WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103066 Patchstack
8.8 High VK Google Job Posting Manager Plugin vk-google-job-posting-manager PHP Object Injection ≤ 1.3.1 Fixed in 1.3.2 CVE-2026-100511 Patchstack
7.2 High WP Spell Check Plugin wp-spell-check PHP Object Injection ≤ 12.1 Fixed in 12.2 CVE-2026-100506 Patchstack
8.8 High Simple Event Planner Plugin simple-event-planner PHP Object Injection ≤ 1.5.7 Fixed in 1.5.8 CVE-2026-97257 Patchstack
7.2 High WP Ultimate Exporter Plugin wp-ultimate-exporter PHP Object Injection ≤ 3.0 Fixed in 3.1 CVE-2026-103348 Patchstack
7.2 High Sunshine Photo Cart Plugin sunshine-photo-cart PHP Object Injection ≤ 3.7.1 Fixed in 3.7.2 CVE-2026-93617 Patchstack
7.2 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro PHP Object Injection ≤ 13.5.7 Fixed in 13.5.8 CVE-2026-103349 Patchstack
7.6 High Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Broken Access Control Giveaways and Contests plugin <= 3.0.2 - Broken Access Control ≤ 3.0.2 Fixed in 3.1.0 CVE-2026-97303 Patchstack
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.24 Fixed in 2.8.0 CVE-2026-103334 Patchstack
7.1 High RepairBuddy Plugin computer-repair-shop Information Disclosure Sensitive Data Exposure ≤ 4.1226 Fixed in 4.1227 CVE-2026-97309 Patchstack
7.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Cross-Site Scripting No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100515 Patchstack
7.1 High Adsmonetizer Plugin adsensei-b30 Cross-Site Scripting No login needed ≤ 3.2.4 CVE-2025-15643 Patchstack
8.5 High Sirv Plugin sirv SQL Injection ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-104389 Patchstack
7.6 High Groundhogg Plugin groundhogg SQL Injection ≤ 4.8.3 Fixed in 4.9 CVE-2026-104408 Patchstack
7.1 High PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104407 Patchstack
7.5 High Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 4.0.17 Fixed in 4.0.18 CVE-2026-97307 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2026-103062 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.14 Fixed in 14.16.15 CVE-2026-97276 Patchstack
7.1 High Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting No login needed ≤ 3.7.11.1 Fixed in 3.7.12 CVE-2026-103354 Patchstack
8.8 High Ultimate Member Plugin ultimate-member Privilege Escalation ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-96451 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
8.2 High Kirki Plugin kirki Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-103065 Patchstack
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
8.8 High ByteCoreStack – MCP Connector for AI Tools Plugin bcs-mcp-manager Privilege Escalation MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation ≤ 1.2.2 Fixed in 1.2.4 CVE-2026-103068 Patchstack
7.1 High Parallax Section block Plugin parallax-section Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.1.0 CVE-2026-102378 Patchstack
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
8.8 High Icegram Plugin icegram PHP Object Injection ≤ 3.1.31 Fixed in 3.1.44 CVE-2026-97284 Patchstack
7.6 High Social Boost Plugin social-boost Broken Access Control ≤ 3.6.2 Fixed in 3.7.0 CVE-2026-97277 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.1 High MaxGalleria Plugin maxgalleria Cross-Site Scripting No login needed ≤ 6.5.3 Fixed in 6.5.4 CVE-2026-97260 Patchstack
8.6 High AcyMailing SMTP Newsletter Plugin acymailing Arbitrary File Deletion No login needed ≤ 11.0.5 Fixed in 11.1.0 CVE-2026-95588 Patchstack
7.2 High Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce PHP Object Injection ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-94390 Patchstack
7.5 High WP Full Stripe Free Plugin wp-full-stripe-free Broken Access Control No login needed ≤ 8.5.6 Fixed in 8.5.7 CVE-2026-62073 Patchstack
7.6 High Ultimate Member Plugin ultimate-member SQL Injection ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-62059 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-62060 Patchstack
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
8.0 High Memberful - Membership Plugin memberful-wp Cross-Site Request Forgery Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) ≤ 1.81.0 Fixed in 1.81.1 CVE-2026-103067 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
7.2 High Extra Product Options For WooCommerce | Custom Product Addons and Fields Plugin woo-extra-product-options PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2026-102392 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.4 Fixed in 3.6.6 CVE-2026-102391 Patchstack
8.8 High Photo Gallery by 10Web Plugin photo-gallery PHP Object Injection ≤ 1.8.46 Fixed in 1.8.47 CVE-2026-102377 Patchstack
7.1 High Branda Plugin branda-white-labeling Cross-Site Scripting No login needed ≤ 3.4.32 Fixed in 3.4.33 CVE-2026-102376 Patchstack
7.1 High Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Scripting No login needed ≤ 1.27.14 Fixed in 1.27.15 CVE-2026-100510 Patchstack
8.8 High Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp PHP Object Injection ≤ 1.66 Fixed in 1.67 CVE-2026-97291 Patchstack
7.1 High Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting No login needed ≤ 3.36 Fixed in 3.37 CVE-2026-97290 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only