WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 166 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Magee Shortcodes Plugin Cross-Site Scripting Reflected XSS via live_preview and magee_create_shortcode Actions No login needed ≤ 2.1.1 CVE-2026-105316 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101161 WPScan
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields ≤ 4.17.4 CVE-2026-92536 Wordfence
8.8 High Groups Plugin groups Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode ≤ 4.6.0 CVE-2026-77203 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter No login needed ≤ 6.5.2 CVE-2026-84280 Wordfence
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute ≤ 6.8.0 CVE-2026-9231 Wordfence
8.1 High WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter ≤ 2.4.2 CVE-2026-92235 Wordfence
8.1 High HUSKY Plugin woocommerce-products-filter Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed ≤ 1.4.4 CVE-2026-92969 Wordfence
8.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) ≤ 4.17.2 CVE-2026-85658 Wordfence
8.8 High Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute ≤ 4.6.1 CVE-2026-92807 Wordfence
8.8 High Live Composer Plugin live-composer-page-builder PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Shortcode ≤ 2.1.18 CVE-2026-16502 Wordfence
7.2 High Affiliate Super Assistent Plugin amazonsimpleadmin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function No login needed ≤ 1.10.2 CVE-2026-19573 Wordfence
7.2 High Pods Plugin pods Remote Code Execution Author+ RCE via Shortcode Display Callback 3.1.0 – < 3.3.9.1 Fixed in 3.3.9.1 CVE-2026-74851 WPScan
7.1 High Multiple Page Generator Plugin – MPG Plugin Cross-Site Scripting MPG < 4.1.8 - Reflected XSS via mpg_shortcode No login needed < 4.1.8 Fixed in 4.1.8 CVE-2026-13726 WPScan
7.5 High NewsPlus Shortcodes Plugin newsplus-shortcodes Local File Inclusion ≤ 4.2.0 CVE-2026-57798 Patchstack
8.8 High AdRotate Banner Manager Plugin adrotate Remote Code Execution Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute ≤ 5.17.7 CVE-2026-12242 Wordfence
7.2 High Cincopa video and media plug-in Plugin video-playlist-and-gallery-plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed ≤ 1.163 CVE-2026-10092 Wordfence
7.1 High Taskbuilder Plugin taskbuilder Cross-Site Scripting Reflected XSS via Shortcode No login needed < 5.0.8 Fixed in 5.0.8 CVE-2026-9570 WPScan
8.8 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin Cross-Site Scripting Unauthenticated Stored XSS via Comment Shortcode Bypass No login needed < 6.79 Fixed in 6.79 CVE-2026-8071 WPScan
8.8 High Crawlomatic Multipage Scraper Post Generator Plugin crawlomatic-multipage-scraper-post-generator Remote Code Execution Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute ≤ 2.7.2 CVE-2026-9009 Wordfence
7.5 High Query Shortcode Plugin query-shortcode Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'lens' Shortcode Attribute ≤ 0.2.1 CVE-2026-9200 Wordfence
7.2 High Prismatic Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode No login needed ≤ 3.7.3 CVE-2026-3876 Wordfence
8.0 High Ultimate Member Plugin ultimate-member Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag ≤ 2.11.2 CVE-2026-4248 Wordfence
7.5 High JS Archive List Plugin jquery-archive-list-widget PHP Object Injection Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute ≤ 6.1.7 CVE-2026-2020 Wordfence
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
8.8 High SportsPress Plugin sportspress Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.7.26 CVE-2025-15368 Wordfence
7.5 High Administrative Shortcodes Plugin administrative-shortcodes Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'slug' Shortcode Attribute ≤ 0.3.4 CVE-2026-1257 Wordfence
7.3 High BuddyPress Plugin buddypress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 14.3.3 CVE-2024-11976 Wordfence
7.2 High GetContentFromURL Plugin getcontentfromurl Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'url' Shortcode Attribute No login needed ≤ 1.0 CVE-2025-14613 Wordfence
7.2 High Advanced Ads Plugin advanced-ads Remote Code Execution Authenticated (Editor+) Remote Code Execution via Shortcode ≤ 2.0.14 CVE-2025-13592 Wordfence
7.5 High Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode ≤ 2.0.2 CVE-2025-14071 Wordfence
8.1 High Extensive VC Addons for WPBakery page builder Plugin extensive-vc-addon Local File Inclusion Unauthenticated Local File Inclusion via 'shortcode_name' Parameter No login needed ≤ 1.9.1 CVE-2025-14475 Wordfence
7.2 High Rich Shortcodes for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Google Review No login needed ≤ 6.8 CVE-2025-12499 Wordfence
8.8 High WPCOM Member Plugin wpcom-member Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 1.7.14 CVE-2025-11920 Wordfence
7.1 High Shortcode Generator Plugin shortcode-generator Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-49945 Patchstack
7.3 High Rehub Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via re_filterpost No login needed ≤ 19.9.7 CVE-2025-7366 Wordfence
7.2 High Easy Timer Plugin easy-timer Remote Code Execution Authenticated (Editor+) Remote Code Execution via Shortcode ≤ 4.2.1 CVE-2025-9519 Wordfence
7.3 High Soledad Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.6.7 CVE-2025-8105 Wordfence
7.3 High Woodmart Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.2.3 CVE-2025-6744 Wordfence
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.16 Fixed in 2.1.17 CVE-2025-47673 Patchstack
7.2 High File Manager Advanced Shortcode <= Multiple Versions Plugin Local File Inclusion Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode ≤ 2.5.4, ≤ 2.5.6 CVE-2024-13914 Wordfence
7.3 High Wolmart | Multi-Vendor Marketplace WooCommerce Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed ≤ 1.8.11 CVE-2024-13793 Wordfence
7.3 High LayoutBoxx Plugin layoutboxx Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.3.1 CVE-2025-2802 Wordfence
7.3 High Motors - Car Dealer, Rental & Listing Theme Arbitrary Shortcode Execution Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.6.65 CVE-2024-13738 Wordfence
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
7.2 High Flickr Shortcode Importer Plugin flickr-shortcode-importer PHP Object Injection ≤ 2.2.3 CVE-2025-46481 Patchstack
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-24621 Patchstack
7.1 High Event Espresso – Custom Email Template Shortcode Plugin email-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-32507 Patchstack
7.1 High Cool Flipbox – Shortcode & Gutenberg Block Plugin flip-boxes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-32521 Patchstack
7.1 High bbPress2 shortcode whitelist Plugin bbpress2-shortcode-whitelist Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.2.1 CVE-2025-39432 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only