WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 404 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
6.8 Medium WP YouTube Lyte Plugin wp-youtube-lyte Cross-Site Scripting Contributor+ Stored XSS via Embed Block Attributes < 1.7.31 Fixed in 1.7.31 CVE-2026-96895 WPScan
6.5 Medium Custom Thank You Page for WooCommerce Plugin wc-custom-thank-you Broken Access Control Missing Authorization to Unauthenticated Settings Export and Settings Reset No login needed ≤ 1.1.2 CVE-2026-4806 Wordfence
8.8 High YOP Poll Plugin yop-poll Privilege Escalation Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route No login needed ≤ 7.0.10 CVE-2026-85682 Wordfence
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Quiz Answer Key Disclosure < 3.4.2 Fixed in 3.4.2 CVE-2026-82850 WPScan
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Arbitrary User Course Progress Disclosure via IDOR < 3.4.2 Fixed in 3.4.2 CVE-2026-82849 WPScan
6.5 Medium PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) ≤ 11.4.1 Fixed in 11.4.2 CVE-2026-95530 Patchstack
7.5 High Rename wp-login.php to anything you want Plugin rename-wp-loginphp-to-anything-you-want SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed ≤ 2.0.1 CVE-2026-93368 Wordfence
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed ≤ 3.15.3 CVE-2026-94504 Wordfence
5.4 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute < 3.1.70 Fixed in 3.1.70 CVE-2026-93339 VulnCheck
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
8.6 High Yo Plugin SQL Injection Unauthenticated SQL Injection via username Parameter No login needed 1.1 – 1.3.1 CVE-2026-87963 WPScan
8.8 High YouTube Embed Plugin Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed 10.0 – 10.3 CVE-2026-88793 WPScan
3.7 Low User Registration & Membership Plugin user-registration Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed 5.0 – < 5.2.8 Fixed in 5.2.8 CVE-2026-86407 WPScan
2.7 Low Masteriyo LMS Plugin learning-management-system Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR 1.14.0 – < 3.4.1 Fixed in 3.4.1 CVE-2026-82851 WPScan
6.8 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Course Highlights < 3.4.1 Fixed in 3.4.1 CVE-2026-82847 WPScan
9.9 Critical Masteriyo LMS Plugin learning-management-system PHP Object Injection Subscriber+ PHP Object Injection < 3.4.1 Fixed in 3.4.1 CVE-2026-82845 WPScan
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 3.4.0 - Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62132 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system PHP Object Injection LMS plugin <= 3.4.0 - PHP Object Injection ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62107 Patchstack
7.5 High Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control No login needed ≤ 1.2.2 CVE-2026-81786 Patchstack
7.1 High MailMunch – Grow your Email List Plugin mailmunch Authentication Bypass Grow your Email List plugin <= 3.2.5 - Broken Authentication ≤ 3.2.5 CVE-2026-81783 Patchstack
6.5 Medium Youzify Plugin youzify Path Traversal Arbitrary File Download ≤ 1.3.7 CVE-2026-81275 Patchstack
5.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Unauthenticated Course Enrollment Disclosure No login needed 1.3.1 – < 3.4.0 Fixed in 3.4.0 CVE-2026-82848 WPScan
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15667 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15406 Wordfence
6.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' ≤ 4.3.9.1 CVE-2026-12230 Wordfence
7.1 High EDD Product Catalog Feed by PixelYourSite Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter ≤ 1.0.2 CVE-2026-9331 Wordfence
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion No login needed ≤ 2.2.0 CVE-2026-8279 Wordfence
6.6 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ LFI via Event Layout Meta < 4.1.21 Fixed in 4.1.21 CVE-2026-84898 WPScan
6.8 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Course Custom Fields 1.18.0 – < 3.4.0 Fixed in 3.4.0 CVE-2026-82846 WPScan
6.6 Medium Yoast SEO Premium Plugin Remote Code Execution Author+ Arbitrary .htaccess Directive Injection to RCE < 27.6.1 Fixed in 27.6.1 CVE-2026-10821 WPScan
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
8.8 High Ninja Forms - Layout & Styles Plugin ninja-forms-style PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed ≤ 3.0.31 CVE-2026-81772 Patchstack
5.3 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed 5.0.13 – < 5.0.15 Fixed in 5.0.15 CVE-2026-74927 WPScan
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
5.4 Medium Gravity Booster – Styles & Layouts for Gravity Forms Plugin styles-and-layouts-for-gravity-forms Broken Access Control Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control ≤ 6.0 CVE-2026-74004 Patchstack
9.8 Critical Masteriyo - LMS Plugin learning-management-system Arbitrary File Upload LMS plugin <= 2.3.2 - Arbitrary File Upload No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-73996 Patchstack
9.8 Critical Youzify Plugin youzify PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3.7 CVE-2026-73397 Patchstack
7.1 High Mayosis Core Plugin mayosis-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.7 CVE-2026-32333 Patchstack
6.1 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Quiz Description No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-19712 WPScan
6.4 Medium Video Gallery Plugin youtube-showcase Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode ≤ 4.0.4 CVE-2026-15790 Wordfence
6.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute ≤ 1.4.0 CVE-2026-15726 Wordfence
4.4 Medium Gravity Booster Plugin styles-and-layouts-for-gravity-forms Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter ≤ 5.26 CVE-2026-12477 Wordfence
5.4 Medium Patterns Kit Plugin Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link ≤ 1.0.3 CVE-2026-15249 WPScan
5.4 Medium YMC Filter Plugin ymc-smart-filter Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema 3.6.0 – < 3.12.8 Fixed in 3.12.8 CVE-2026-16558 WPScan
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
6.5 Medium Layouts for WPBakery Plugin layouts-for-wpbakery Broken Access Control Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action No login needed ≤ 1.1.3 CVE-2026-7726 Wordfence
6.5 Medium Contest Gallery Plugin contest-gallery Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library < 30.0.7 Fixed in 30.0.7 CVE-2026-16057 WPScan
5.3 Medium PixelYourSite Plugin pixelyoursite Information Disclosure Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation No login needed ≤ 11.2.1, < 12.6.1 Fixed in 12.6.1 CVE-2026-18059 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only