WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–39 of 39 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.8 Low Bookly Plugin Information Disclosure Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR < 28.3 Fixed in 28.3 CVE-2026-86839 WPScan
2.7 Low Events Manager Plugin events-manager Broken Access Control Contributor+ Arbitrary Ticket Overwrite via IDOR < 7.4.5 Fixed in 7.4.5 CVE-2026-93661 WPScan
2.7 Low WPeMatico RSS Feed Fetcher Plugin wpematico Information Disclosure Contributor+ Campaign Configuration and Log Disclosure via IDOR < 2.8.26 Fixed in 2.8.26 CVE-2026-89004 WPScan
2.7 Low NextGEN Gallery Plugin Information Disclosure Contributor+ Image Metadata Disclosure via IDOR 3.59.5 – < 4.5.0 Fixed in 4.5.0 CVE-2026-81652 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81651 WPScan
3.8 Low Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-92420 WPScan
2.7 Low MasterStudy LMS 3.6.2 Plugin Information Disclosure < 3.7.50 - Instructor+ Student PII Disclosure via IDOR 3.6.2 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88844 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Order Status Manipulation via IDOR < 3.7.50 Fixed in 3.7.50 CVE-2026-81340 WPScan
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
2.7 Low Masteriyo LMS Plugin learning-management-system Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR 1.14.0 – < 3.4.1 Fixed in 3.4.1 CVE-2026-82851 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13146 WPScan
2.2 Low Kirki Plugin kirki Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84225 WPScan
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
3.8 Low Timetics Plugin timetics Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR ≤ 1.0.61 CVE-2026-14326 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81198 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Quiz Answer Disclosure via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81196 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR < 3.7.42 Fixed in 3.7.42 CVE-2026-81200 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-79615 WPScan
2.7 Low Tutor LMS Plugin tutor Information Disclosure Instructor+ Cross-Instructor Private Course Disclosure via IDOR < 4.0.6 Fixed in 4.0.6 CVE-2026-14187 WPScan
2.7 Low Dokan Plugin Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount < 5.0.14 Fixed in 5.0.14 CVE-2026-16577 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
3.7 Low Amelia Plugin Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed < 2.4.6 Fixed in 2.4.6 CVE-2026-14213 WPScan
3.8 Low Amelia Pro Plugin Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR 9.0 – < 9.7 Fixed in 9.7 CVE-2026-14211 WPScan
2.7 Low MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16746 WPScan
2.7 Low Brizy - Page Builder Plugin Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR < 2.8.19 Fixed in 2.8.19 CVE-2026-16070 WPScan
2.7 Low TaxoPress Plugin Information Disclosure Contributor+ Private Post Disclosure via IDOR < 3.51.0 Fixed in 3.51.0 CVE-2026-15231 WPScan
2.2 Low Event Tickets Plugin Broken Access Control Contributor+ Seating Layout and Ticket Inventory Modification via IDOR < 5.29.0.1 Fixed in 5.29.0.1 CVE-2026-14823 WPScan
3.8 Low Fluent Support Plugin fluent-support Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR < 2.3.1 Fixed in 2.3.1 CVE-2026-14197 WPScan
2.7 Low User Profile Picture Plugin metronet-profile-picture Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.6.3 Fixed in 2.6.4 CVE-2026-61971 Patchstack
2.7 Low Fluent Forms Plugin fluentform Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR < 6.2.5 Fixed in 6.2.5 CVE-2026-11578 WPScan
3.1 Low Fluent Forms Plugin fluentform Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 6.2.1 Fixed in 6.2.1 CVE-2026-11880 WPScan
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
2.7 Low Timetable and Event Schedule by MotoPress Plugin mp-timetable Information Disclosure Contributor+ Event Disclosure via IDOR < 2.4.16 Fixed in 2.4.16 CVE-2025-12954 WPScan
3.8 Low Content Mask Plugin content-mask Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8.5.3 CVE-2025-58012 Patchstack
3.5 Low BuddyBoss platform Plugin Broken Access Control Private Comment Exposure via IDOR < 2.7.60 Fixed in 2.7.60 CVE-2024-12767 WPScan
3.8 Low Filebird Plugin filebird Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.2.1 Fixed in 6.4.6 CVE-2025-26977 Patchstack
2.7 Low Molongui Plugin molongui-authorship Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.7 Fixed in 4.7.8 CVE-2024-30507 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only