WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1–50 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 7
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting No login needed ≤ 2.9.3 CVE-2026-94167 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.3.1 Fixed in 9.3.2 CVE-2026-96607 Patchstack
7.1 High BlockStrap Page Builder - Bootstrap Blocks Plugin blockstrap-page-builder-blocks Cross-Site Scripting Bootstrap Blocks plugin <= 0.1.58 - Cross Site Scripting (XSS) No login needed ≤ 0.1.58 Fixed in 0.1.59 CVE-2026-94632 Patchstack
8.5 High tagDiv Opt-In Builder Plugin td-subscription SQL Injection ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-96329 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 6.0.5 Fixed in 6.0.6 CVE-2026-95599 Patchstack
7.1 High ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Cross-Site Scripting Elementor WooCommerce Builder Addons plugin <= 3.4.1 - Cross Site Scripting (XSS) No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2026-95596 Patchstack
7.5 High Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included Plugin uncanny-automator PHP Object Injection AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion ≤ 7.6.1.1 CVE-2026-82627 Wordfence
7.5 High Nexi XPay Build Plugin Price Manipulation Unauthenticated Payment Bypass via NPG Notification Handler No login needed 7.2.2 – 7.6.2 CVE-2026-82212 WPScan
8.2 High Nexi XPay Build Plugin Information Disclosure Unauthenticated Payment Completion and Order Key Disclosure No login needed 7.0.0 – 7.6.2 CVE-2026-82211 WPScan
7.2 High Kirki – Freeform Page Builder, Website Builder & Customizer Plugin kirki Cross-Site Scripting Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata No login needed ≤ 6.3.1 CVE-2026-102173 Wordfence
7.5 High Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 4.0.17 Fixed in 4.0.18 CVE-2026-97307 Patchstack
8.8 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting Unauthenticated Stored XSS via Comment Content No login needed < 2.9.3 Fixed in 2.9.3 CVE-2026-88783 WPScan
7.2 High Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview No login needed ≤ 4.13.0 CVE-2026-93756 Wordfence
7.2 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) No login needed ≤ 2.9.2 CVE-2026-100107 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action No login needed ≤ 3.6.5.4 CVE-2026-97342 Wordfence
8.8 High Super Forms – Drag & Drop Form Builder Plugin Privilege Escalation Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login ≤ 6.3.316 CVE-2026-15897 Wordfence
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.4 Fixed in 3.6.6 CVE-2026-102391 Patchstack
7.1 High Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Scripting No login needed ≤ 1.27.14 Fixed in 1.27.15 CVE-2026-100510 Patchstack
7.2 High Page Builder by SiteOrigin Plugin siteorigin-panels PHP Object Injection ≤ 2.36.0 Fixed in 2.36.1 CVE-2026-97256 Patchstack
8.8 High Themify Builder Plugin themify-builder PHP Object Injection ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-96831 Patchstack
7.2 High HT Contact Form – Drag & Drop Form Builder Plugin ht-contactform Cross-Site Scripting Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenticated Stored Cross-Site Scripting via Rich Text Editor Field No login needed ≤ 2.10.2 CVE-2026-96326 Wordfence
7.2 High Themify Builder Plugin themify-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter No login needed ≤ 7.8.1 CVE-2026-95864 Wordfence
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Avatar Field No login needed ≤ 4.0.2 CVE-2026-95866 Wordfence
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
8.6 High JetFormBuilder Stripe Gateway Plugin SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed < 1.1.0 Fixed in 1.1.0 CVE-2022-4997 WPScan
7.1 High WP Table Builder Plugin wp-table-builder Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter ≤ 2.2.1 CVE-2026-6922 Wordfence
8.8 High BM Content Builder Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion < 3.17.1 Fixed in 3.17.1 CVE-2025-1281 Wordfence
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed ≤ 3.15.3 CVE-2026-94504 Wordfence
8.8 High Easy Form Builder Plugin easy-form-builder Cross-Site Scripting Unauthenticated Stored XSS via Form Type Confusion No login needed 4.0.0 – < 4.2.0 Fixed in 4.2.0 CVE-2026-85122 WPScan
7.1 High Export & Import WPBakery Page Builder Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.2 CVE-2026-81429 WPScan
8.8 High Live Composer Plugin live-composer-page-builder PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Shortcode ≤ 2.1.18 CVE-2026-16502 Wordfence
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.1 Fixed in 3.6.5.2 CVE-2026-84817 Patchstack
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field No login needed ≤ 3.15.7 CVE-2026-6431 Wordfence
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation No login needed 5.0.1.8 – < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77826 WPScan
7.5 High JetFormBuilder Plugin Information Disclosure Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19858 WPScan
8.8 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting Unauthenticated Stored XSS via ays_get_user_information No login needed 1.6.3 – < 1.8.5 Fixed in 1.8.5 CVE-2026-81737 WPScan
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Unauthenticated Stored XSS via Rating Field No login needed < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77792 WPScan
7.4 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82225 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82221 Patchstack
8.2 High Profile Builder Plugin Authentication Bypass Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass No login needed 3.8.1 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76548 WPScan
7.2 High WP User Frontend Plugin PHP Object Injection Editor+ PHP Object Injection via AI Form Builder < 4.3.10 Fixed in 4.3.10 CVE-2026-14558 WPScan
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.5 High Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Information Disclosure Unauthenticated Customer File Disclosure via getpublicfileupload No login needed < 1.2.176 Fixed in 1.2.176 CVE-2026-19728 WPScan
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting ≤ 1.7.1064 CVE-2026-17123 Wordfence
7.5 High JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.6.4.1 Fixed in 3.6.4.2 CVE-2026-28140 Patchstack
7.2 High FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More Plugin formgent Cross-Site Scripting Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.9.2 CVE-2025-15028 Wordfence
8.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter ≤ 9.2.3 CVE-2026-15450 Wordfence
7.2 High MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder Plugin mailchimp-subscribe-sm Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field Values No login needed ≤ 4.3.3 CVE-2026-15052 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only