WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 2,543 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Tourfic Pro Plugin tourfic-pro Privilege Escalation ≤ 1.17.3 CVE-2026-39774 Patchstack
7.1 High ARForms Plugin arforms Cross-Site Scripting No login needed ≤ 7.1.2 CVE-2026-39766 Patchstack
7.2 High Instapage Plugin instapage Server-Side Request Forgery No login needed ≤ 3.7.2 CVE-2026-39728 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-39719 Patchstack
7.1 High PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104407 Patchstack
4.3 Medium Memberful - Membership Plugin memberful-wp Information Disclosure Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure ≤ 1.81.2 Fixed in 1.82.0 CVE-2026-104401 Patchstack
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
8.0 High Memberful - Membership Plugin memberful-wp Cross-Site Request Forgery Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) ≤ 1.81.0 Fixed in 1.81.1 CVE-2026-103067 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
8.8 High Featured Image from URL (FIFU) Free & Premium Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed 6.0.0 – < 6.0.8, 6.8.0 – < 8.2.8 Fixed in 6.0.8 CVE-2026-101147 WPScan
5.4 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.21.0 Fixed in 1.21.1 CVE-2026-102399 Patchstack
5.4 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.2.0 CVE-2026-97299 Patchstack
8.8 High Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification Plugin wc-blacklist-manager Cross-Site Request Forgery WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-96838 Patchstack
5.8 Medium Broken Link Notifier Plugin broken-link-notifier Server-Side Request Forgery Unauthenticated SSRF via Redirect Bypass No login needed 1.3.1 – < 2.0.0.1 Fixed in 2.0.0.1 CVE-2026-97316 WPScan
7.1 High WP Mobile Menu Plugin mobile-menu Cross-Site Scripting Stored XSS via CSRF No login needed 2.7.4 – < 2.9 Fixed in 2.9 CVE-2026-91832 WPScan
4.1 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Server-Side Request Forgery Contributor+ SSRF via Campaign Preview < 2.8.27 Fixed in 2.8.27 CVE-2026-89003 WPScan
4.1 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Server-Side Request Forgery Contributor+ SSRF via Campaign Run < 2.8.27 Fixed in 2.8.27 CVE-2026-89000 WPScan
5.8 Medium Testimonials Widget Plugin Server-Side Request Forgery Unauthenticated SSRF via Featured Image URL No login needed ≤ 4.0.4 CVE-2026-96533 WPScan
8.8 High MCP Server Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed < 1.8.2 Fixed in 1.8.2 CVE-2026-96524 WPScan
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
4.0 Medium Link Library Plugin link-library Server-Side Request Forgery Unauthenticated SSRF via Reciprocal Link Validation No login needed 7.8.8 – < 7.9.6 Fixed in 7.9.6 CVE-2026-78397 WPScan
8.1 High PublishPress Capabilities Plugin capability-manager-enhanced Cross-Site Request Forgery No login needed ≤ 2.50.1 Fixed in 2.51.0 CVE-2026-94487 Patchstack
3.7 Low NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Information Disclosure Unauthenticated Order Data Disclosure via Quote Request Page No login needed 2.0 – < 2.4.16 Fixed in 2.4.16 CVE-2026-93528 WPScan
5.0 Medium Directorist Plugin directorist-wpml-integration Server-Side Request Forgery Subscriber+ SSRF via Avatar URL < 8.9.5 Fixed in 8.9.5 CVE-2026-84046 WPScan
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery Arbitrary Sign-up Deletion via CSRF No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-92410 WPScan
4.1 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Server-Side Request Forgery Admin+ SSRF via bp_avatar < 2.4.5 Fixed in 2.4.5 CVE-2026-16542 WPScan
8.8 High Xagio SEO Plugin xagio-seo Cross-Site Request Forgery No login needed ≤ 7.1.0.43 Fixed in 7.1.0.44 CVE-2026-78295 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-74005 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
7.1 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Request Forgery No login needed ≤ 1.4.0.5 Fixed in 1.4.0.6 CVE-2026-66571 Patchstack
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Cross-Site Request Forgery Subscription Cancellation via CSRF No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87860 WPScan
6.5 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85131 WPScan
4.1 Medium WP Import Export Lite Plugin wp-import-export-lite Server-Side Request Forgery Admin+ SSRF via Import URL Handling < 3.9.33 Fixed in 3.9.33 CVE-2026-76559 WPScan
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
4.3 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84024 WPScan
6.5 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84023 WPScan
7.1 High Export & Import WPBakery Page Builder Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.2 CVE-2026-81429 WPScan
7.2 High Gpx2Graphics Plugin Arbitrary File Upload Arbitrary File Upload via CSRF ≤ 0.3 CVE-2026-81090 WPScan
4.3 Medium Site Kit by Google Plugin google-site-kit Cross-Site Request Forgery No login needed ≤ 1.186.0 Fixed in 1.187.0 CVE-2026-62139 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
7.2 High Hide My WP Ghost Plugin hide-my-wp Server-Side Request Forgery No login needed ≤ 7.0.09 Fixed in 7.0.10 CVE-2026-81806 Patchstack
4.1 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Server-Side Request Forgery Contributor+ SSRF via get-csv-to-json REST Endpoint < 13.2.0 Fixed in 13.2.0 CVE-2026-83543 WPScan
9.8 Critical Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN Plugin hummingbird-performance Remote Code Execution Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log No login needed ≤ 3.21.0 CVE-2026-83627 Wordfence
5.4 Medium SEOPress Plugin wp-seopress Server-Side Request Forgery ≤ 10.1 Fixed in 10.2 CVE-2026-85305 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery No login needed ≤ 7.9 Fixed in 7.9.1 CVE-2026-84761 Patchstack
5.4 Medium Simple Membership MailChimp Integration Plugin simple-membership-mailchimp-integration Cross-Site Request Forgery API Key Update via CSRF No login needed < 1.9.8 Fixed in 1.9.8 CVE-2026-8151 WPScan
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
8.8 High Mang Board WP Plugin mangboard Cross-Site Request Forgery No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2026-84770 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only