WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Tourfic Pro Plugin tourfic-pro Privilege Escalation ≤ 1.17.3 CVE-2026-39774 Patchstack
7.1 High ARForms Plugin arforms Cross-Site Scripting No login needed ≤ 7.1.2 CVE-2026-39766 Patchstack
7.2 High Instapage Plugin instapage Server-Side Request Forgery No login needed ≤ 3.7.2 CVE-2026-39728 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-39719 Patchstack
7.1 High PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104407 Patchstack
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
8.0 High Memberful - Membership Plugin memberful-wp Cross-Site Request Forgery Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) ≤ 1.81.0 Fixed in 1.81.1 CVE-2026-103067 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
8.8 High Featured Image from URL (FIFU) Free & Premium Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed 6.0.0 – < 6.0.8, 6.8.0 – < 8.2.8 Fixed in 6.0.8 CVE-2026-101147 WPScan
8.8 High Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification Plugin wc-blacklist-manager Cross-Site Request Forgery WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-96838 Patchstack
7.1 High WP Mobile Menu Plugin mobile-menu Cross-Site Scripting Stored XSS via CSRF No login needed 2.7.4 – < 2.9 Fixed in 2.9 CVE-2026-91832 WPScan
8.8 High MCP Server Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed < 1.8.2 Fixed in 1.8.2 CVE-2026-96524 WPScan
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
8.1 High PublishPress Capabilities Plugin capability-manager-enhanced Cross-Site Request Forgery No login needed ≤ 2.50.1 Fixed in 2.51.0 CVE-2026-94487 Patchstack
8.8 High Xagio SEO Plugin xagio-seo Cross-Site Request Forgery No login needed ≤ 7.1.0.43 Fixed in 7.1.0.44 CVE-2026-78295 Patchstack
7.1 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Request Forgery No login needed ≤ 1.4.0.5 Fixed in 1.4.0.6 CVE-2026-66571 Patchstack
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
7.1 High Export & Import WPBakery Page Builder Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.2 CVE-2026-81429 WPScan
7.2 High Gpx2Graphics Plugin Arbitrary File Upload Arbitrary File Upload via CSRF ≤ 0.3 CVE-2026-81090 WPScan
7.2 High Hide My WP Ghost Plugin hide-my-wp Server-Side Request Forgery No login needed ≤ 7.0.09 Fixed in 7.0.10 CVE-2026-81806 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery No login needed ≤ 7.9 Fixed in 7.9.1 CVE-2026-84761 Patchstack
8.8 High Mang Board WP Plugin mangboard Cross-Site Request Forgery No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2026-84770 Patchstack
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
8.1 High FluentBooking Pro Plugin fluent-booking-pro Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-81273 Patchstack
8.8 High GeoDirectory Plugin geodirectory Cross-Site Request Forgery No login needed ≤ 2.8.176 Fixed in 2.8.177 CVE-2026-81271 Patchstack
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
7.4 High Slider by 10Web Plugin slider-wd Cross-Site Request Forgery No login needed ≤ 1.2.63 CVE-2026-66635 Patchstack
7.2 High OttoKit Plugin suretriggers Server-Side Request Forgery No login needed ≤ 1.1.35 Fixed in 1.1.36 CVE-2026-32553 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-32473 Patchstack
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
7.5 High Estatik Plugin Cross-Site Request Forgery Login CSRF No login needed < 4.3.3 Fixed in 4.3.3 CVE-2026-16262 WPScan
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
7.1 High Tourmaster Plugin Cross-Site Scripting Stored XSS via CSRF No login needed < 5.4.8 Fixed in 5.4.8 CVE-2026-14239 WPScan
7.1 High WOLF - WordPress Posts Bulk Editor and Manager Plugin Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed < 1.1.0 Fixed in 1.1.0 CVE-2026-14234 WPScan
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.2 High Simple Link Directory Pro Plugin simple-link-directory-pro Server-Side Request Forgery No login needed ≤ 15.0.6 Fixed in 15.0.7 CVE-2026-61953 Patchstack
7.2 High 3D Flipbook PDF Viewer & Embedder Plugin pdf-embed-viewer Server-Side Request Forgery No login needed ≤ 1.4.2 Fixed in 1.4.4 CVE-2026-59552 Patchstack
7.1 High MailPoet Plugin mailpoet Cross-Site Request Forgery No login needed 5.30.0 – 5.33.0 Fixed in 5.33.1 CVE-2026-57626 Patchstack
7.1 High Popup for CF7 with Sweet Alert Plugin cf7-sweet-alert-popup Cross-Site Request Forgery No login needed ≤ 1.6.5 CVE-2026-65540 Patchstack
7.1 High Kwayy HTML Sitemap Plugin kwayy-html-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0 CVE-2026-65539 Patchstack
7.2 High PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Server-Side Request Forgery No login needed ≤ 2.2.6 CVE-2026-65516 Patchstack
7.1 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65488 Patchstack
8.8 High ApusListing Theme apuslisting Cross-Site Request Forgery No login needed ≤ 1.2.63 Fixed in 1.2.64 CVE-2026-57785 Patchstack
7.2 High ARforms Plugin arforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'password' Field Values No login needed ≤ 7.2.1 CVE-2026-12421 Wordfence
7.1 High ووسلام – همگام سازی ووکامرس و باسلام Plugin sync-basalam Cross-Site Request Forgery همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-61956 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Broken Authentication No login needed ≤ 1.7.08 CVE-2026-57786 Patchstack
7.2 High PDF Generator Plugin pdf-generator-for-wp Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-57407 Patchstack
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only