WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection No login needed ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103352 Patchstack
9.8 Critical Advanced Post Manager Plugin advanced-post-manager PHP Object Injection No login needed ≤ 4.5.5 Fixed in 4.5.6 CVE-2026-97283 Patchstack
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
9.3 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload SQL Injection No login needed ≤ 5.1.10 Fixed in 5.2.0 CVE-2026-62071 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.3 Fixed in 3.16.0 CVE-2026-103752 Patchstack
9.8 Critical Nested Pages Plugin wp-nested-pages PHP Object Injection No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-100512 Patchstack
9.8 Critical OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability No login needed ≤ 7.1.2 Fixed in 7.1.3 CVE-2026-97274 Patchstack
9.8 Critical Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.7.1 Fixed in 1.18.8 CVE-2026-97248 Patchstack
9.3 Critical Books Gallery Plugin wp-books-gallery SQL Injection No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-96822 Patchstack
9.8 Critical Estatik Plugin estatik Privilege Escalation No login needed ≤ 4.3.5 Fixed in 4.3.6 CVE-2026-96350 Patchstack
10.0 Critical SiteSkite Plugin siteskite Remote Code Execution No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2026-96349 Patchstack
9.0 Critical AcyMailing SMTP Newsletter Plugin acymailing Remote Code Execution No login needed ≤ 11.0.5 Fixed in 11.1.0 CVE-2026-94389 Patchstack
9.1 Critical GiveWP Plugin give Authentication Bypass Broken Authentication No login needed ≤ 4.16.9 Fixed in 4.17.0 CVE-2026-97196 Patchstack
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-95601 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-62108 Patchstack
10.0 Critical Migratico Lite Plugin migratico-lite Remote Code Execution No login needed ≤ 2.6.8 Fixed in 2.7.1 CVE-2026-62104 Patchstack
9.8 Critical EduAdmin Booking Plugin eduadmin-booking Authentication Bypass Broken Authentication No login needed ≤ 5.4.2 Fixed in 6.0.0 CVE-2026-62101 Patchstack
9.8 Critical ThemeREX Addons Plugin trx_addons PHP Object Injection No login needed < 2.45.0 Fixed in 2.45.0 CVE-2026-62105 Patchstack
9.8 Critical Everest Forms Plugin everest-forms PHP Object Injection No login needed ≤ 3.6.0 Fixed in 3.6.1 CVE-2026-62103 Patchstack
9.3 Critical Verified Reviews (Avis Vérifiés) Plugin netreviews SQL Injection No login needed ≤ 2.4.6 CVE-2026-81800 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.2.0 CVE-2026-84834 Patchstack
9.8 Critical Bricksforge Plugin bricksforge Privilege Escalation No login needed ≤ 3.1.8.8 Fixed in 3.1.8.9 CVE-2026-84814 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.174 Fixed in 2.8.175 CVE-2026-84813 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84753 Patchstack
9.8 Critical YITH Request a Quote for WooCommerce Premium Plugin yith-woocommerce-request-a-quote-premium Broken Access Control No login needed < 4.46.0 Fixed in 4.46.0 CVE-2026-84238 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.1 Fixed in 3.15.2 CVE-2026-81294 Patchstack
9.3 Critical WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2026-81286 Patchstack
9.8 Critical Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter No login needed ≤ 1.6.6 CVE-2026-18550 Wordfence
10.0 Critical Newspapers X Theme newspapers-x Other Backdoor No login needed 1.0.46 – 1.0.48 Fixed in 1.0.49 CVE-2026-81779 Patchstack
9.8 Critical Tickera Plugin tickera-event-ticketing-system PHP Object Injection No login needed ≤ 3.6.0.2 Fixed in 3.6.0.3 CVE-2026-82226 Patchstack
10.0 Critical Hash Form Plugin hash-form Arbitrary File Upload No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-81780 Patchstack
9.3 Critical Throws SPAM Away Plugin throws-spam-away SQL Injection No login needed ≤ 3.8.2 Fixed in 3.9 CVE-2026-81763 Patchstack
9.3 Critical Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp SQL Injection No login needed ≤ 5.1.24 Fixed in 5.1.25 CVE-2026-81756 Patchstack
9.3 Critical WP Data Access Plugin wp-data-access SQL Injection No login needed ≤ 5.5.81 Fixed in 5.5.82 CVE-2026-81293 Patchstack
10.0 Critical WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Arbitrary File Upload No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-82970 Patchstack
10.0 Critical GiveWP Plugin give Remote Code Execution No login needed ≤ 4.16.7.1 Fixed in 4.16.7.2 CVE-2026-82222 Patchstack
9.8 Critical Hash Form Plugin hash-form PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-78292 Patchstack
9.3 Critical Beautiful Taxonomy Filters Plugin beautiful-taxonomy-filters SQL Injection No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2026-78288 Patchstack
9.8 Critical Geo Controller Plugin cf-geoplugin PHP Object Injection No login needed ≤ 8.9.8 Fixed in 8.9.9 CVE-2026-78286 Patchstack
9.1 Critical Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Upload ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78274 Patchstack
9.3 Critical Epayco Plugin epayco-gateway SQL Injection No login needed ≤ 8.4.6 Fixed in 8.4.7 CVE-2026-78260 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed ≤ 2.0.63 CVE-2026-32566 Patchstack
9.3 Critical Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro SQL Injection No login needed ≤ 11.17 Fixed in 11.18 CVE-2026-32479 Patchstack
9.8 Critical TranslatePress Plugin translatepress-multilingual Privilege Escalation No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-78267 Patchstack
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection No login needed ≤ 6.17.2 Fixed in 6.17.3 CVE-2026-78265 Patchstack
9.8 Critical WP Project Manager Plugin wedevs-project-manager PHP Object Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-78262 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed ≤ 2.0.63 CVE-2026-32563 Patchstack
9.9 Critical UltimateAI Plugin ultimate_ai Arbitrary File Upload ≤ 3.1.0 CVE-2026-32559 Patchstack
9.3 Critical Boost Plugin boost SQL Injection No login needed ≤ 2.0.4 CVE-2026-32555 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only