WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–50 of 1,401 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.3 Critical | WP BASE Booking | SQL Injection No login needed |
≤ 6.4.0 Fixed in 6.5.0 |
CVE-2026-103352 |
Patchstack | |
| 9.8 Critical | Advanced Post Manager | PHP Object Injection No login needed |
≤ 4.5.5 Fixed in 4.5.6 |
CVE-2026-97283 |
Patchstack | |
| 9.3 Critical | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection No login needed |
≤ 2.0.20 Fixed in 2.0.21 |
CVE-2026-103355 |
Patchstack | |
| 9.3 Critical | WordPress File Upload | Arbitrary File Upload SQL Injection No login needed |
≤ 5.1.10 Fixed in 5.2.0 |
CVE-2026-62071 |
Patchstack | |
| 9.8 Critical | Authorizer | Privilege Escalation No login needed |
≤ 3.15.3 Fixed in 3.16.0 |
CVE-2026-103752 |
Patchstack | |
| 9.8 Critical | Nested Pages | PHP Object Injection No login needed |
≤ 3.3.2 Fixed in 3.3.3 |
CVE-2026-100512 |
Patchstack | |
| 9.8 Critical | OAuth Single Sign On – SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability No login needed |
≤ 7.1.2 Fixed in 7.1.3 |
CVE-2026-97274 |
Patchstack | |
| 9.8 Critical | Booking Activities | PHP Object Injection No login needed |
≤ 1.18.7.1 Fixed in 1.18.8 |
CVE-2026-97248 |
Patchstack | |
| 9.3 Critical | Books Gallery | SQL Injection No login needed |
≤ 4.8.3 Fixed in 4.8.4 |
CVE-2026-96822 |
Patchstack | |
| 9.8 Critical | Estatik | Privilege Escalation No login needed |
≤ 4.3.5 Fixed in 4.3.6 |
CVE-2026-96350 |
Patchstack | |
| 10.0 Critical | SiteSkite | Remote Code Execution No login needed |
≤ 2.1.8 Fixed in 2.2.0 |
CVE-2026-96349 |
Patchstack | |
| 9.0 Critical | AcyMailing SMTP Newsletter | Remote Code Execution No login needed |
≤ 11.0.5 Fixed in 11.1.0 |
CVE-2026-94389 |
Patchstack | |
| 9.1 Critical | GiveWP | Authentication Bypass Broken Authentication No login needed |
≤ 4.16.9 Fixed in 4.17.0 |
CVE-2026-97196 |
Patchstack | |
| 9.3 Critical | Product Filter by WBW | SQL Injection No login needed |
≤ 3.1.7 Fixed in 3.1.8 |
CVE-2026-95601 |
Patchstack | |
| 9.8 Critical | Headless Single Sign On | Authentication Bypass Broken Authentication No login needed |
≤ 1.7.0 Fixed in 1.7.1 |
CVE-2026-62108 |
Patchstack | |
| 10.0 Critical | Migratico Lite | Remote Code Execution No login needed |
≤ 2.6.8 Fixed in 2.7.1 |
CVE-2026-62104 |
Patchstack | |
| 9.8 Critical | EduAdmin Booking | Authentication Bypass Broken Authentication No login needed |
≤ 5.4.2 Fixed in 6.0.0 |
CVE-2026-62101 |
Patchstack | |
| 9.8 Critical | ThemeREX Addons | PHP Object Injection No login needed |
< 2.45.0 Fixed in 2.45.0 |
CVE-2026-62105 |
Patchstack | |
| 9.8 Critical | Everest Forms | PHP Object Injection No login needed |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2026-62103 |
Patchstack | |
| 9.3 Critical | Verified Reviews (Avis Vérifiés) | SQL Injection No login needed |
≤ 2.4.6 |
CVE-2026-81800 |
Patchstack | |
| 9.8 Critical | JobSearch | PHP Object Injection No login needed |
≤ 3.2.0 |
CVE-2026-84834 |
Patchstack | |
| 9.8 Critical | Bricksforge | Privilege Escalation No login needed |
≤ 3.1.8.8 Fixed in 3.1.8.9 |
CVE-2026-84814 |
Patchstack | |
| 9.3 Critical | GeoDirectory | SQL Injection No login needed |
≤ 2.8.174 Fixed in 2.8.175 |
CVE-2026-84813 |
Patchstack | |
| 9.3 Critical | VikAppointments Services Booking Calendar | SQL Injection No login needed |
≤ 1.2.20 Fixed in 1.2.21 |
CVE-2026-84768 |
Patchstack | |
| 9.8 Critical | Mail Mint | PHP Object Injection No login needed |
≤ 1.31.0 Fixed in 1.31.1 |
CVE-2026-84753 |
Patchstack | |
| 9.8 Critical | YITH Request a Quote for WooCommerce Premium | Broken Access Control No login needed |
< 4.46.0 Fixed in 4.46.0 |
CVE-2026-84238 |
Patchstack | |
| 9.8 Critical | Authorizer | Privilege Escalation No login needed |
≤ 3.15.1 Fixed in 3.15.2 |
CVE-2026-81294 |
Patchstack | |
| 9.3 Critical | WCFM Marketplace | SQL Injection No login needed |
≤ 3.8.1 Fixed in 3.8.2 |
CVE-2026-81286 |
Patchstack | |
| 9.8 Critical | Nokri - Job Board | Privilege Escalation Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter No login needed |
≤ 1.6.6 |
CVE-2026-18550 |
Wordfence | |
| 10.0 Critical | Newspapers X | Other Backdoor No login needed |
1.0.46 – 1.0.48 Fixed in 1.0.49 |
CVE-2026-81779 |
Patchstack | |
| 9.8 Critical | Tickera | PHP Object Injection No login needed |
≤ 3.6.0.2 Fixed in 3.6.0.3 |
CVE-2026-82226 |
Patchstack | |
| 10.0 Critical | Hash Form | Arbitrary File Upload No login needed |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2026-81780 |
Patchstack | |
| 9.3 Critical | Throws SPAM Away | SQL Injection No login needed |
≤ 3.8.2 Fixed in 3.9 |
CVE-2026-81763 |
Patchstack | |
| 9.3 Critical | Smart Marketing SMS and Newsletters Forms | SQL Injection No login needed |
≤ 5.1.24 Fixed in 5.1.25 |
CVE-2026-81756 |
Patchstack | |
| 9.3 Critical | WP Data Access | SQL Injection No login needed |
≤ 5.5.81 Fixed in 5.5.82 |
CVE-2026-81293 |
Patchstack | |
| 10.0 Critical | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | Arbitrary File Upload No login needed |
≤ 4.4.1 Fixed in 4.4.2 |
CVE-2026-82970 |
Patchstack | |
| 10.0 Critical | GiveWP | Remote Code Execution No login needed |
≤ 4.16.7.1 Fixed in 4.16.7.2 |
CVE-2026-82222 |
Patchstack | |
| 9.8 Critical | Hash Form | PHP Object Injection No login needed |
≤ 1.4.1 Fixed in 1.4.2 |
CVE-2026-78292 |
Patchstack | |
| 9.3 Critical | Beautiful Taxonomy Filters | SQL Injection No login needed |
≤ 2.4.6 Fixed in 2.4.7 |
CVE-2026-78288 |
Patchstack | |
| 9.8 Critical | Geo Controller | PHP Object Injection No login needed |
≤ 8.9.8 Fixed in 8.9.9 |
CVE-2026-78286 |
Patchstack | |
| 9.1 Critical | Fluent Boards Pro | Arbitrary File Upload |
≤ 2.0.11 Fixed in 2.0.12 |
CVE-2026-78274 |
Patchstack | |
| 9.3 Critical | Epayco | SQL Injection No login needed |
≤ 8.4.6 Fixed in 8.4.7 |
CVE-2026-78260 |
Patchstack | |
| 9.8 Critical | ACPT (Pro) - Custom Post Types | Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed |
≤ 2.0.63 |
CVE-2026-32566 |
Patchstack | |
| 9.3 Critical | Visitor Traffic Real Time Statistics Pro | SQL Injection No login needed |
≤ 11.17 Fixed in 11.18 |
CVE-2026-32479 |
Patchstack | |
| 9.8 Critical | TranslatePress | Privilege Escalation No login needed |
≤ 3.3.2 Fixed in 3.3.3 |
CVE-2026-78267 |
Patchstack | |
| 9.8 Critical | The Events Calendar | PHP Object Injection No login needed |
≤ 6.17.2 Fixed in 6.17.3 |
CVE-2026-78265 |
Patchstack | |
| 9.8 Critical | WP Project Manager | PHP Object Injection No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2026-78262 |
Patchstack | |
| 9.8 Critical | ACPT (Pro) - Custom Post Types | PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed |
≤ 2.0.63 |
CVE-2026-32563 |
Patchstack | |
| 9.9 Critical | UltimateAI | Arbitrary File Upload |
≤ 3.1.0 |
CVE-2026-32559 |
Patchstack | |
| 9.3 Critical | Boost | SQL Injection No login needed |
≤ 2.0.4 |
CVE-2026-32555 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.