WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–50 of 404 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | Business Essentials for Contact Form 7 | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed |
≤ 1.2.1 |
CVE-2026-97661 |
Wordfence | |
| 6.8 Medium | WP YouTube Lyte | Cross-Site Scripting Contributor+ Stored XSS via Embed Block Attributes |
< 1.7.31 Fixed in 1.7.31 |
CVE-2026-96895 |
WPScan | |
| 6.5 Medium | Custom Thank You Page for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Settings Export and Settings Reset No login needed |
≤ 1.1.2 |
CVE-2026-4806 |
Wordfence | |
| 8.8 High | YOP Poll | Privilege Escalation Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route No login needed |
≤ 7.0.10 |
CVE-2026-85682 |
Wordfence | |
| 4.3 Medium | Masteriyo LMS | Information Disclosure Subscriber+ Quiz Answer Key Disclosure |
< 3.4.2 Fixed in 3.4.2 |
CVE-2026-82850 |
WPScan | |
| 4.3 Medium | Masteriyo LMS | Information Disclosure Subscriber+ Arbitrary User Course Progress Disclosure via IDOR |
< 3.4.2 Fixed in 3.4.2 |
CVE-2026-82849 |
WPScan | |
| 6.5 Medium | PixelYourSite – Your smart PIXEL (TAG) Manager | Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) |
≤ 11.4.1 Fixed in 11.4.2 |
CVE-2026-95530 |
Patchstack | |
| 7.5 High | Rename wp-login.php to anything you want | SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed |
≤ 2.0.1 |
CVE-2026-93368 |
Wordfence | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed |
≤ 3.15.3 |
CVE-2026-94504 |
Wordfence | |
| 5.4 Medium | Ditty | Cross-Site Scripting Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute |
< 3.1.70 Fixed in 3.1.70 |
CVE-2026-93339 |
VulnCheck | |
| 8.8 High | WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import |
2.0 – 3.8.3 |
CVE-2026-93031 |
Wordfence | |
| 8.6 High | Yo | SQL Injection Unauthenticated SQL Injection via username Parameter No login needed |
1.1 – 1.3.1 |
CVE-2026-87963 |
WPScan | |
| 8.8 High | YouTube Embed | Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed |
10.0 – 10.3 |
CVE-2026-88793 |
WPScan | |
| 3.7 Low | User Registration & Membership | Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed |
5.0 – < 5.2.8 Fixed in 5.2.8 |
CVE-2026-86407 |
WPScan | |
| 2.7 Low | Masteriyo LMS | Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR |
1.14.0 – < 3.4.1 Fixed in 3.4.1 |
CVE-2026-82851 |
WPScan | |
| 6.8 Medium | Masteriyo LMS | Cross-Site Scripting Instructor+ Stored XSS via Course Highlights |
< 3.4.1 Fixed in 3.4.1 |
CVE-2026-82847 |
WPScan | |
| 9.9 Critical | Masteriyo LMS | PHP Object Injection Subscriber+ PHP Object Injection |
< 3.4.1 Fixed in 3.4.1 |
CVE-2026-82845 |
WPScan | |
| 8.6 High | Yogeta WP Cloud | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 1.0 |
CVE-2026-80494 |
WPScan | |
| 5.3 Medium | Masteriyo - LMS | Broken Access Control LMS plugin <= 3.4.0 - Broken Access Control No login needed |
≤ 3.4.0 Fixed in 3.4.1 |
CVE-2026-62132 |
Patchstack | |
| 8.8 High | Masteriyo - LMS | PHP Object Injection LMS plugin <= 3.4.0 - PHP Object Injection |
≤ 3.4.0 Fixed in 3.4.1 |
CVE-2026-62107 |
Patchstack | |
| 7.5 High | Thank You Page Customizer for WooCommerce | Broken Access Control No login needed |
≤ 1.2.2 |
CVE-2026-81786 |
Patchstack | |
| 7.1 High | MailMunch – Grow your Email List | Authentication Bypass Grow your Email List plugin <= 3.2.5 - Broken Authentication |
≤ 3.2.5 |
CVE-2026-81783 |
Patchstack | |
| 6.5 Medium | Youzify | Path Traversal Arbitrary File Download |
≤ 1.3.7 |
CVE-2026-81275 |
Patchstack | |
| 5.3 Medium | Masteriyo LMS | Information Disclosure Unauthenticated Course Enrollment Disclosure No login needed |
1.3.1 – < 3.4.0 Fixed in 3.4.0 |
CVE-2026-82848 |
WPScan | |
| 7.5 High | Eventin | Local File Inclusion Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter |
≤ 4.1.22 |
CVE-2026-15667 |
Wordfence | |
| 7.5 High | Eventin | Local File Inclusion Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter |
≤ 4.1.22 |
CVE-2026-15406 |
Wordfence | |
| 6.4 Medium | LearnPress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' |
≤ 4.3.9.1 |
CVE-2026-12230 |
Wordfence | |
| 7.1 High | EDD Product Catalog Feed by PixelYourSite | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter |
≤ 1.0.2 |
CVE-2026-9331 |
Wordfence | |
| 5.3 Medium | Masteriyo LMS | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion No login needed |
≤ 2.2.0 |
CVE-2026-8279 |
Wordfence | |
| 6.6 Medium | Eventin | Local File Inclusion Contributor+ LFI via Event Layout Meta |
< 4.1.21 Fixed in 4.1.21 |
CVE-2026-84898 |
WPScan | |
| 6.8 Medium | Masteriyo LMS | Cross-Site Scripting Instructor+ Stored XSS via Course Custom Fields |
1.18.0 – < 3.4.0 Fixed in 3.4.0 |
CVE-2026-82846 |
WPScan | |
| 6.6 Medium | Yoast SEO Premium | Remote Code Execution Author+ Arbitrary .htaccess Directive Injection to RCE |
< 27.6.1 Fixed in 27.6.1 |
CVE-2026-10821 |
WPScan | |
| 7.1 High | Activity Log | Cross-Site Request Forgery No login needed |
≤ 2.13.1 Fixed in 2.14.0 |
CVE-2026-84759 |
Patchstack | |
| 8.8 High | Ninja Forms - Layout & Styles | PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed |
≤ 3.0.31 |
CVE-2026-81772 |
Patchstack | |
| 5.3 Medium | MultiVendorX | Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed |
5.0.13 – < 5.0.15 Fixed in 5.0.15 |
CVE-2026-74927 |
WPScan | |
| 6.5 Medium | Print Barcode Labels for your WooCommerce products/orders | Information Disclosure Sensitive Data Exposure |
≤ 4.0.0 Fixed in 4.0.1 |
CVE-2026-81280 |
Patchstack | |
| 5.4 Medium | Gravity Booster – Styles & Layouts for Gravity Forms | Broken Access Control Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control |
≤ 6.0 |
CVE-2026-74004 |
Patchstack | |
| 9.8 Critical | Masteriyo - LMS | Arbitrary File Upload LMS plugin <= 2.3.2 - Arbitrary File Upload No login needed |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2026-73996 |
Patchstack | |
| 9.8 Critical | Youzify | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 1.3.7 |
CVE-2026-73397 |
Patchstack | |
| 7.1 High | Mayosis Core | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.4.7 |
CVE-2026-32333 |
Patchstack | |
| 6.1 Medium | Masteriyo LMS | Cross-Site Scripting Instructor+ Stored XSS via Quiz Description No login needed |
< 2.3.3 Fixed in 2.3.3 |
CVE-2026-19712 |
WPScan | |
| 6.4 Medium | Video Gallery | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode |
≤ 4.0.4 |
CVE-2026-15790 |
Wordfence | |
| 6.4 Medium | Serious Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute |
≤ 1.4.0 |
CVE-2026-15726 |
Wordfence | |
| 4.4 Medium | Gravity Booster | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter |
≤ 5.26 |
CVE-2026-12477 |
Wordfence | |
| 5.4 Medium | Patterns Kit | Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link |
≤ 1.0.3 |
CVE-2026-15249 |
WPScan | |
| 5.4 Medium | YMC Filter | Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema |
3.6.0 – < 3.12.8 Fixed in 3.12.8 |
CVE-2026-16558 |
WPScan | |
| 7.5 High | WPC Name Your Price for WooCommerce | Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-16620 |
WPScan | |
| 6.5 Medium | Layouts for WPBakery | Broken Access Control Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action No login needed |
≤ 1.1.3 |
CVE-2026-7726 |
Wordfence | |
| 6.5 Medium | Contest Gallery | Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16057 |
WPScan | |
| 5.3 Medium | PixelYourSite | Information Disclosure Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation No login needed |
≤ 11.2.1, < 12.6.1 Fixed in 12.6.1 |
CVE-2026-18059 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.