WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 1,456 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Magee Shortcodes Plugin Other Unauthenticated Mail Relay via Contact Form No login needed ≤ 2.1.1 CVE-2026-105322 WPScan
5.4 Medium MetForm Plugin metform Content Injection Unauthenticated HTML Injection in Notification Emails via Field Shortcodes No login needed < 4.3.1 Fixed in 4.3.1 CVE-2026-86833 WPScan
7.1 High Magee Shortcodes Plugin Cross-Site Scripting Reflected XSS via live_preview and magee_create_shortcode Actions No login needed ≤ 2.1.1 CVE-2026-105316 WPScan
5.3 Medium Name Directory Plugin name-directory Arbitrary Shortcode Execution No login needed ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104397 Patchstack
6.4 Medium Twenty20 Image Before-After Plugin twenty20 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute ≤ 2.0.5 CVE-2026-92767 Wordfence
9.1 Critical Beaver Builder Page Builder Plugin beaver-builder-lite-version Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output No login needed ≤ 2.11.0.5 CVE-2026-92084 Wordfence
6.5 Medium WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode) No login needed ≤ 2.4.3 CVE-2026-100157 Wordfence
5.4 Medium WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter ≤ 2.4.3 CVE-2026-103519 Wordfence
6.4 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.5.3 CVE-2026-15795 Wordfence
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101161 WPScan
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter No login needed ≤ 5.0.2 CVE-2026-100152 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields ≤ 4.17.4 CVE-2026-92536 Wordfence
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Search Query No login needed < 5.0.2.1 Fixed in 5.0.2.1 CVE-2026-19856 WPScan
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
6.5 Medium The Events Calendar Plugin the-events-calendar Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter No login needed 6.12.0 – < 6.17.5.1 Fixed in 6.17.5.1 CVE-2026-84740 WPScan
4.7 Medium If-So Dynamic Content Plugin if-so Cross-Site Scripting Reflected XSS via render_ifso_shortcodes No login needed 1.8 – < 1.10.2 Fixed in 1.10.2 CVE-2026-87970 WPScan
9.1 Critical Appointment Booking Plugin latepoint Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field No login needed ≤ 5.7.0 CVE-2026-92966 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute ≤ 5.7.2 CVE-2026-6171 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute ≤ 5.7.2 CVE-2026-6170 Wordfence
6.5 Medium WPForms Lite Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation No login needed 1.5.0.1 – < 2.0.2.1 Fixed in 2.0.2.1 CVE-2026-84744 WPScan
8.8 High Groups Plugin groups Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode ≤ 4.6.0 CVE-2026-77203 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter No login needed ≤ 6.5.2 CVE-2026-84280 Wordfence
6.4 Medium CSS & JavaScript Toolbox Plugin css-javascript-toolbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox Shortcode ≤ 12.0.6 CVE-2025-14814 Wordfence
5.6 Medium Ninja Tables Plugin ninja-tables Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source No login needed < 5.2.17 Fixed in 5.2.17 CVE-2026-86612 WPScan
4.8 Medium GTranslate Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Email Translation No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-86604 WPScan
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Comment Content No login needed < 10.8.2 Fixed in 10.8.2 CVE-2026-86601 WPScan
6.5 Medium Advanced Contact form 7 DB Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Information Disclosure via 'acf7db' Shortcode ≤ 2.1.1 CVE-2026-6831 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Information Disclosure Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview 10.3.0 – < 10.8.2 Fixed in 10.8.2 CVE-2026-86602 WPScan
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute ≤ 6.8.0 CVE-2026-9231 Wordfence
8.1 High WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter ≤ 2.4.2 CVE-2026-92235 Wordfence
8.1 High HUSKY Plugin woocommerce-products-filter Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed ≤ 1.4.4 CVE-2026-92969 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content ≤ 2.1.21 CVE-2026-16778 Wordfence
6.5 Medium GiveWP Plugin give Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Donor Name No login needed 4.13.2 – < 4.16.9 Fixed in 4.16.9 CVE-2026-85113 WPScan
6.5 Medium Meow Gallery Plugin meow-gallery Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route No login needed < 5.5.5 Fixed in 5.5.5 CVE-2026-92422 WPScan
6.8 Medium Master Slider Plugin master-slider Cross-Site Scripting Contributor+ Stored XSS via ms_slider Shortcode Attributes ≤ 3.11.2 CVE-2026-14844 WPScan
6.4 Medium Real 3D Flipbook Plugin real3d-flipbook-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute ≤ 5.1.1 CVE-2026-15098 Wordfence
8.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) ≤ 4.17.2 CVE-2026-85658 Wordfence
6.4 Medium WP Composer Plugin page-builder-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode ≤ 1.0.5 CVE-2026-2422 Wordfence
8.8 High Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute ≤ 4.6.1 CVE-2026-92807 Wordfence
9.1 Critical WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content No login needed ≤ 10.8.1 CVE-2026-89274 Wordfence
9.1 Critical Forminator Forms Plugin forminator Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter No login needed ≤ 1.57.2 CVE-2026-92229 Wordfence
6.4 Medium WPComplete Plugin wpcomplete Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute ≤ 2.9.9.0 CVE-2026-77820 Wordfence
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute ≤ 1.8.44 CVE-2026-85652 Wordfence
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute ≤ 3.3.8 CVE-2026-92622 Wordfence
6.5 Medium WP Inventory Manager Plugin wp-inventory-manager SQL Injection Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute ≤ 2.5.1 CVE-2026-17607 Wordfence
6.4 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute ≤ 2.8.0 CVE-2026-84909 Wordfence
5.3 Medium Divi Theme Broken Access Control Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via 'content' Parameter via Shortcode Module REST Endpoint No login needed ≤ 5.11.1 CVE-2026-91707 Wordfence
2.7 Low King Addons for Elementor Plugin king-addons Information Disclosure Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode < 51.1.81 Fixed in 51.1.81 CVE-2026-84903 WPScan
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.44 CVE-2026-86311 Wordfence
4.8 Medium Formidable Forms Plugin formidable Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token No login needed 6.34 – < 6.35 Fixed in 6.35 CVE-2026-19857 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only