WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 114 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
8.8 High YOP Poll Plugin yop-poll Privilege Escalation Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route No login needed ≤ 7.0.10 CVE-2026-85682 Wordfence
7.5 High Rename wp-login.php to anything you want Plugin rename-wp-loginphp-to-anything-you-want SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed ≤ 2.0.1 CVE-2026-93368 Wordfence
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed ≤ 3.15.3 CVE-2026-94504 Wordfence
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
8.6 High Yo Plugin SQL Injection Unauthenticated SQL Injection via username Parameter No login needed 1.1 – 1.3.1 CVE-2026-87963 WPScan
8.8 High YouTube Embed Plugin Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed 10.0 – 10.3 CVE-2026-88793 WPScan
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
8.8 High Masteriyo - LMS Plugin learning-management-system PHP Object Injection LMS plugin <= 3.4.0 - PHP Object Injection ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62107 Patchstack
7.5 High Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control No login needed ≤ 1.2.2 CVE-2026-81786 Patchstack
7.1 High MailMunch – Grow your Email List Plugin mailmunch Authentication Bypass Grow your Email List plugin <= 3.2.5 - Broken Authentication ≤ 3.2.5 CVE-2026-81783 Patchstack
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15667 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15406 Wordfence
7.1 High EDD Product Catalog Feed by PixelYourSite Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter ≤ 1.0.2 CVE-2026-9331 Wordfence
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
8.8 High Ninja Forms - Layout & Styles Plugin ninja-forms-style PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed ≤ 3.0.31 CVE-2026-81772 Patchstack
7.1 High Mayosis Core Plugin mayosis-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.7 CVE-2026-32333 Patchstack
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
7.2 High Planyo online reservation system Plugin planyo-online-reservation-system Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter No login needed ≤ 3.0 CVE-2026-3576 Wordfence
7.5 High Video Gallery Plugin youtube-showcase Information Disclosure Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter ≤ 4.0.3 CVE-2026-12923 Wordfence
8.5 High Recipe Maker For Your Food Blog from Zip Recipes Plugin zip-recipes SQL Injection ≤ 8.2.7 Fixed in 8.2.8 CVE-2026-57663 Patchstack
7.5 High Object Cache 4 everyone Plugin object-cache-4-everyone Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-54834 Patchstack
8.1 High Kelly Young Theme kelly-young Local File Inclusion No login needed ≤ 1.1.0 CVE-2025-69141 Patchstack
7.5 High Masteriyo - LMS Plugin learning-management-system Price Manipulation LMS plugin <= 2.1.5 - Payment Bypass No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-39524 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
7.2 High Cost of Goods by PixelYourSite Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import No login needed ≤ 1.2.12 CVE-2026-7613 Wordfence
7.5 High Court Reservation – Manage Your Court Bookings Online Plugin court-reservation SQL Injection Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injection No login needed ≤ 1.10.11 CVE-2026-1250 Wordfence
8.5 High Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin views-for-ninja-forms SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-42741 Patchstack
7.2 High PixelYourSite Pro Plugin pixelyoursite-pro Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery via 'urls[]' Parameter No login needed ≤ 12.5.0.1 CVE-2026-7049 Wordfence
8.8 High Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator ≤ 2.1.6 CVE-2026-4484 Wordfence
7.1 High Yobazar Theme yobazar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.7 CVE-2026-25356 Patchstack
8.1 High Kayon Theme kayon Local File Inclusion No login needed ≤ 1.3 CVE-2026-28027 Patchstack
8.1 High Yottis Theme yottis Local File Inclusion No login needed ≤ 1.0.10 CVE-2026-28011 Patchstack
7.1 High PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) No login needed ≤ 11.2.0.1 Fixed in 11.2.0.2 CVE-2026-27072 Patchstack
8.1 High Yokoo Theme yokoo Local File Inclusion No login needed ≤ 1.1.11 CVE-2025-69400 Patchstack
7.5 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control No login needed ≤ 2.23.0 Fixed in 2.24.0 CVE-2025-68048 Patchstack
7.2 High PixelYourSite Plugin pixelyoursite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 11.2.0 CVE-2026-1841 Wordfence
7.2 High PixelYourSite PRO Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 12.4.0.2 CVE-2026-1844 Wordfence
8.1 High Yolox Theme yolox Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-69075 Patchstack
8.1 High Hyori Plugin hyori Local File Inclusion No login needed ≤ 1.3.6 CVE-2025-69038 Patchstack
8.1 High Myour Plugin myour Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-67615 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
7.5 High Yoco Payments Plugin yoco-payment-gateway Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 3.9.0 CVE-2025-13801 Wordfence
7.1 High Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin yournewsapp Cross-Site Scripting Your native, mobile iPhone App and Android App Plugin <= 0.8.8.8 - Cross Site Scripting (XSS) No login needed ≤ 0.8.8.8 CVE-2025-50053 Patchstack
7.5 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Broken Access Control The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token No login needed ≤ 3.13.2 CVE-2025-11924 Wordfence
7.1 High YOP Poll Plugin yop-poll Cross-Site Scripting No login needed ≤ 6.5.37 Fixed in 6.5.38 CVE-2025-62040 Patchstack
8.8 High Yogi - Health Beauty & Yoga Plugin noo-yogi PHP Object Injection Health Beauty & Yoga Theme <= 2.9.2 - Deserialization of untrusted data ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-54719 Patchstack
7.1 High Yogi - Health Beauty & Yoga Plugin noo-yogi Cross-Site Scripting Health Beauty & Yoga theme <= 2.9.2 - Cross Site Scripting (XSS) No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-54718 Patchstack
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Broken Access Control Unauthenticated Price Alteration No login needed ≤ 2.1.9 CVE-2025-12115 Wordfence
7.1 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting No login needed ≤ 2.24.0 CVE-2025-52735 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only