WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WooCommerce Multivendor Marketplace – REST API Plugin wcfm-marketplace-rest-api Broken Access Control REST API plugin <= 1.6.3 - Broken Access Control No login needed ≤ 1.6.3 CVE-2026-39794 Patchstack
6.5 Medium Wappointment Plugin wappointment Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.7.7 CVE-2026-39756 Patchstack
6.5 Medium Faktur Pro for WooCommerce Plugin woorechnung Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.2.2 CVE-2026-32576 Patchstack
6.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Broken Access Control Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-97305 Patchstack
6.9 Medium Cozy Blocks Plugin cozy-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.23 Fixed in 2.2.24 CVE-2026-97070 Patchstack
5.4 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103079 Patchstack
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103078 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Unauthenticated Order Shipping Modification via IDOR No login needed < 4.8.8 Fixed in 4.8.8 CVE-2026-104118 WPScan
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
5.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.4.9 Fixed in 4.4.9.1 CVE-2026-104403 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor SQL Injection Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter ≤ 5.0.18 CVE-2026-12951 Wordfence
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-97269 Patchstack
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
4.3 Medium Majestic Support Plugin majestic-support Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102382 Patchstack
5.3 Medium Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Order Key Disclosure via IDOR No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96173 WPScan
5.3 Medium Pay with Vipps for WooCommerce Plugin woo-vipps Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.2.4 Fixed in 6.2.5 CVE-2026-97259 Patchstack
5.3 Medium Review Schema Plugin review-schema Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-97282 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.5.0 Fixed in 6.5.2 CVE-2026-97079 Patchstack
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 20.8.17 Fixed in 20.8.18 CVE-2026-97078 Patchstack
4.3 Medium Newsletters, Email Marketing, SMS and Popups by Omnisend Plugin omnisend Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-97074 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.16.9 Fixed in 4.17.0 CVE-2026-97066 Patchstack
6.5 Medium Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object References (IDOR) ≤ 28.2 Fixed in 28.3 CVE-2026-96347 Patchstack
5.3 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.6.12.31 Fixed in 1.6.12.33 CVE-2026-94673 Patchstack
4.3 Medium Safe SVG Plugin safe-svg Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-94672 Patchstack
5.4 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.27 Fixed in 6.4.28 CVE-2026-94173 Patchstack
5.4 Medium Flexible PDF Coupons Plugin flexible-coupons Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.14.11 Fixed in 1.14.12 CVE-2026-62081 Patchstack
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Information Disclosure Unauthenticated Customer Email and Cart Disclosure via IDOR No login needed < 6.3 Fixed in 6.3 CVE-2026-92436 WPScan
3.8 Low Bookly Plugin Information Disclosure Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR < 28.3 Fixed in 28.3 CVE-2026-86839 WPScan
2.7 Low Events Manager Plugin events-manager Broken Access Control Contributor+ Arbitrary Ticket Overwrite via IDOR < 7.4.5 Fixed in 7.4.5 CVE-2026-93661 WPScan
2.7 Low WPeMatico RSS Feed Fetcher Plugin wpematico Information Disclosure Contributor+ Campaign Configuration and Log Disclosure via IDOR < 2.8.26 Fixed in 2.8.26 CVE-2026-89004 WPScan
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Arbitrary User Course Progress Disclosure via IDOR < 3.4.2 Fixed in 3.4.2 CVE-2026-82849 WPScan
6.5 Medium YITH WooCommerce Request A Quote Plugin yith-woocommerce-request-a-quote Broken Access Control Insecure Direct Object References (IDOR) No login needed < 4.46.1 Fixed in 4.46.1 CVE-2026-95602 Patchstack
5.3 Medium Team Plugin tlp-team Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-95592 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.70 Fixed in 2.1.72 CVE-2026-94080 Patchstack
5.3 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2026-93623 Patchstack
4.3 Medium SiteSkite Plugin siteskite Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-93513 Patchstack
4.3 Medium Booking Manager Plugin booking-manager Broken Access Control Subscriber+ Arbitrary User Plugin Meta Modification via IDOR < 2.1.21 Fixed in 2.1.21 CVE-2026-91025 WPScan
4.3 Medium MasterStudy LMS Plugin Information Disclosure Subscriber+ Quiz Attempt Grade Disclosure via IDOR < 3.7.50 Fixed in 3.7.50 CVE-2026-81339 WPScan
6.5 Medium Newsletters Plugin newsletters-lite Information Disclosure Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR No login needed < 4.18.1 Fixed in 4.18.1 CVE-2026-16264 WPScan
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93344 VulnCheck
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax < 2.1.72 Fixed in 2.1.72 CVE-2026-93343 VulnCheck
5.4 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93342 VulnCheck
4.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93341 VulnCheck
4.2 Medium NextGEN Gallery Plugin Broken Access Control Authenticated Arbitrary Gallery Image Deletion via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81653 WPScan
2.7 Low NextGEN Gallery Plugin Information Disclosure Contributor+ Image Metadata Disclosure via IDOR 3.59.5 – < 4.5.0 Fixed in 4.5.0 CVE-2026-81652 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81651 WPScan
5.5 Medium Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Account Modification and Deletion via IDOR < 1.2.4 Fixed in 1.2.4 CVE-2026-92425 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only