WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Deema Payment Gateway Plugin Authentication Bypass Unauthenticated Payment Confirmation Forgery via Unverified Success Return No login needed ≤ 1.1.2 CVE-2026-94271 WPScan
5.3 Medium UPI QR Code Payment Gateway Plugin upi-qr-code-payment-for-woocommerce Broken Access Control Unauthenticated Cross-Order Payment-Status Forgery No login needed ≤ 1.4.3 CVE-2026-84169 WPScan
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
5.3 Medium Payments for Hubtel Plugin payments-hubtel Broken Access Control Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96200 WPScan
5.4 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.21.0 Fixed in 1.21.1 CVE-2026-102399 Patchstack
5.4 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.2.0 CVE-2026-97299 Patchstack
5.3 Medium InPost for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Forgery via Shipment Webhook No login needed 1.7.5 – < 1.9.8 Fixed in 1.9.8 CVE-2026-93580 WPScan
5.5 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter ≤ 1.4.0.5 CVE-2026-12037 Wordfence
5.4 Medium Kirki – Freeform Page Builder, Website Builder & Customizer Plugin kirki Server-Side Request Forgery Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter No login needed ≤ 6.2.0 CVE-2026-18335 Wordfence
5.3 Medium SUMIT Payment Gateway for WooCommerce Plugin woo-payment-gateway-officeguy Authentication Bypass Unauthenticated Payment Confirmation Forgery via bit IPN No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-84091 WPScan
4.3 Medium Directorist Plugin directorist-wpml-integration Broken Access Control Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint 8.9.1 – < 8.9.5 Fixed in 8.9.5 CVE-2026-84027 WPScan
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Action / Forged comment_author_email Cookie ≤ 3.1.5 CVE-2026-91092 Wordfence
6.5 Medium Wow Elements Addons for Elementor Plugin wow-elements-addons-for-elementor Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting No login needed ≤ 1.11.2 CVE-2026-1641 Wordfence
6.4 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> Tags ≤ 3.3.2 CVE-2026-12106 Wordfence
5.8 Medium Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Array-Valued Form Field No login needed < 4.2.2 Fixed in 4.2.2 CVE-2026-90984 WPScan
4.8 Medium Easy Appointments Plugin easy-appointments Broken Access Control Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token No login needed < 4.0.2.2 Fixed in 4.0.2.2 CVE-2026-87965 WPScan
5.4 Medium PublishPress Series Plugin organize-series Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-74005 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
4.3 Medium Site Kit by Google Plugin google-site-kit Cross-Site Request Forgery No login needed ≤ 1.186.0 Fixed in 1.187.0 CVE-2026-62139 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
5.0 Medium Divi Theme Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter ≤ 4.27.6 CVE-2026-4361 Wordfence
5.3 Medium Restaurant Menu and Food Ordering Plugin mp-restaurant-menu Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed < 2.4.12 Fixed in 2.4.12 CVE-2026-84044 WPScan
5.4 Medium SEOPress Plugin wp-seopress Server-Side Request Forgery ≤ 10.1 Fixed in 10.2 CVE-2026-85305 Patchstack
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
5.3 Medium Everest Forms Plugin everest-forms Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' No login needed ≤ 3.4.4 CVE-2026-5096 Wordfence
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack
6.4 Medium Shared Files Plugin shared-files Server-Side Request Forgery ≤ 1.7.69 Fixed in 1.7.70 CVE-2026-78269 Patchstack
5.3 Medium Conekta Payment Gateway Plugin conekta-payment-gateway Broken Access Control Unauthenticated Order Payment Completion via Webhook Forgery No login needed < 6.2.2 Fixed in 6.2.2 CVE-2026-16738 WPScan
6.0 Medium [Aotuman] Grab WeChat Articles Plugin apoyl-grabweixin Server-Side Request Forgery ≤ 2.0.1 CVE-2026-32467 Patchstack
5.9 Medium WooMS Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure No login needed ≤ 9.14 CVE-2026-13700 WPScan
6.5 Medium WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Deletion No login needed ≤ 7.10.09 CVE-2026-17608 Wordfence
5.9 Medium Epeken All Kurir Plugin epeken-all-kurir Authentication Bypass Unauthenticated Order Payment Confirmation Forgery No login needed ≤ 2.1.4 CVE-2026-16739 WPScan
4.3 Medium Astro Booking Engine Plugin astro-booking-engine Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 1.4.0 CVE-2025-10308 Wordfence
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
5.3 Medium Welcart e-Commerce Plugin usc-e-shop Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed < 2.11.33 Fixed in 2.11.33 CVE-2026-15213 WPScan
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
5.3 Medium Podcast Player Plugin podcast-player Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 8.3.1 Fixed in 8.3.1 CVE-2026-14860 WPScan
4.8 Medium AI Engine Plugin ai-engine Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed < 3.6.4 Fixed in 3.6.4 CVE-2026-16953 WPScan
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
6.8 Medium Visualizer: Tables and Charts Manager Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via JSON Import < 4.0.6 Fixed in 4.0.6 CVE-2026-14939 WPScan
6.5 Medium The GDPR Framework Plugin gdpr-framework Broken Access Control Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-14816 WPScan
4.3 Medium Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross-Site Request Forgery to CSS Modification No login needed ≤ 3.1 CVE-2025-14469 Wordfence
6.5 Medium Pixel Tag Manager for WooCommerce Plugin pixel-manager-for-woocommerce Broken Access Control Unauthenticated Forged Conversion Event Submission No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14315 WPScan
4.3 Medium FuseWP Plugin fusewp Cross-Site Request Forgery Cross-Site Request Forgery to Sync Rule Status Toggle No login needed ≤ 1.1.24.2 CVE-2026-5582 Wordfence
5.3 Medium WP Travel Plugin wp-travel Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed < 11.8.1 Fixed in 11.8.1 CVE-2026-13143 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only