Sirv Plugin sirv SQL Injection ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-104389 Patchstack
5.3 Medium PowerPress Podcasting Plugin powerpress Information Disclosure Sensitive Data Exposure No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104388 Patchstack
6.5 Medium Starter Templates Plugin astra-sites Cross-Site Scripting ≤ 4.7.7 Fixed in 4.7.8 CVE-2026-102393 Patchstack
5.4 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103079 Patchstack
6.5 Medium Name Directory Plugin name-directory Cross-Site Scripting ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104396 Patchstack
6.5 Medium Presto Player Plugin presto-player Cross-Site Scripting ≤ 4.5.2 Fixed in 4.5.3 CVE-2026-102914 Patchstack
4.3 Medium Event Tickets Plugin event-tickets Broken Access Control ≤ 5.30.0 Fixed in 5.30.0.1 CVE-2026-104675 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.109 Fixed in 4.11.110 CVE-2026-103084 Patchstack
5.3 Medium Name Directory Plugin name-directory Arbitrary Shortcode Execution No login needed ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104397 Patchstack
6.5 Medium Logo Showcase Plugin logo-showcase Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2026-105060 Patchstack
6.5 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting ≤ 5.14.2 Fixed in 5.15 CVE-2026-104673 Patchstack
6.5 Medium eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting ≤ 3.6.2 Fixed in 3.6.3 CVE-2026-105056 Patchstack
7.6 High Groundhogg Plugin groundhogg SQL Injection ≤ 4.8.3 Fixed in 4.9 CVE-2026-104408 Patchstack
5.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Information Disclosure Sensitive Data Exposure ≤ 4.6.10 Fixed in 4.6.11 CVE-2026-103335 Patchstack
5.3 Medium WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.9.0.0 Fixed in 1.9.1.0 CVE-2026-105055 Patchstack
5.3 Medium CURCY Plugin woo-multi-currency Broken Access Control No login needed ≤ 2.2.17 Fixed in 2.2.18 CVE-2026-97071 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only