WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 1–50 of 66 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.3 Critical | tagDiv Opt-In Builder | SQL Injection No login needed |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2026-96330 |
Patchstack | |
| 9.1 Critical | Beaver Builder Page Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output No login needed |
≤ 2.11.0.5 |
CVE-2026-92084 |
Wordfence | |
| 9.8 Critical | Visual Composer Website Builder | Local File Inclusion Unauthenticated Local File Inclusion via 'vcv-template' Parameter No login needed |
≤ 45.16.0 |
CVE-2026-12227 |
Wordfence | |
| 9.8 Critical | Botiga Pro | Privilege Escalation Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route No login needed |
< 1.6.5 Fixed in 1.6.5 |
CVE-2026-86591 |
WPScan | |
| 9.8 Critical | JetFormBuilder | Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed |
≤ 3.6.2 |
CVE-2026-12793 |
Wordfence | |
| 9.8 Critical | AI Website Builder (GitHub build) | Remote Code Execution Unauthenticated RCE via Unprotected REST Routes No login needed |
1.0.0 – 1.0.0 |
CVE-2026-82923 |
WPScan | |
| 9.8 Critical | Avada | Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary File Write No login needed |
≤ 3.16, ≤ 7.16 |
CVE-2026-18431 |
Wordfence | |
| 9.8 Critical | RegistrationMagic | PHP Object Injection No login needed |
≤ 6.0.9.7 Fixed in 6.0.9.8 |
CVE-2026-73341 |
Patchstack | |
| 9.8 Critical | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed |
≤ 1.8.5 |
CVE-2024-13784 |
Wordfence | |
| 9.8 Critical | User Profile Builder | Authentication Bypass Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter No login needed |
≤ 3.16.4 |
CVE-2026-15826 |
Wordfence | |
| 9.8 Critical | Fluent Forms Pro | Other Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build No login needed |
6.2.7 |
CVE-2026-73532 |
VulnCheck | |
| 9.8 Critical | Ninja Tables Pro | Other Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build No login needed |
5.2.11 |
CVE-2026-73533 |
VulnCheck | |
| 9.8 Critical | Cost Calculator Builder PRO | Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed |
≤ 4.0.3 |
CVE-2026-14900 |
Wordfence | |
| 9.8 Critical | Thrive Quiz Builder | PHP Object Injection No login needed |
≤ 10.9.3.0 Fixed in 10.9.3.1 |
CVE-2026-59544 |
Patchstack | |
| 9.8 Critical | Easy Form Builder by WhiteStudio | Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint No login needed |
≤ 4.0.11 |
CVE-2026-13439 |
Wordfence | |
| 9.8 Critical | Divi Form Builder | Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter No login needed |
≤ 5.1.8 |
CVE-2026-5524 |
Wordfence | |
| 9.1 Critical | Avada (Fusion) Builder | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Form Entry Value No login needed |
≤ 3.15.3 |
CVE-2026-8713 |
Wordfence | |
| 9.8 Critical | Fusion Builder | PHP Object Injection No login needed |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-54194 |
Patchstack | |
| 9.8 Critical | RegistrationMagic | Authentication Bypass Broken Authentication No login needed |
≤ 6.0.8.6 Fixed in 6.0.8.7 |
CVE-2026-49764 |
Patchstack | |
| 9.3 Critical | Funnel Builder by FunnelKit | SQL Injection No login needed |
≤ 3.15.0.1 Fixed in 3.15.0.2 |
CVE-2026-42381 |
Patchstack | |
| 10.0 Critical | WooCommerce PDF Invoice Builder | Remote Code Execution No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2026-52704 |
Patchstack | |
| 9.3 Critical | Easy Form Builder | SQL Injection No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2026-42747 |
Patchstack | |
| 9.8 Critical | Divi Form Builder | Privilege Escalation Unauthenticated Privilege Escalation via 'role' No login needed |
≤ 5.1.2 |
CVE-2026-5118 |
Wordfence | |
| 9.8 Critical | Avada (Fusion) Builder | Remote Code Execution Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler No login needed |
≤ 3.15.2 |
CVE-2026-6279 |
Wordfence | |
| 9.9 Critical | JetFormBuilder | Remote Code Execution |
≤ <= 3.5.6.1 Fixed in 3.5.6.2 |
CVE-2026-32525 |
Patchstack | |
| 9.8 Critical | BuilderPress | Local File Inclusion No login needed |
≤ 2.0.1 |
CVE-2026-27065 |
Patchstack | |
| 9.3 Critical | Profile Builder Pro | SQL Injection No login needed |
< 3.14.0 Fixed in 3.14.0 |
CVE-2026-27413 |
Patchstack | |
| 9.9 Critical | Builderall Builder | Remote Code Execution |
≤ 3.0.1 |
CVE-2026-22390 |
Patchstack | |
| 9.8 Critical | User Profile Builder | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
1.1.27 – < 3.15.2 Fixed in 3.15.2 |
CVE-2025-15030 |
WPScan | |
| 9.8 Critical | RegistrationMagic | Privilege Escalation Unauthenticated Privilege Escalation via admin_order No login needed |
≤ 6.0.7.1 |
CVE-2025-15403 |
Wordfence | |
| 9.8 Critical | Mobile builder | Authentication Bypass Broken Authentication No login needed |
≤ 1.4.2 |
CVE-2025-68860 |
Patchstack | |
| 9.8 Critical | RegistrationMagic - Custom Registration Forms | PHP Object Injection Custom Registration Forms <= 3.7.9.2 - PHP Object Injection No login needed |
< 3.7.9.3 Fixed in 3.7.9.3 |
CVE-2017-20208 |
Wordfence | |
| 9.3 Critical | Easy Form Builder | SQL Injection No login needed |
≤ 3.8.15 Fixed in 3.8.16 |
CVE-2025-54678 |
Patchstack | |
| 9.8 Critical | HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.2.1 |
CVE-2025-7340 |
Wordfence | |
| 9.1 Critical | HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. | Path Traversal Directory Traversal to Arbitrary File Move No login needed |
≤ 2.2.1 |
CVE-2025-7360 |
Wordfence | |
| 9.1 Critical | HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 2.2.1 |
CVE-2025-7341 |
Wordfence | |
| 9.8 Critical | Course Builder | PHP Object Injection No login needed |
≤ 3.6.6 Fixed in 3.6.6 |
CVE-2025-48336 |
Patchstack | |
| 9.3 Critical | Pixel WordPress Form BuilderPlugin & Autoresponder | SQL Injection No login needed |
≤ 1.0.2 Fixed in 1.0.3 |
CVE-2025-31914 |
Patchstack | |
| 9.8 Critical | Smart Sections Theme Builder - WPBakery Page Builder Addon | PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed |
≤ 1.7.8 |
CVE-2025-39410 |
Patchstack | |
| 9.3 Critical | Cost Calculator Builder | SQL Injection No login needed |
≤ 3.2.65 Fixed in 3.2.68 |
CVE-2025-39587 |
Patchstack | |
| 9.8 Critical | Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder | PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed |
≤ 3.1.1 |
CVE-2025-3439 |
Wordfence | |
| 9.8 Critical | Build App Online | Local File Inclusion No login needed |
≤ 1.0.23 |
CVE-2025-32577 |
Patchstack | |
| 9.9 Critical | Countdown & Clock | Remote Code Execution |
≤ 2.8.8 Fixed in 2.8.9 |
CVE-2025-30841 |
Patchstack | |
| 9.8 Critical | Kubio AI Page Builder | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 2.5.1 |
CVE-2025-2294 |
Wordfence | |
| 9.9 Critical | Brizy – Page Builder | Arbitrary File Upload Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads |
≤ 2.6.4 |
CVE-2024-10960 |
Wordfence | |
| 9.8 Critical | Build App Online | Local File Inclusion No login needed |
≤ 1.0.23 |
CVE-2024-49649 |
Patchstack | |
| 9.1 Critical | Zita Site Builder | Broken Access Control Arbitrary Plugin Installation and Activation No login needed |
≤ 1.0.2 |
CVE-2024-54369 |
Patchstack | |
| 9.8 Critical | Matix Popup Builder | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0.0 |
CVE-2024-52382 |
Patchstack | |
| 9.8 Critical | Chartify – WordPress Chart | Local File Inclusion WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source No login needed |
≤ 2.9.5 |
CVE-2024-10571 |
Wordfence | |
| 9.8 Critical | RegistrationMagic – User Registration Plugin with Custom Registration Forms | Privilege Escalation User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery No login needed |
≤ 6.0.2.6 |
CVE-2024-10508 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.