WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 131 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Popup Maker WP Plugin Broken Access Control Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization 1.2.2.1 – 1.4.5 CVE-2026-85005 WPScan
5.4 Medium Advanced Woo Labels – Product Labels & Badges for WooCommerce Plugin advanced-woo-labels Cross-Site Scripting Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.51 CVE-2026-12241 Wordfence
7.1 High Branda Plugin branda-white-labeling Cross-Site Scripting No login needed ≤ 3.4.32 Fixed in 3.4.33 CVE-2026-102376 Patchstack
5.4 Medium AllAble Connector Plugin allable-connector Broken Access Control ≤ 0.13.4 Fixed in 0.13.6 CVE-2026-97243 Patchstack
7.2 High Frontend Post Submission Manager Lite Plugin frontend-post-submission-manager-lite Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) No login needed ≤ 1.3.4 CVE-2026-96649 Wordfence
4.3 Medium Search Atlas SEO Plugin metasync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function ≤ 2.6.23 CVE-2026-15946 Wordfence
8.8 High Master Blocks Plugin ultimate-blocks-for-gutenberg Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed 1.4.1 – < 1.5.0 Fixed in 1.5.0 CVE-2026-88824 WPScan
5.3 Medium Bookit Plugin bookit-for-cal-com Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed < 2.6.0.1 Fixed in 2.6.0.1 CVE-2026-88995 WPScan
9.8 Critical The Events Calendar Plugin the-events-calendar Remote Code Execution Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation No login needed ≤ 6.17.3 CVE-2026-78159 Wordfence
7.2 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed ≤ 6.86 CVE-2026-77830 Wordfence
2.2 Low Kirki Plugin kirki Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84225 WPScan
6.8 Medium BEAF Plugin Cross-Site Scripting Author+ Stored XSS via Before Label < 4.7.19 Fixed in 4.7.19 CVE-2025-15664 WPScan
6.8 Medium BEAF Plugin Cross-Site Scripting Author+ Stored XSS via After Label < 4.7.19 Fixed in 4.7.19 CVE-2025-15663 WPScan
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
6.5 Medium WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter ≤ 4.9.8 CVE-2026-18027 Wordfence
8.1 High Atarim Plugin atarim-visual-collaboration Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta ≤ 5.1.1 CVE-2026-19942 Wordfence
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed < 7.9.4 Fixed in 7.9.4 CVE-2026-16535 WPScan
3.7 Low DHL for WooCommerce Plugin Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16993 WPScan
5.3 Medium DHL for WooCommerce Plugin Broken Access Control Unauthenticated Shipping Label Download via IDOR No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16981 WPScan
6.4 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter ≤ 2.48 CVE-2026-15662 Wordfence
4.8 Medium Bit Form Plugin bit-form Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label < 3.1.4 Fixed in 3.1.4 CVE-2025-15669 WPScan
4.3 Medium Avada Custom Branding Plugin fusion-white-label-branding Broken Access Control ≤ 1.2 CVE-2026-65524 Patchstack
4.4 Medium White Label CMS Plugin white-label-cms Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings ≤ 2.7.12 CVE-2026-11898 Wordfence
4.3 Medium DHL eCommerce (Benelux) for WooCommerce Plugin dhlpwc Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions ≤ 2.2.3 CVE-2026-9235 Wordfence
7.1 High SpaLab | Beauty Salon Theme spalab Cross-Site Scripting No login needed ≤ 6.7 CVE-2025-69154 Patchstack
9.8 Critical Branda – White Label & Branding, Free Login Page Customizer Plugin branda-white-labeling Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.4.29 CVE-2026-11551 Wordfence
6.4 Medium Appointment Booking Calendar Plugin creavi-booking-service Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label ≤ 1.4.4 CVE-2026-1856 Wordfence
8.1 High Atomlab Theme atomlab Local File Inclusion No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2026-39590 Patchstack
9.8 Critical AI Lab Theme ailab PHP Object Injection No login needed < 5.4.2 Fixed in 5.4.2 CVE-2026-42380 Patchstack
8.1 High Softlab Core Plugin softlab-core Local File Inclusion No login needed < 1.2.11 Fixed in 1.2.11 CVE-2026-34895 Patchstack
7.5 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2026-49056 Patchstack
4.3 Medium Multicollab: Content Team Collaboration and Editorial Workflow Plugin commenting-feature Broken Access Control Missing Authorization to Authenticated (Subscriber+) Collaboration Comment ≤ 5.2 CVE-2025-4202 Wordfence
4.4 Medium Call for Price for WooCommerce Plugin woocommerce-call-for-price Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Call for Price' Label Settings ≤ 4.2.0 CVE-2026-6447 Wordfence
4.4 Medium VideoZen Plugin videozen Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field ≤ 1.0.1 CVE-2026-6439 Wordfence
6.4 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting ≤ 5.1.3 CVE-2026-4300 Wordfence
7.5 High LabtechCO Theme labtechco Local File Inclusion ≤ 8.3 Fixed in 8.4 CVE-2026-39544 Patchstack
7.3 High Automated FedEx live/manual rates with shipping labels Plugin a2z-fedex-shipping Broken Access Control No login needed ≤ 5.1.9 CVE-2026-25456 Patchstack
4.4 Medium CM Custom Reports Plugin cm-custom-reports Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels ≤ 1.2.7 CVE-2026-2432 Wordfence
4.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-32447 Patchstack
7.2 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution ≤ 2.36 Fixed in 2.37 CVE-2026-32414 Patchstack
6.4 Medium Dear Flipbook Plugin Cross-Site Scripting Authenticated (Auhtor+) Stored Cross-Site Scripting via PDF Page Labels ≤ 2.4.20 CVE-2026-2569 Wordfence
8.8 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter ≤ 2.36 CVE-2026-1929 Wordfence
8.1 High Blabber Theme blabber Local File Inclusion No login needed ≤ 1.7.0 CVE-2026-22378 Patchstack
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-67993 Patchstack
4.4 Medium Private Comment Plugin private-comment Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting ≤ 0.0.4 CVE-2026-2281 Wordfence
6.4 Medium Orbisius Random Name Generator Plugin orbisius-random-name-generator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_label' Shortcode Attribute ≤ 1.0.2 CVE-2026-1893 Wordfence
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-25019 Patchstack
9.8 Critical Branda – White Label & Branding, Free Login Page Customizer Plugin branda-white-labeling Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.4.24 CVE-2025-14998 Wordfence
4.4 Medium Custom Post Type UI Plugin custom-post-type-ui Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter ≤ 1.18.1 CVE-2025-14056 Wordfence
9.8 Critical LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Plugin lazytasks-project-task-management Broken Access Control Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation No login needed ≤ 1.2.29 CVE-2025-12963 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only