WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1–50 of 66 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 2
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical tagDiv Opt-In Builder Plugin td-subscription SQL Injection No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-96330 Patchstack
9.1 Critical Beaver Builder Page Builder Plugin beaver-builder-lite-version Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output No login needed ≤ 2.11.0.5 CVE-2026-92084 Wordfence
9.8 Critical Visual Composer Website Builder Plugin visualcomposer Local File Inclusion Unauthenticated Local File Inclusion via 'vcv-template' Parameter No login needed ≤ 45.16.0 CVE-2026-12227 Wordfence
9.8 Critical Botiga Pro Plugin Privilege Escalation Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route No login needed < 1.6.5 Fixed in 1.6.5 CVE-2026-86591 WPScan
9.8 Critical JetFormBuilder Plugin jetformbuilder Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed ≤ 3.6.2 CVE-2026-12793 Wordfence
9.8 Critical AI Website Builder (GitHub build) Plugin Remote Code Execution Unauthenticated RCE via Unprotected REST Routes No login needed 1.0.0 – 1.0.0 CVE-2026-82923 WPScan
9.8 Critical Avada Theme Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary File Write No login needed ≤ 3.16, ≤ 7.16 CVE-2026-18431 Wordfence
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection No login needed ≤ 6.0.9.7 Fixed in 6.0.9.8 CVE-2026-73341 Patchstack
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
9.8 Critical User Profile Builder Plugin profile-builder Authentication Bypass Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter No login needed ≤ 3.16.4 CVE-2026-15826 Wordfence
9.8 Critical Fluent Forms Pro Plugin fluentformpro Other Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build No login needed 6.2.7 CVE-2026-73532 VulnCheck
9.8 Critical Ninja Tables Pro Plugin ninja-tables Other Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build No login needed 5.2.11 CVE-2026-73533 VulnCheck
9.8 Critical Cost Calculator Builder PRO Plugin Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed ≤ 4.0.3 CVE-2026-14900 Wordfence
9.8 Critical Thrive Quiz Builder Plugin thrive-quiz-builder PHP Object Injection No login needed ≤ 10.9.3.0 Fixed in 10.9.3.1 CVE-2026-59544 Patchstack
9.8 Critical Easy Form Builder by WhiteStudio Plugin easy-form-builder Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint No login needed ≤ 4.0.11 CVE-2026-13439 Wordfence
9.8 Critical Divi Form Builder Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter No login needed ≤ 5.1.8 CVE-2026-5524 Wordfence
9.1 Critical Avada (Fusion) Builder Plugin fusion-builder Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Form Entry Value No login needed ≤ 3.15.3 CVE-2026-8713 Wordfence
9.8 Critical Fusion Builder Plugin fusion-builder PHP Object Injection No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-54194 Patchstack
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.8.6 Fixed in 6.0.8.7 CVE-2026-49764 Patchstack
9.3 Critical Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection No login needed ≤ 3.15.0.1 Fixed in 3.15.0.2 CVE-2026-42381 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-42747 Patchstack
9.8 Critical Divi Form Builder Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'role' No login needed ≤ 5.1.2 CVE-2026-5118 Wordfence
9.8 Critical Avada (Fusion) Builder Plugin fusion-builder Remote Code Execution Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler No login needed ≤ 3.15.2 CVE-2026-6279 Wordfence
9.9 Critical JetFormBuilder Plugin jetformbuilder Remote Code Execution ≤ <= 3.5.6.1 Fixed in 3.5.6.2 CVE-2026-32525 Patchstack
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack
9.3 Critical Profile Builder Pro Plugin profile-builder-pro SQL Injection No login needed < 3.14.0 Fixed in 3.14.0 CVE-2026-27413 Patchstack
9.9 Critical Builderall Builder Plugin builderall-cheetah-for-wp Remote Code Execution ≤ 3.0.1 CVE-2026-22390 Patchstack
9.8 Critical User Profile Builder Plugin profile-builder Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed 1.1.27 – < 3.15.2 Fixed in 3.15.2 CVE-2025-15030 WPScan
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Unauthenticated Privilege Escalation via admin_order No login needed ≤ 6.0.7.1 CVE-2025-15403 Wordfence
9.8 Critical Mobile builder Plugin mobile-builder Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 CVE-2025-68860 Patchstack
9.8 Critical RegistrationMagic - Custom Registration Forms Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection Custom Registration Forms <= 3.7.9.2 - PHP Object Injection No login needed < 3.7.9.3 Fixed in 3.7.9.3 CVE-2017-20208 Wordfence
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 3.8.15 Fixed in 3.8.16 CVE-2025-54678 Patchstack
9.8 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.1 CVE-2025-7340 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Path Traversal Directory Traversal to Arbitrary File Move No login needed ≤ 2.2.1 CVE-2025-7360 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.1 CVE-2025-7341 Wordfence
9.8 Critical Course Builder Plugin course-builder PHP Object Injection No login needed ≤ 3.6.6 Fixed in 3.6.6 CVE-2025-48336 Patchstack
9.3 Critical Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder SQL Injection No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-31914 Patchstack
9.8 Critical Smart Sections Theme Builder - WPBakery Page Builder Addon Plugin visucom-smart-sections PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed ≤ 1.7.8 CVE-2025-39410 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.65 Fixed in 3.2.68 CVE-2025-39587 Patchstack
9.8 Critical Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder Plugin everest-forms PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.1.1 CVE-2025-3439 Wordfence
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2025-32577 Patchstack
9.9 Critical Countdown & Clock Plugin countdown-builder Remote Code Execution ≤ 2.8.8 Fixed in 2.8.9 CVE-2025-30841 Patchstack
9.8 Critical Kubio AI Page Builder Plugin kubio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.5.1 CVE-2025-2294 Wordfence
9.9 Critical Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads ≤ 2.6.4 CVE-2024-10960 Wordfence
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2024-49649 Patchstack
9.1 Critical Zita Site Builder Plugin ai-site-builder Broken Access Control Arbitrary Plugin Installation and Activation No login needed ≤ 1.0.2 CVE-2024-54369 Patchstack
9.8 Critical Matix Popup Builder Plugin medma-matix Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0.0 CVE-2024-52382 Patchstack
9.8 Critical Chartify – WordPress Chart Plugin chart-builder Local File Inclusion WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source No login needed ≤ 2.9.5 CVE-2024-10571 Wordfence
9.8 Critical RegistrationMagic – User Registration Plugin with Custom Registration Forms Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery No login needed ≤ 6.0.2.6 CVE-2024-10508 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only