WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 205 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Simple Event Planner Plugin simple-event-planner PHP Object Injection ≤ 1.5.7 Fixed in 1.5.8 CVE-2026-97257 Patchstack
6.8 Medium Horizontal Scrolling Announcements Plugin Cross-Site Scripting Contributor+ Stored XSS via Style Field ≤ 2.6 CVE-2026-17005 WPScan
7.2 High Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 5.3.5 CVE-2026-92977 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter No login needed ≤ 4.4.1 CVE-2026-14989 Wordfence
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Banner Settings Overwrite and A/B Test Data Reset 3.6.5 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82185 WPScan
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter No login needed ≤ 4.3.5 CVE-2026-13360 Wordfence
9.8 Critical AI ANN Theme ann PHP Object Injection No login needed ≤ 1.29.0 CVE-2026-65581 Patchstack
7.5 High Uncanny Automator Plugin uncanny-automator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints No login needed ≤ 7.3.2 CVE-2026-15025 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
7.6 High Uncanny Automator Plugin uncanny-automator SQL Injection ≤ 7.3.2 Fixed in 7.4.0 CVE-2026-65462 Patchstack
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token No login needed ≤ 7.3.1.4 CVE-2026-15008 Wordfence
5.3 Medium Members Plugin members Information Disclosure Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel No login needed ≤ 3.2.22 CVE-2026-12426 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action ≤ 4.3.6 CVE-2026-12955 Wordfence
4.9 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent SQL Injection Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter ≤ 4.3.6 CVE-2026-14475 Wordfence
9.8 Critical Uncanny Automator Pro Plugin Other Backdoor via Compromised Vendor Update Server No login needed 7.3.0.5 – < 7.3.0.6 Fixed in 7.3.0.6 CVE-2026-12375 WPScan
4.9 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 4.3.5 CVE-2026-12920 Wordfence
4.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification ≤ 2.2.1 CVE-2026-11773 Wordfence
9.8 Critical Uncanny Automator Pro Plugin uncanny-automator-pro PHP Object Injection No login needed ≤ 7.3.0.6 Fixed in 7.3.0.7 CVE-2026-56057 Patchstack
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection No login needed ≤ 7.3.1.2 Fixed in 7.3.1.3 CVE-2026-56031 Patchstack
8.8 High AdRotate Banner Manager Plugin adrotate Remote Code Execution Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute ≤ 5.17.7 CVE-2026-12242 Wordfence
4.3 Medium Reviews and Rating Plugin reviews-and-rating-docplanner Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action ≤ 1.1.4 CVE-2026-9619 Wordfence
6.1 Medium Osiris Signature Banner Plugin osiris-signature-banner Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter No login needed ≤ 0.5 CVE-2026-8905 Wordfence
2.7 Low UsersWP Plugin userswp Broken Access Control Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter ≤ 1.2.63 CVE-2026-12102 Wordfence
5.9 Medium Progress Planner Plugin progress-planner Cross-Site Scripting ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-28116 Patchstack
7.5 High easy-paypal-events-tickets Plugin easy-paypal-events-tickets Authentication Bypass Easy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code Scanning No login needed < 1.4.0 Fixed in 1.4.0 CVE-2026-32834 VulnCheck
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.11.0 Fixed in 1.12.0 CVE-2026-42645 Patchstack
9.8 Critical Barcode Scanner (+Mobile App) Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation via Insecure Token Authentication No login needed ≤ 1.11.0 CVE-2026-4880 Wordfence
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2026-25464 Patchstack
7.1 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator Cross-Site Scripting Banner Rotator plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28112 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist Cross-Site Scripting AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28110 Patchstack
7.1 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner Cross-Site Scripting AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28108 Patchstack
8.1 High Au Pair Agency - Babysitting & Nanny Theme au-pair-agency PHP Object Injection Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data No login needed ≤ 1.2.2 CVE-2026-27098 Patchstack
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
8.8 High Woocommerce Category Banner Management Plugin banner-management-for-woocommerce PHP Object Injection ≤ 2.5.1 CVE-2026-22354 Patchstack
7.5 High Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed ≤ 4.1.2 CVE-2025-11754 Wordfence
5.3 Medium WP Bannerize Pro Plugin wp-bannerize-pro Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2026-25012 Patchstack
6.4 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Cross-Site Scripting Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.10.0.2 CVE-2025-15522 Wordfence
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
9.0 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2025-68015 Patchstack
6.4 Medium Smart App Banners Plugin smart-app-banners Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' and 'verticalalign' Shortcode Attributes ≤ 1.2 CVE-2025-13841 Wordfence
7.1 High Jannah Plugin jannah Cross-Site Scripting No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64207 Patchstack
9.8 Critical Jannah Plugin jannah PHP Object Injection No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64206 Patchstack
8.1 High Jannah Plugin jannah Local File Inclusion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2025-64205 Patchstack
5.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 4.0.7 CVE-2025-14061 Wordfence
4.3 Medium AnnunciFunebri Impresa Plugin annuncifunebri-onoranza Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Deletion ≤ 4.7.0 CVE-2025-14447 Wordfence
4.4 Medium Weekly Planner Plugin weekly-planner Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-12186 Wordfence
7.2 High Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto Plugin codistoconnect Cross-Site Scripting Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-11727 Wordfence
4.4 Medium YouTube Subscribe Plugin easy-youtube-subscribe Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Title and Channel ID ≤ 3.0.0 CVE-2025-12025 Wordfence
7.2 High Telegram Bot & Channel Plugin telegram-bot Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Telegram Username No login needed ≤ 4.1 CVE-2025-13068 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only