WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 74 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WooCommerce Multivendor Marketplace – REST API Plugin wcfm-marketplace-rest-api Broken Access Control REST API plugin <= 1.6.3 - Broken Access Control No login needed ≤ 1.6.3 CVE-2026-39794 Patchstack
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
7.5 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter No login needed ≤ 3.8.2 CVE-2026-18442 Wordfence
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.7.2.1 Fixed in 2.7.2.2 CVE-2026-66625 Patchstack
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Privilege Escalation Store Owner+ Privilege Escalation to Administrator 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74925 WPScan
7.1 High Classified Listing Plugin classified-listing Broken Access Control Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR 5.3.0 – < 6.1.1 Fixed in 6.1.1 CVE-2026-16281 WPScan
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
7.1 High WCFM Membership Plugin wc-multivendor-membership Privilege Escalation ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-84756 Patchstack
7.5 High User Verification Plugin Broken Access Control Unauthenticated Arbitrary Account Lockout via IDOR No login needed ≤ 2.0.47 CVE-2026-14861 WPScan
7.2 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Speaker Account Deletion via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13174 WPScan
8.1 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13169 WPScan
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66441 Patchstack
7.5 High Formidable Forms Signature Online Contract Automation Plugin forms-signature-formidable-online-contract-automation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-65523 Patchstack
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization < 5.0.11 Fixed in 5.0.11 CVE-2026-16605 WPScan
8.8 High Dokan Plugin dokan-lite Broken Access Control Missing Authorization to Authenticated (Vendor+) Privilege Escalation <=5.0.2 CVE-2026-8761 Wordfence
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-59539 Patchstack
7.5 High Dør Plugin dor Local File Inclusion ≤ 2.4.1 CVE-2026-57792 Patchstack
8.1 High User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Cross-User Role and Membership Tier Modification via IDOR < 5.2.2 Fixed in 5.2.2 CVE-2026-11963 WPScan
7.5 High EscortWP Theme Other Content Deletion via Vendor-Authored Backdoor No login needed ≤ 3.6.2 CVE-2026-12685 WPScan
8.1 High WCFM - WooCommerce Multivendor Membership Plugin wc-multivendor-membership Broken Access Control WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite ≤ 2.11.10 CVE-2026-3688 Wordfence
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint ≤ 5.0.4 CVE-2026-12224 Wordfence
8.1 High ProfilePress Plugin Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 4.16.17 Fixed in 4.16.17 CVE-2026-10820 WPScan
7.5 High Toolset Forms Plugin cred-frontend-editor Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.6.24 Fixed in 2.6.25 CVE-2026-56069 Patchstack
7.6 High SupportCandy Plugin supportcandy Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-54826 Patchstack
8.5 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.6.8 Fixed in 2.6.9 CVE-2026-54838 Patchstack
7.5 High ShapedPlugin Multiple Pro Plugins Plugin Information Disclosure Backdoor via Compromised Vendor Update Server No login needed 4.0.1 – < 4.0.2, 3.2.4 – < 3.2.5, 3.5.2 – < 3.5.3 Fixed in 4.0.2 CVE-2026-10735 WPScan
8.2 High Clean Login Plugin clean-login Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.15 Fixed in 1.16 CVE-2026-54184 Patchstack
7.3 High Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.30.24 Fixed in 10.30.25 CVE-2026-40768 Patchstack
7.5 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset ≤ 5.5.1 CVE-2026-8176 Wordfence
7.5 High VikRentCar Plugin vikrentcar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-52699 Patchstack
7.5 High Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.2.9 Fixed in 5.3.0 CVE-2026-48868 Patchstack
7.1 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.3.0.0 Fixed in 4.3.0.1 CVE-2026-39518 Patchstack
7.5 High Projectopia Plugin projectopia-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.25.2 CVE-2025-59133 Patchstack
8.1 High BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter ≤ 14.4.0 CVE-2026-53673 VulnCheck
7.3 High WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.10 Fixed in 2.11.11 CVE-2026-42753 Patchstack
7.5 High BP Better Messages Plugin bp-better-messages Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.14.16 Fixed in 2.15.0 CVE-2026-42736 Patchstack
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
8.8 High my-calendar Plugin Information Disclosure My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog No login needed < 3.7.7 CVE-2026-40308 GitHub_M
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
8.8 High BuddyPress Groupblog Plugin bp-groupblog Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR ≤ 1.9.3 CVE-2026-5144 Wordfence
7.2 High Gerador de Certificados – DevApps Plugin gerador-de-certificados-devapps Arbitrary File Upload DevApps <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload ≤ 1.3.6 CVE-2026-4808 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence
8.6 High WPSubscription Plugin subscription Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.8.10 Fixed in 1.8.11 CVE-2025-69347 Patchstack
7.5 High Authorsy Plugin authorsy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-24950 Patchstack
7.5 High PawFriends - Pet Shop and Veterinary Theme pawfriends Broken Access Control Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) No login needed ≤ 1.3 CVE-2026-22383 Patchstack
7.5 High Cnvrse Plugin cnvrse Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 026.02.10.20 Fixed in 026.02.10.20 CVE-2025-69394 Patchstack
7.5 High VidoRev Theme vidorev Local File Inclusion ≤ 2.9.9.9.9.9.7 CVE-2025-69373 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only