WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control ≤ 1.23.2 Fixed in 1.23.3 CVE-2026-103337 Patchstack
6.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Broken Access Control Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-97305 Patchstack
5.3 Medium BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder Other Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - Bypass Vulnerability No login needed ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-97275 Patchstack
6.9 Medium Cozy Blocks Plugin cozy-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.23 Fixed in 2.2.24 CVE-2026-97070 Patchstack
6.5 Medium UsersWP Plugin userswp Broken Access Control ≤ 1.2.74 Fixed in 1.2.76 CVE-2026-103086 Patchstack
6.5 Medium WP User Manager Plugin wp-user-manager Privilege Escalation No login needed ≤ 2.9.20 Fixed in 2.9.21 CVE-2026-103085 Patchstack
6.5 Medium Lookzy Plugin woo-lookbook Broken Access Control No login needed ≤ 1.1.14 Fixed in 1.1.15 CVE-2026-102383 Patchstack
6.5 Medium RepairBuddy Plugin computer-repair-shop Cross-Site Scripting ≤ 4.1225 Fixed in 4.1227 CVE-2026-100509 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.63 Fixed in 1.0.64 CVE-2026-97304 Patchstack
6.5 Medium Image Slider Widget Plugin image-slider-widget Cross-Site Scripting ≤ 1.1.130 CVE-2026-42700 Patchstack
5.4 Medium LearnPress Plugin learnpress Cross-Site Scripting LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation ≤ 4.4.9.1 CVE-2026-105397 VulnCheck
5.3 Medium Kit (formerly ConvertKit) for WooCommerce Plugin convertkit-for-woocommerce Broken Access Control No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-105421 Patchstack
4.3 Medium Polylang Plugin polylang Information Disclosure Sensitive Data Exposure ≤ 3.8.7 Fixed in 3.8.8 CVE-2026-39783 Patchstack
5.3 Medium WP Event Solution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.25 Fixed in 4.1.26 CVE-2026-103684 Patchstack
5.3 Medium WP Event Solution Plugin wp-event-solution Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.25 Fixed in 4.1.26 CVE-2026-105073 Patchstack
5.3 Medium Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.13 Fixed in 6.2.14 CVE-2026-94669 Patchstack
4.3 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control ≤ 4.0.0 CVE-2026-39763 Patchstack
5.4 Medium Starter Templates Plugin astra-sites Broken Access Control ≤ 4.7.7 Fixed in 4.7.8 CVE-2026-39721 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.22 Fixed in 2.0.23 CVE-2026-105064 Patchstack
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Other Other vulnerability Type No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-103351 Patchstack
5.3 Medium PowerPress Podcasting Plugin powerpress Information Disclosure Sensitive Data Exposure No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104388 Patchstack
6.5 Medium Starter Templates Plugin astra-sites Cross-Site Scripting ≤ 4.7.7 Fixed in 4.7.8 CVE-2026-102393 Patchstack
5.4 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103079 Patchstack
6.5 Medium Name Directory Plugin name-directory Cross-Site Scripting ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104396 Patchstack
6.5 Medium Presto Player Plugin presto-player Cross-Site Scripting ≤ 4.5.2 Fixed in 4.5.3 CVE-2026-102914 Patchstack
4.3 Medium Event Tickets Plugin event-tickets Broken Access Control ≤ 5.30.0 Fixed in 5.30.0.1 CVE-2026-104675 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.109 Fixed in 4.11.110 CVE-2026-103084 Patchstack
5.3 Medium Name Directory Plugin name-directory Arbitrary Shortcode Execution No login needed ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104397 Patchstack
6.5 Medium Logo Showcase Plugin logo-showcase Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2026-105060 Patchstack
6.5 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting ≤ 5.14.2 Fixed in 5.15 CVE-2026-104673 Patchstack
6.5 Medium eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting ≤ 3.6.2 Fixed in 3.6.3 CVE-2026-105056 Patchstack
5.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Information Disclosure Sensitive Data Exposure ≤ 4.6.10 Fixed in 4.6.11 CVE-2026-103335 Patchstack
5.3 Medium WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.9.0.0 Fixed in 1.9.1.0 CVE-2026-105055 Patchstack
5.3 Medium CURCY Plugin woo-multi-currency Broken Access Control No login needed ≤ 2.2.17 Fixed in 2.2.18 CVE-2026-97071 Patchstack
4.3 Medium WP Admin Audit Plugin wp-admin-audit Broken Access Control ≤ 1.2.17 Fixed in 1.2.18 CVE-2026-105062 Patchstack
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103078 Patchstack
6.5 Medium WP VR Plugin wpvr Broken Access Control ≤ 9.1.3 Fixed in 9.1.4 CVE-2026-104386 Patchstack
6.5 Medium QR Redirector Plugin qr-redirector Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2026-105069 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting ≤ 4.17.0 Fixed in 4.18.0 CVE-2026-104404 Patchstack
5.3 Medium Events Manager Plugin events-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 7.4.5 Fixed in 7.4.6 CVE-2026-105068 Patchstack
4.3 Medium Memberful - Membership Plugin memberful-wp Information Disclosure Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure ≤ 1.81.2 Fixed in 1.82.0 CVE-2026-104401 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting ≤ 2.1.8 Fixed in 2.1.9 CVE-2026-104400 Patchstack
6.5 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting ≤ 3.6.13 Fixed in 3.6.14 CVE-2026-104409 Patchstack
4.3 Medium Mindio Magic MCP Plugin mindio-magic-mcp Information Disclosure Sensitive Data Exposure ≤ 0.5.6 Fixed in 0.7.1 CVE-2026-104402 Patchstack
4.3 Medium LearnPress Plugin learnpress Broken Access Control ≤ 4.4.9.1 CVE-2026-39717 Patchstack
4.7 Medium Aculect AI Companion Plugin aculect-ai-companion Open Redirect Unvalidated Redirects and Forwards No login needed ≤ 0.8.1 CVE-2026-39600 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
6.5 Medium WebSamurai Plugin websamurai Broken Access Control ≤ 1.0.7 CVE-2026-39439 Patchstack
6.5 Medium Airano MCP Bridge Plugin airano-mcp-bridge Broken Access Control ≤ 2.11.0 CVE-2026-32585 Patchstack
5.3 Medium Smart One Click Setup – Complete Demo Import & Export Plugin smart-one-click-setup Information Disclosure Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure No login needed ≤ 1.4.3 CVE-2026-32584 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only