WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 1–50 of 131 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Popup Maker WP | Broken Access Control Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization |
1.2.2.1 – 1.4.5 |
CVE-2026-85005 |
WPScan | |
| 5.4 Medium | Advanced Woo Labels – Product Labels & Badges for WooCommerce | Cross-Site Scripting Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.51 |
CVE-2026-12241 |
Wordfence | |
| 7.1 High | Branda | Cross-Site Scripting No login needed |
≤ 3.4.32 Fixed in 3.4.33 |
CVE-2026-102376 |
Patchstack | |
| 5.4 Medium | AllAble Connector | Broken Access Control |
≤ 0.13.4 Fixed in 0.13.6 |
CVE-2026-97243 |
Patchstack | |
| 7.2 High | Frontend Post Submission Manager Lite | Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) No login needed |
≤ 1.3.4 |
CVE-2026-96649 |
Wordfence | |
| 4.3 Medium | Search Atlas SEO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function |
≤ 2.6.23 |
CVE-2026-15946 |
Wordfence | |
| 8.8 High | Master Blocks | Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed |
1.4.1 – < 1.5.0 Fixed in 1.5.0 |
CVE-2026-88824 |
WPScan | |
| 5.3 Medium | Bookit | Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed |
< 2.6.0.1 Fixed in 2.6.0.1 |
CVE-2026-88995 |
WPScan | |
| 9.8 Critical | The Events Calendar | Remote Code Execution Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation No login needed |
≤ 6.17.3 |
CVE-2026-78159 |
Wordfence | |
| 7.2 High | Spam protection, Honeypot, Anti-Spam by CleanTalk | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed |
≤ 6.86 |
CVE-2026-77830 |
Wordfence | |
| 2.2 Low | Kirki | Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR |
6.0.0 – < 6.3.0 Fixed in 6.3.0 |
CVE-2026-84225 |
WPScan | |
| 6.8 Medium | BEAF | Cross-Site Scripting Author+ Stored XSS via Before Label |
< 4.7.19 Fixed in 4.7.19 |
CVE-2025-15664 |
WPScan | |
| 6.8 Medium | BEAF | Cross-Site Scripting Author+ Stored XSS via After Label |
< 4.7.19 Fixed in 4.7.19 |
CVE-2025-15663 |
WPScan | |
| 6.5 Medium | Print Barcode Labels for your WooCommerce products/orders | Information Disclosure Sensitive Data Exposure |
≤ 4.0.0 Fixed in 4.0.1 |
CVE-2026-81280 |
Patchstack | |
| 6.5 Medium | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter |
≤ 4.9.8 |
CVE-2026-18027 |
Wordfence | |
| 8.1 High | Atarim | Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta |
≤ 5.1.1 |
CVE-2026-19942 |
Wordfence | |
| 6.1 Medium | Link Library | Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-16535 |
WPScan | |
| 3.7 Low | DHL for WooCommerce | Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed |
< 4.0.1 Fixed in 4.0.1 |
CVE-2026-16993 |
WPScan | |
| 5.3 Medium | DHL for WooCommerce | Broken Access Control Unauthenticated Shipping Label Download via IDOR No login needed |
< 4.0.1 Fixed in 4.0.1 |
CVE-2026-16981 |
WPScan | |
| 6.4 Medium | Advanced Woo Labels | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter |
≤ 2.48 |
CVE-2026-15662 |
Wordfence | |
| 4.8 Medium | Bit Form | Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label |
< 3.1.4 Fixed in 3.1.4 |
CVE-2025-15669 |
WPScan | |
| 4.3 Medium | Avada Custom Branding | Broken Access Control |
≤ 1.2 |
CVE-2026-65524 |
Patchstack | |
| 4.4 Medium | White Label CMS | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings |
≤ 2.7.12 |
CVE-2026-11898 |
Wordfence | |
| 4.3 Medium | DHL eCommerce (Benelux) for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions |
≤ 2.2.3 |
CVE-2026-9235 |
Wordfence | |
| 7.1 High | SpaLab | Beauty Salon | Cross-Site Scripting No login needed |
≤ 6.7 |
CVE-2025-69154 |
Patchstack | |
| 9.8 Critical | Branda – White Label & Branding, Free Login Page Customizer | Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover No login needed |
≤ 3.4.29 |
CVE-2026-11551 |
Wordfence | |
| 6.4 Medium | Appointment Booking Calendar | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label |
≤ 1.4.4 |
CVE-2026-1856 |
Wordfence | |
| 8.1 High | Atomlab | Local File Inclusion No login needed |
≤ 2.4.5 Fixed in 2.4.6 |
CVE-2026-39590 |
Patchstack | |
| 9.8 Critical | AI Lab | PHP Object Injection No login needed |
< 5.4.2 Fixed in 5.4.2 |
CVE-2026-42380 |
Patchstack | |
| 8.1 High | Softlab Core | Local File Inclusion No login needed |
< 1.2.11 Fixed in 1.2.11 |
CVE-2026-34895 |
Patchstack | |
| 7.5 High | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Information Disclosure Sensitive Data Exposure No login needed |
≤ 4.9.4 Fixed in 4.9.5 |
CVE-2026-49056 |
Patchstack | |
| 4.3 Medium | Multicollab: Content Team Collaboration and Editorial Workflow | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Collaboration Comment |
≤ 5.2 |
CVE-2025-4202 |
Wordfence | |
| 4.4 Medium | Call for Price for WooCommerce | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Call for Price' Label Settings |
≤ 4.2.0 |
CVE-2026-6447 |
Wordfence | |
| 4.4 Medium | VideoZen | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field |
≤ 1.0.1 |
CVE-2026-6439 |
Wordfence | |
| 6.4 Medium | Robo Gallery | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting |
≤ 5.1.3 |
CVE-2026-4300 |
Wordfence | |
| 7.5 High | LabtechCO | Local File Inclusion |
≤ 8.3 Fixed in 8.4 |
CVE-2026-39544 |
Patchstack | |
| 7.3 High | Automated FedEx live/manual rates with shipping labels | Broken Access Control No login needed |
≤ 5.1.9 |
CVE-2026-25456 |
Patchstack | |
| 4.4 Medium | CM Custom Reports | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels |
≤ 1.2.7 |
CVE-2026-2432 |
Wordfence | |
| 4.3 Medium | Atarim | Broken Access Control |
≤ 4.3.2 Fixed in 4.3.3 |
CVE-2026-32447 |
Patchstack | |
| 7.2 High | Advanced Woo Labels | Remote Code Execution |
≤ 2.36 Fixed in 2.37 |
CVE-2026-32414 |
Patchstack | |
| 6.4 Medium | Dear Flipbook | Cross-Site Scripting Authenticated (Auhtor+) Stored Cross-Site Scripting via PDF Page Labels |
≤ 2.4.20 |
CVE-2026-2569 |
Wordfence | |
| 8.8 High | Advanced Woo Labels | Remote Code Execution Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter |
≤ 2.36 |
CVE-2026-1929 |
Wordfence | |
| 8.1 High | Blabber | Local File Inclusion No login needed |
≤ 1.7.0 |
CVE-2026-22378 |
Patchstack | |
| 6.5 Medium | Atarim | Broken Access Control No login needed |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2025-67993 |
Patchstack | |
| 4.4 Medium | Private Comment | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting |
≤ 0.0.4 |
CVE-2026-2281 |
Wordfence | |
| 6.4 Medium | Orbisius Random Name Generator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_label' Shortcode Attribute |
≤ 1.0.2 |
CVE-2026-1893 |
Wordfence | |
| 5.3 Medium | Atarim | Broken Access Control No login needed |
≤ 4.3.1 Fixed in 4.3.2 |
CVE-2026-25019 |
Patchstack | |
| 9.8 Critical | Branda – White Label & Branding, Free Login Page Customizer | Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover No login needed |
≤ 3.4.24 |
CVE-2025-14998 |
Wordfence | |
| 4.4 Medium | Custom Post Type UI | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter |
≤ 1.18.1 |
CVE-2025-14056 |
Wordfence | |
| 9.8 Critical | LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart | Broken Access Control Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation No login needed |
≤ 1.2.29 |
CVE-2025-12963 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.