WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–39 of 39 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 3.8 Low | Bookly | Information Disclosure Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR |
< 28.3 Fixed in 28.3 |
CVE-2026-86839 |
WPScan | |
| 2.7 Low | Events Manager | Broken Access Control Contributor+ Arbitrary Ticket Overwrite via IDOR |
< 7.4.5 Fixed in 7.4.5 |
CVE-2026-93661 |
WPScan | |
| 2.7 Low | WPeMatico RSS Feed Fetcher | Information Disclosure Contributor+ Campaign Configuration and Log Disclosure via IDOR |
< 2.8.26 Fixed in 2.8.26 |
CVE-2026-89004 |
WPScan | |
| 2.7 Low | NextGEN Gallery | Information Disclosure Contributor+ Image Metadata Disclosure via IDOR |
3.59.5 – < 4.5.0 Fixed in 4.5.0 |
CVE-2026-81652 |
WPScan | |
| 3.1 Low | NextGEN Gallery | Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR |
< 4.5.0 Fixed in 4.5.0 |
CVE-2026-81651 |
WPScan | |
| 3.8 Low | Hydra Booking | Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR |
< 1.2.2 Fixed in 1.2.2 |
CVE-2026-92420 |
WPScan | |
| 2.7 Low | MasterStudy LMS 3.6.2 | Information Disclosure < 3.7.50 - Instructor+ Student PII Disclosure via IDOR |
3.6.2 – < 3.7.50 Fixed in 3.7.50 |
CVE-2026-88844 |
WPScan | |
| 3.8 Low | MasterStudy LMS | Broken Access Control Instructor+ Order Status Manipulation via IDOR |
< 3.7.50 Fixed in 3.7.50 |
CVE-2026-81340 |
WPScan | |
| 2.2 Low | BEAR - Bulk Editor and Products Manager Professional for WooCommerce | Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR |
< 1.2.2 Fixed in 1.2.2 |
CVE-2026-84025 |
WPScan | |
| 2.7 Low | Masteriyo LMS | Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR |
1.14.0 – < 3.4.1 Fixed in 3.4.1 |
CVE-2026-82851 |
WPScan | |
| 3.7 Low | WP Travel | Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed |
< 12.0.2 Fixed in 12.0.2 |
CVE-2026-13146 |
WPScan | |
| 2.2 Low | Kirki | Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR |
6.0.0 – < 6.3.0 Fixed in 6.3.0 |
CVE-2026-84225 |
WPScan | |
| 2.7 Low | Post Carousel | Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR |
4.0.0 – < 4.0.8 Fixed in 4.0.8 |
CVE-2026-78150 |
WPScan | |
| 3.8 Low | Timetics | Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR |
≤ 1.0.61 |
CVE-2026-14326 |
WPScan | |
| 3.8 Low | MasterStudy LMS | Broken Access Control Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR |
< 3.7.46 Fixed in 3.7.46 |
CVE-2026-81198 |
WPScan | |
| 2.7 Low | MasterStudy LMS | Information Disclosure Instructor+ Quiz Answer Disclosure via IDOR |
< 3.7.46 Fixed in 3.7.46 |
CVE-2026-81196 |
WPScan | |
| 2.7 Low | MasterStudy LMS | Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR |
< 3.7.42 Fixed in 3.7.42 |
CVE-2026-81200 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-79615 |
WPScan | |
| 2.7 Low | Tutor LMS | Information Disclosure Instructor+ Cross-Instructor Private Course Disclosure via IDOR |
< 4.0.6 Fixed in 4.0.6 |
CVE-2026-14187 |
WPScan | |
| 2.7 Low | Dokan | Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount |
< 5.0.14 Fixed in 5.0.14 |
CVE-2026-16577 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-14826 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-14825 |
WPScan | |
| 3.7 Low | Amelia | Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed |
< 2.4.6 Fixed in 2.4.6 |
CVE-2026-14213 |
WPScan | |
| 3.8 Low | Amelia Pro | Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR |
9.0 – < 9.7 Fixed in 9.7 |
CVE-2026-14211 |
WPScan | |
| 2.7 Low | MultiVendorX | Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint |
< 5.0.11 Fixed in 5.0.11 |
CVE-2026-16746 |
WPScan | |
| 2.7 Low | Brizy - Page Builder | Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR |
< 2.8.19 Fixed in 2.8.19 |
CVE-2026-16070 |
WPScan | |
| 2.7 Low | TaxoPress | Information Disclosure Contributor+ Private Post Disclosure via IDOR |
< 3.51.0 Fixed in 3.51.0 |
CVE-2026-15231 |
WPScan | |
| 2.2 Low | Event Tickets | Broken Access Control Contributor+ Seating Layout and Ticket Inventory Modification via IDOR |
< 5.29.0.1 Fixed in 5.29.0.1 |
CVE-2026-14823 |
WPScan | |
| 3.8 Low | Fluent Support | Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-14197 |
WPScan | |
| 2.7 Low | User Profile Picture | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 2.6.3 Fixed in 2.6.4 |
CVE-2026-61971 |
Patchstack | |
| 2.7 Low | Fluent Forms | Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR |
< 6.2.5 Fixed in 6.2.5 |
CVE-2026-11578 |
WPScan | |
| 3.1 Low | Fluent Forms | Broken Access Control Subscriber+ Subscription Cancellation via IDOR |
< 6.2.1 Fixed in 6.2.1 |
CVE-2026-11880 |
WPScan | |
| 2.7 Low | Image Photo Gallery Final Tiles Grid | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 3.6.11 Fixed in 3.6.12 |
CVE-2026-39510 |
Patchstack | |
| 3.8 Low | Tutor LMS | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 3.9.4 Fixed in 3.9.5 |
CVE-2025-47555 |
Patchstack | |
| 2.7 Low | Timetable and Event Schedule by MotoPress | Information Disclosure Contributor+ Event Disclosure via IDOR |
< 2.4.16 Fixed in 2.4.16 |
CVE-2025-12954 |
WPScan | |
| 3.8 Low | Content Mask | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 1.8.5.3 |
CVE-2025-58012 |
Patchstack | |
| 3.5 Low | BuddyBoss platform | Broken Access Control Private Comment Exposure via IDOR |
< 2.7.60 Fixed in 2.7.60 |
CVE-2024-12767 |
WPScan | |
| 3.8 Low | Filebird | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 6.4.2.1 Fixed in 6.4.6 |
CVE-2025-26977 |
Patchstack | |
| 2.7 Low | Molongui | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 4.7.7 Fixed in 4.7.8 |
CVE-2024-30507 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.