WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 118 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High BEAR Plugin woo-bulk-editor Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-95526 Patchstack
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
4.3 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84024 WPScan
6.5 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84023 WPScan
6.4 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import ≤ 3.35 CVE-2026-6642 Wordfence
8.0 High Bulk Password Reset Plugin bulk-password-reset Privilege Escalation Authenticated (Subscriber+) Arbitrary Password Reset ≤ 1.3.3 CVE-2026-14873 Wordfence
2.7 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk 1.0.255 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77787 WPScan
8.5 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-82227 Patchstack
4.3 Medium Dokan Plugin Broken Access Control Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint < 5.0.9 Fixed in 5.0.9 CVE-2026-16564 WPScan
5.3 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() No login needed ≤ 1.9.0 CVE-2026-11995 Wordfence
7.1 High WOLF - WordPress Posts Bulk Editor and Manager Plugin Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed < 1.1.0 Fixed in 1.1.0 CVE-2026-14234 WPScan
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
6.4 Medium Bulk Page Generator Plugin lpagery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 2.5.7 CVE-2026-15404 Wordfence
4.9 Medium WP Bulk Delete Plugin wp-bulk-delete SQL Injection Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter ≤ 1.4.2 CVE-2026-15727 Wordfence
4.9 Medium WooCommerce Bulk Edit Products – WP Sheet Editor Plugin woo-bulk-edit-products Broken Access Control WP Sheet Editor plugin <= 1.8.21 - Broken Access Control ≤ 1.8.21 Fixed in 1.8.22 CVE-2026-61952 Patchstack
4.3 Medium Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation ≤ 3.12.27 CVE-2026-11992 Wordfence
5.3 Medium Bulk Order Update for WooCommerce Plugin bulk-order-update-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read via 'csv_url' Parameter No login needed ≤ 1.6 CVE-2026-14500 Wordfence
7.1 High BEAR Plugin woo-bulk-editor Cross-Site Scripting No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2026-57320 Patchstack
4.3 Medium Bulk SEO Image Plugin bulk-seo-image Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.1 CVE-2026-11997 Wordfence
6.4 Medium Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) Plugin auto-image-attributes-from-filename-with-bulk-updater Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute ≤ 4.9 CVE-2026-3722 Wordfence
8.1 High Media Library Assistant Plugin media-library-assistant Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed ≤ 3.35 CVE-2026-6075 Wordfence
5.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint No login needed ≤ 1.6.11.8 CVE-2026-6937 Wordfence
7.6 High BEAR Plugin woo-bulk-editor SQL Injection ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2026-45213 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-27415 Patchstack
6.5 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification No login needed ≤ 1.1.5 CVE-2026-1672 Wordfence
4.3 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion No login needed ≤ 1.1.5 CVE-2026-1673 Wordfence
7.6 High WOLF Plugin bulk-editor SQL Injection ≤ 1.0.8.7 Fixed in 1.0.9 CVE-2026-32458 Patchstack
6.5 Medium Astra Bulk Edit Plugin astra-bulk-edit Cross-Site Scripting ≤ 1.2.10 Fixed in 1.2.11 CVE-2026-32431 Patchstack
7.1 High WooCommerce Bulk Product Editor Plugin woocommerce-quick-product-editor Broken Access Control ≤ 3.0 CVE-2025-69381 Patchstack
4.3 Medium Set Bulk Post Categories Plugin set-bulk-post-categories Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Post Category Update No login needed ≤ 1.1 CVE-2026-1081 Wordfence
4.3 Medium Wordpress Movies Bulk Importer Plugin movies Cross-Site Request Forgery No login needed ≤ <= 1.0 CVE-2026-22359 Patchstack
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
5.4 Medium Bulk Landing Page Creator for WordPress LPagery Plugin lpagery Broken Access Control ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-22490 Patchstack
4.3 Medium My Sticky Elements Plugin mystickyelements Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion ≤ 2.3.3 CVE-2025-14428 Wordfence
6.5 Medium Pro Bulk Watermark Plugin pro-watermark Path Traversal ≤ 2.0 CVE-2025-28973 Patchstack
7.6 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.1.13 Fixed in 1.1.14 CVE-2025-68550 Patchstack
4.3 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Plugin/Theme Archival No login needed ≤ 1.9.6 CVE-2025-14399 Wordfence
4.3 Medium Image Optimizer by wps.sk Plugin image-optimizer-wpssk Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Image Optimization No login needed ≤ 1.2.0 CVE-2025-12190 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
4.3 Medium Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Plugin Broken Access Control Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion ≤ 1.8.3 CVE-2025-12113 Wordfence
6.5 Medium Bulk Auto Image Title Attribute Plugin bulk-image-title-attribute Cross-Site Scripting ≤ 2.0.1 CVE-2025-62921 Patchstack
7.1 High Bulk Watermark Plugin bulk-watermark Cross-Site Request Forgery No login needed ≤ 1.6.10 CVE-2025-58845 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-58819 Patchstack
4.3 Medium Pro Bulk Watermark Plugin pro-watermark Path Traversal ≤ 2.0 CVE-2025-4956 Patchstack
4.3 Medium WP Bulk Delete Plugin wp-bulk-delete Broken Access Control ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58192 Patchstack
5.5 Medium Featured Image Plus – Quick & Bulk Edit with Unsplash Plugin featured-image-plus Server-Side Request Forgery Quick & Bulk Edit with Unsplash <= 1.6.6 - Authenticated (Admin+) Server-Side Request Forgery ≤ 1.6.6 CVE-2025-5818 Wordfence
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-28951 Patchstack
7.1 High Bulk YouTube Post Creator Plugin bulk-youtube-post-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-49423 Patchstack
4.3 Medium Custom Bulk/Quick Edit Plugin custom-bulkquick-edit Cross-Site Request Forgery No login needed ≤ 1.6.10 CVE-2025-30946 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only