WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 275 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons Plugin social-icons-widget-by-wpzoom Information Disclosure Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`… No login needed ≤ 4.7.3 CVE-2026-100149 Wordfence
5.3 Medium Easy PayPal & Stripe Buy Now Button Plugin wp-ecommerce-paypal Price Manipulation Unauthenticated Payment Amount Manipulation via Client-Supplied Price No login needed 1.8 – < 2.0.6 Fixed in 2.0.6 CVE-2026-90987 WPScan
5.3 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Information Disclosure Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum No login needed ≤ 2.5.6 CVE-2026-90988 WPScan
6.1 Medium Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL No login needed ≤ 3.0.1 CVE-2026-89047 Wordfence
8.6 High Pro Like Button Plugin SQL Injection Unauthenticated SQLi via 'postid' Parameter No login needed < 2.0 Fixed in 2.0 CVE-2026-89296 WPScan
9.8 Critical Request a Quote for WooCommerce Plugin get-a-quote-button-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via AJAX Popup Handler No login needed ≤ 2.9.2 CVE-2026-18143 Wordfence
7.1 High Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2026-94179 Patchstack
6.8 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Contributor+ Stored XSS via Creative Button Widget < 3.50.0 Fixed in 3.50.0 CVE-2026-85006 WPScan
3.5 Low Business Name Generator Plugin Cross-Site Scripting Admin+ Stored XSS via Button Color Setting ≤ 1.3 CVE-2025-15698 WPScan
6.4 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute ≤ 2.8.0 CVE-2026-84909 Wordfence
4.3 Medium Foxtool All-in-One: Contact chat button, Custom login, Media optimize images Plugin foxtool Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via 'option_key' Parameter of toggle_watermark AJAX Action ≤ 2.5.3 CVE-2026-18317 Wordfence
6.8 Medium All Bootstrap Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS via areoi/button type Attribute ≤ 1.3.31 CVE-2026-88993 WPScan
6.4 Medium Advanced Popups Plugin advanced-popups Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field ≤ 1.2.3 CVE-2026-11996 Wordfence
6.4 Medium Job Postings Plugin job-postings Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter ≤ 2.8.1 CVE-2026-18063 Wordfence
6.1 Medium Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Plugin chaty Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.9 CVE-2026-18964 Wordfence
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL < 5.9.8 Fixed in 5.9.8 CVE-2026-84021 WPScan
7.1 High Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Reflected XSS via Pin It Share Handler No login needed < 3.0.1 Fixed in 3.0.1 CVE-2026-19723 WPScan
6.8 Medium Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Contributor+ Stored XSS via Post Title < 3.0.1 Fixed in 3.0.1 CVE-2026-19719 WPScan
7.5 High HEL Online Classroom: AI-powered Online Classrooms Plugin Information Disclosure Unauthenticated BigBlueButton API Secret Disclosure No login needed ≤ 1.0.3 CVE-2026-77007 WPScan
8.5 High Like Button Rating Plugin likebtn-like-button SQL Injection ≤ 2.6.61 Fixed in 2.6.62 CVE-2026-78285 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
9.8 Critical Social Login & Sharing buttons with Analytics By SoClever Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.2.0 CVE-2026-77001 WPScan
6.4 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter ≤ 2.10.2.2 CVE-2026-17090 Wordfence
7.1 High Blog Floating Button Plugin blog-floating-button Cross-Site Scripting No login needed ≤ 1.4.20 Fixed in 1.4.21 CVE-2026-28170 Patchstack
5.3 Medium Payment Button for PayPal Plugin wp-paypal Price Manipulation Unauthenticated Payment Price Manipulation No login needed ≤ 1.2.3.44 CVE-2026-16990 WPScan
7.1 High Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2026-65517 Patchstack
6.1 Medium Blog Floating Button Plugin blog-floating-button Cross-Site Scripting Unauthenticated Stored XSS via User-Agent Header No login needed ≤ 1.4.20 CVE-2026-15383 WPScan
6.6 Medium Payment forms, Buy now buttons, and Invoicing System | GetPaid Plugin invoicing Local File Inclusion Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field ≤ 2.8.56 CVE-2026-17605 Wordfence
6.1 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via ult_buttons Shortcode No login needed < 3.21.5 Fixed in 3.21.5 CVE-2026-14921 WPScan
6.5 Medium Improved Save Button Plugin improved-save-button SQL Injection Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter ≤ 1.2.1 CVE-2026-16092 Wordfence
7.5 High Chat Help – Click to Chat Button & Form Plugin chat-help Broken Access Control Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 3.1.3 CVE-2026-15291 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 6.4.11 CVE-2026-15285 Wordfence
6.1 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting Reflected Cross-Site Scripting via 'view' Parameter No login needed ≤ 9.8.5 CVE-2026-13245 Wordfence
5.4 Medium Forget About Shortcode Buttons Plugin forget-about-shortcode-buttons Broken Access Control ≤ 2.1.3 CVE-2025-63041 Patchstack
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-31435 Patchstack
7.4 High Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons Plugin chatway-live-chat Information Disclosure AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin <= 1.4.8 - Sensitive Data Exposure ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-49082 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode ≤ 5.6.8 CVE-2026-3694 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter ≤ 1.7.1056 CVE-2026-5159 Wordfence
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute ≤ 3.3.5 CVE-2026-4059 Wordfence
6.4 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 2.0.8 CVE-2026-2509 Wordfence
7.5 High Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Request Forgery No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-34904 Patchstack
6.4 Medium WP Random Button Plugin wp-random-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'cat' Shortcode Attribute ≤ 1.0 CVE-2026-4086 Wordfence
4.3 Medium Purchase Button For Affiliate Link Plugin purchase-button Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.2 CVE-2026-1073 Wordfence
6.4 Medium Electric Enquiries Plugin electric-enquiries Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Shortcode Attribute ≤ 1.1 CVE-2025-14142 Wordfence
4.3 Medium Bitcoin Donate Button Plugin bitcoin-donate-button Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1380 Wordfence
5.3 Medium Payment Button for PayPal Plugin wp-paypal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Creation No login needed ≤ 1.2.3.41 CVE-2025-14463 Wordfence
4.3 Medium Sosh Share Buttons Plugin sosh-share-buttons Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-15377 Wordfence
4.3 Medium Sticky Action Buttons Plugin sticky-action-buttons Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.1 CVE-2025-14465 Wordfence
6.4 Medium Viitor Button Shortcodes Plugin viitor-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute ≤ 3.0.0 CVE-2025-14113 Wordfence
6.4 Medium WishSuite Plugin wishsuite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute ≤ 1.5.1 CVE-2025-13838 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only