WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 245 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Payflex Payment Gateway Plugin payflex-payment-gateway Cross-Site Scripting No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2026-103346 Patchstack
5.3 Medium Deema Payment Gateway Plugin Authentication Bypass Unauthenticated Payment Confirmation Forgery via Unverified Success Return No login needed ≤ 1.1.2 CVE-2026-94271 WPScan
5.3 Medium Deema Payment Gateway Plugin Price Manipulation Unauthenticated Payment Bypass and Order Manipulation via Webhook No login needed ≤ 1.1.2 CVE-2026-94270 WPScan
7.5 High Morning for WooCommerce Plugin wc-gateway-greeninvoice Broken Access Control No login needed ≤ 2.4.1 CVE-2026-39723 Patchstack
5.3 Medium UPI QR Code Payment Gateway Plugin upi-qr-code-payment-for-woocommerce Broken Access Control Unauthenticated Cross-Order Payment-Status Forgery No login needed ≤ 1.4.3 CVE-2026-84169 WPScan
4.3 Medium WP User Frontend Plugin Broken Access Control Subscriber+ Post Creation via Subscription-Gated Form < 4.3.12 Fixed in 4.3.12 CVE-2026-79618 WPScan
5.3 Medium Paytm Payment Gateway Plugin paytm-payments Authentication Bypass Unauthenticated Order Status Manipulation via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81740 WPScan
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
7.5 High Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Payment Gateway Credentials Disclosure via Debug Log No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96255 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments SQL Injection Unauthenticated SQLi via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81809 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments Cross-Site Scripting Unauthenticated Stored XSS via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81739 WPScan
6.5 Medium Conekta Payment Gateway Plugin conekta-payment-gateway Broken Access Control No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2026-95527 Patchstack
6.5 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Broken Access Control No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-93620 Patchstack
5.3 Medium SUMIT Payment Gateway for WooCommerce Plugin woo-payment-gateway-officeguy Authentication Bypass Unauthenticated Payment Confirmation Forgery via bit IPN No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-84091 WPScan
4.7 Medium Paymob for WooCommerce Plugin paymob-for-woocommerce Broken Access Control Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions < 4.1.14 Fixed in 4.1.14 CVE-2026-87981 WPScan
8.6 High JetFormBuilder Stripe Gateway Plugin SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed < 1.1.0 Fixed in 1.1.0 CVE-2022-4997 WPScan
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-92400 WPScan
4.9 Medium GoPay for WooCommerce Plugin gopay-gateway SQL Injection Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter ≤ 1.0.36 CVE-2026-75959 Wordfence
5.3 Medium Payment Gateway of Stripe for WooCommerce Plugin payment-gateway-stripe-and-woocommerce-integration Other Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint No login needed ≤ 5.0.8 CVE-2026-9832 Wordfence
3.7 Low Robokassa payment gateway for Woocommerce Plugin robokassa Price Manipulation Unauthenticated Payment Bypass via Forged JWT Callback No login needed < 1.8.9 Fixed in 1.8.9 CVE-2026-91017 WPScan
4.9 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Payment Gateway Credential Disclosure 5.3.6 – < 5.6.0 Fixed in 5.6.0 CVE-2026-91019 WPScan
10.0 Critical CryptoPayment Gateway Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router No login needed 1.2.1 – 1.2.2 CVE-2026-81648 WPScan
8.8 High Gato GraphQL Plugin gatographql Privilege Escalation ≤ 19.2.3 Fixed in 19.2.4 CVE-2026-62102 Patchstack
5.9 Medium WC PayPay Gateway Plugin Price Manipulation Unauthenticated Payment Bypass via Unverified Webhook No login needed 0.5 – 0.9.3 CVE-2026-82215 WPScan
6.5 Medium Robokassa payment gateway for Woocommerce Plugin robokassa Broken Access Control No login needed ≤ 1.8.9 CVE-2026-78536 Patchstack
5.3 Medium ePayco Payment Gateway for WooCommerce Plugin Other Unauthenticated Payment Confirmation Bypass No login needed < 8.4.7 Fixed in 8.4.7 CVE-2026-84043 WPScan
5.3 Medium WP User Frontend Plugin Broken Access Control Unauthenticated Post Creation via Subscription-Gated Form No login needed < 4.3.11 Fixed in 4.3.11 CVE-2026-17563 WPScan
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form No login needed ≤ 5.106.0 CVE-2026-6176 Wordfence
9.3 Critical Epayco Plugin epayco-gateway SQL Injection No login needed ≤ 8.4.6 Fixed in 8.4.7 CVE-2026-78260 Patchstack
5.3 Medium Conekta Payment Gateway Plugin conekta-payment-gateway Broken Access Control Unauthenticated Order Payment Completion via Webhook Forgery No login needed < 6.2.2 Fixed in 6.2.2 CVE-2026-16738 WPScan
9.8 Critical TabaPay Gateway Plugin Privilege Escalation Unauthenticated Account Takeover via Payment Callback No login needed ≤ 1.4.0 CVE-2026-18031 WPScan
6.5 Medium Flutterwave WooCommerce Plugin rave-woocommerce-payment-gateway Authentication Bypass Broken Authentication No login needed ≤ 3.3.0 CVE-2026-73399 Patchstack
6.5 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Authentication Bypass Broken Authentication No login needed 3.2.0 CVE-2026-73398 Patchstack
7.5 High Duitku Payment Gateway Plugin duitku-social-payment-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.11.14 CVE-2026-32468 Patchstack
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints ≤ 3.5.2 CVE-2026-13167 Wordfence
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control No login needed < 4.22.10 Fixed in 4.22.10 CVE-2026-73353 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
7.5 High Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin clink-gateway-for-woocommerce Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-66431 Patchstack
6.5 Medium Secure Card Gateway for ePay Paycenter (Piraeus Bank) Plugin secure-card-gateway-for-epay-paycenter-piraeus-bank Broken Access Control No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2026-61978 Patchstack
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-16621 WPScan
5.5 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion < 5.2.6 Fixed in 5.2.6 CVE-2026-18934 WPScan
9.1 Critical MStore API Plugin mstore-api Price Manipulation Unauthenticated Payment Bypass via Multiple Payment Gateways No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16038 WPScan
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed < 7.0.2 Fixed in 7.0.2 CVE-2026-12584 WPScan
6.5 Medium WC Buckaroo BPE Gateway Plugin Broken Access Control Subscriber+ Unauthorized Order Refund < 4.9.0 Fixed in 4.9.0 CVE-2026-13329 WPScan
5.3 Medium GiveWP Plugin give Broken Access Control Unauthenticated Payment Gateway Restriction Bypass No login needed < 4.16.3 Fixed in 4.16.3 CVE-2026-14317 WPScan
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Unauthenticated Event Aggregator Import Status Manipulation No login needed < 6.16.5.1 Fixed in 6.16.5.1 CVE-2026-13390 WPScan
7.5 High Clover Payment Gateway by Zaytech for WooCommerce Plugin woo-clover-gateway-by-zaytech Price Manipulation Unauthenticated Payment Bypass via check_order No login needed < 1.3.6 Fixed in 1.3.6 CVE-2026-12493 WPScan
4.3 Medium Zarinpal Gateway Plugin zarinpal-woocommerce-payment-gateway Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65460 Patchstack
7.5 High Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Broken Access Control No login needed ≤ 9.1.4 Fixed in 9.1.5 CVE-2026-59547 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only