WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 133 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Five Star Business Profile and Schema Plugin business-profile Information Disclosure Author+ Sensitive Data Disclosure via Schema Field Default Callback 2.3.20 – < 2.4.0 Fixed in 2.4.0 CVE-2026-86817 WPScan
6.4 Medium Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter ≤ 6.1.1 CVE-2026-96647 Wordfence
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
7.6 High Business Directory Plugin business-directory-plugin SQL Injection ≤ 6.4.27 Fixed in 6.4.28 CVE-2026-62097 Patchstack
5.4 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.27 Fixed in 6.4.28 CVE-2026-94173 Patchstack
5.3 Medium Connections Business Directory Plugin Information Disclosure Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes No login needed ≤ 10.4.67 CVE-2026-86789 WPScan
6.4 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter ≤ 2.8.183 CVE-2026-96766 Wordfence
3.7 Low TikTok Plugin tiktok-for-business Broken Access Control Unauthenticated OAuth Code Redemption No login needed 1.2.0 – < 1.4.2 Fixed in 1.4.2 CVE-2026-92965 WPScan
5.3 Medium TikTok Plugin tiktok-for-business Broken Access Control Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter No login needed ≤ 1.4.1 CVE-2026-18346 Wordfence
3.5 Low Business Name Generator Plugin Cross-Site Scripting Admin+ Stored XSS via Button Color Setting ≤ 1.3 CVE-2025-15698 WPScan
8.8 High Consulting - Business, Finance Theme Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX ≤ 6.7.16 CVE-2026-14805 Wordfence
5.3 Medium Booktics – Booking Calendar for Appointments and Service Businesses Plugin booktics Broken Access Control Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization No login needed ≤ 1.0.23 CVE-2026-11446 Wordfence
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84758 Patchstack
7.2 High Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter No login needed ≤ 5.8.1 CVE-2026-19796 Wordfence
6.4 Medium Reviews and Rating – Google Reviews Plugin g-business-reviews-rating Cross-Site Scripting Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 5.10 CVE-2026-2388 Wordfence
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
7.1 High Business Directory Plugin business-directory-plugin Cross-Site Scripting No login needed ≤ 6.4.25 Fixed in 6.4.26 CVE-2026-28004 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting ≤ 6.4.24 Fixed in 6.4.25 CVE-2026-61959 Patchstack
9.3 Critical Simple Business Directory Pro Plugin simple-business-directory-pro SQL Injection No login needed ≤ 15.9.4 Fixed in 15.9.5 CVE-2026-57707 Patchstack
8.0 High WP Business Intelligence Lite Plugin wp-business-intelligence-lite Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification ≤ 3.2.0 CVE-2026-15293 Wordfence
6.4 Medium CM Business Directory Plugin cm-business-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields ≤ 1.5.7 CVE-2026-8892 Wordfence
9.1 Critical Five Star Business Profile and Schema Plugin business-profile Remote Code Execution Arbitrary Code Execution ≤ 2.3.19 CVE-2026-27436 Patchstack
7.1 High Automotive Car Dealership Business Theme automotive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.3.3 CVE-2026-27426 Patchstack
8.1 High Pearl - Corporate Business Theme pearl Local File Inclusion Corporate Business theme <= 3.4.10 - Local File Inclusion No login needed ≤ 3.4.10 CVE-2026-27412 Patchstack
9.1 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter No login needed ≤ 4.0.1 CVE-2026-6070 Wordfence
6.6 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.23 Fixed in 6.4.24 CVE-2026-57339 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting ≤ 6.4.22 Fixed in 6.4.23 CVE-2026-57328 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting No login needed ≤ 6.4.22 Fixed in 6.4.23 CVE-2026-57326 Patchstack
8.8 High Entrepreneur - Booking for Small Businesses Theme entrepreneurx PHP Object Injection Booking for Small Businesses WordPress Theme theme < 3.1.5 - PHP Object Injection < 3.1.5 Fixed in 3.1.5 CVE-2025-69130 Patchstack
9.9 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Upload ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-39591 Patchstack
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details ≤ 13.4.1 CVE-2025-14042 Wordfence
7.5 High DirectoryPress – Business Directory And Classified Ad Listing Plugin directorypress SQL Injection Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' No login needed ≤ 3.6.26 CVE-2026-3489 Wordfence
5.3 Medium Business One Page Plugin business-one-page Broken Access Control No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2026-32340 Patchstack
5.3 Medium Rara Business Plugin rara-business Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-32336 Patchstack
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action Fields ≤ 13.4 CVE-2025-14040 Wordfence
8.1 High PJ | Life & Business Coaching Theme pj Local File Inclusion No login needed ≤ 3.0.0 CVE-2025-69409 Patchstack
7.1 High Business Template Blocks for WPBakery (Visual Composer) Page Builder Plugin templates-and-addons-for-wpbakery-page-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-69390 Patchstack
4.3 Medium Business Roy Plugin business-roy Broken Access Control ≤ 1.1.4 CVE-2026-25395 Patchstack
5.9 Medium CM Business Directory Plugin cm-business-directory Cross-Site Scripting ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-25004 Patchstack
5.4 Medium Better Business Reviews Plugin better-business-reviews Broken Access Control ≤ 0.1.1 Fixed in 0.1.2 CVE-2026-23804 Patchstack
5.3 Medium Business Directory Plugin business-directory-plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Listing Modification No login needed ≤ 6.4.20 CVE-2026-1656 Wordfence
7.5 High Business Directory Plugin business-directory-plugin SQL Injection Unauthenticated SQL Injection via payment Parameter No login needed ≤ 6.4.21 CVE-2026-2576 Wordfence
6.4 Medium Debt.com Business in a Box Plugin debtcom-business-in-a-box Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.1.0 CVE-2025-13852 Wordfence
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2025-68887 Patchstack
8.1 High Brook Plugin brook Local File Inclusion Agency Business Creative theme <= 2.9.0 - Local File Inclusion No login needed ≤ 2.9.0 CVE-2025-14430 Patchstack
4.3 Medium Better Business Reviews Plugin better-business-reviews Broken Access Control ≤ 0.1.1 Fixed in 0.1.2 CVE-2025-69354 Patchstack
4.9 Medium Business Directory Plugin business-directory-plugin Broken Access Control ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-64630 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Cross-Site Request Forgery No login needed ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-67596 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only