WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 1–50 of 166 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Magee Shortcodes | Cross-Site Scripting Reflected XSS via live_preview and magee_create_shortcode Actions No login needed |
≤ 2.1.1 |
CVE-2026-105316 |
WPScan | |
| 7.5 High | WP Ultimate Review | Denial of Service Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode No login needed |
< 2.4.4 Fixed in 2.4.4 |
CVE-2026-101161 |
WPScan | |
| 8.8 High | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields |
≤ 4.17.4 |
CVE-2026-92536 |
Wordfence | |
| 8.8 High | Groups | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode |
≤ 4.6.0 |
CVE-2026-77203 |
Wordfence | |
| 7.2 High | Fancy Product Designer | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter No login needed |
≤ 6.5.2 |
CVE-2026-84280 |
Wordfence | |
| 7.5 High | WP Travel Engine | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute |
≤ 6.8.0 |
CVE-2026-9231 |
Wordfence | |
| 8.1 High | WP Ultimate Review | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter |
≤ 2.4.2 |
CVE-2026-92235 |
Wordfence | |
| 8.1 High | HUSKY | Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed |
≤ 1.4.4 |
CVE-2026-92969 |
Wordfence | |
| 8.1 High | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) |
≤ 4.17.2 |
CVE-2026-85658 |
Wordfence | |
| 8.8 High | Save as PDF Plugin by PDFCrowd | Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute |
≤ 4.6.1 |
CVE-2026-92807 |
Wordfence | |
| 8.8 High | Live Composer | PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Shortcode |
≤ 2.1.18 |
CVE-2026-16502 |
Wordfence | |
| 7.2 High | Affiliate Super Assistent | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function No login needed |
≤ 1.10.2 |
CVE-2026-19573 |
Wordfence | |
| 7.2 High | Pods | Remote Code Execution Author+ RCE via Shortcode Display Callback |
3.1.0 – < 3.3.9.1 Fixed in 3.3.9.1 |
CVE-2026-74851 |
WPScan | |
| 7.1 High | Multiple Page Generator Plugin – MPG | Cross-Site Scripting MPG < 4.1.8 - Reflected XSS via mpg_shortcode No login needed |
< 4.1.8 Fixed in 4.1.8 |
CVE-2026-13726 |
WPScan | |
| 7.5 High | NewsPlus Shortcodes | Local File Inclusion |
≤ 4.2.0 |
CVE-2026-57798 |
Patchstack | |
| 8.8 High | AdRotate Banner Manager | Remote Code Execution Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute |
≤ 5.17.7 |
CVE-2026-12242 |
Wordfence | |
| 7.2 High | Cincopa video and media plug-in | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed |
≤ 1.163 |
CVE-2026-10092 |
Wordfence | |
| 7.1 High | Taskbuilder | Cross-Site Scripting Reflected XSS via Shortcode No login needed |
< 5.0.8 Fixed in 5.0.8 |
CVE-2026-9570 |
WPScan | |
| 8.8 High | Spam protection, Honeypot, Anti-Spam by CleanTalk | Cross-Site Scripting Unauthenticated Stored XSS via Comment Shortcode Bypass No login needed |
< 6.79 Fixed in 6.79 |
CVE-2026-8071 |
WPScan | |
| 8.8 High | Crawlomatic Multipage Scraper Post Generator | Remote Code Execution Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute |
≤ 2.7.2 |
CVE-2026-9009 |
Wordfence | |
| 7.5 High | Query Shortcode | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'lens' Shortcode Attribute |
≤ 0.2.1 |
CVE-2026-9200 |
Wordfence | |
| 7.2 High | Prismatic | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode No login needed |
≤ 3.7.3 |
CVE-2026-3876 |
Wordfence | |
| 8.0 High | Ultimate Member | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag |
≤ 2.11.2 |
CVE-2026-4248 |
Wordfence | |
| 7.5 High | JS Archive List | PHP Object Injection Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute |
≤ 6.1.7 |
CVE-2026-2020 |
Wordfence | |
| 7.5 High | Flexi Product Slider and Grid for WooCommerce | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute |
≤ 1.0.5 |
CVE-2026-1988 |
Wordfence | |
| 8.8 High | SportsPress | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 2.7.26 |
CVE-2025-15368 |
Wordfence | |
| 7.5 High | Administrative Shortcodes | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'slug' Shortcode Attribute |
≤ 0.3.4 |
CVE-2026-1257 |
Wordfence | |
| 7.3 High | BuddyPress | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 14.3.3 |
CVE-2024-11976 |
Wordfence | |
| 7.2 High | GetContentFromURL | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'url' Shortcode Attribute No login needed |
≤ 1.0 |
CVE-2025-14613 |
Wordfence | |
| 7.2 High | Advanced Ads | Remote Code Execution Authenticated (Editor+) Remote Code Execution via Shortcode |
≤ 2.0.14 |
CVE-2025-13592 |
Wordfence | |
| 7.5 High | Live Composer – Free WordPress Website Builder | PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode |
≤ 2.0.2 |
CVE-2025-14071 |
Wordfence | |
| 8.1 High | Extensive VC Addons for WPBakery page builder | Local File Inclusion Unauthenticated Local File Inclusion via 'shortcode_name' Parameter No login needed |
≤ 1.9.1 |
CVE-2025-14475 |
Wordfence | |
| 7.2 High | Rich Shortcodes for Google Reviews | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Google Review No login needed |
≤ 6.8 |
CVE-2025-12499 |
Wordfence | |
| 8.8 High | WPCOM Member | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 1.7.14 |
CVE-2025-11920 |
Wordfence | |
| 7.1 High | Shortcode Generator | Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-49945 |
Patchstack | |
| 7.3 High | Rehub | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via re_filterpost No login needed |
≤ 19.9.7 |
CVE-2025-7366 |
Wordfence | |
| 7.2 High | Easy Timer | Remote Code Execution Authenticated (Editor+) Remote Code Execution via Shortcode |
≤ 4.2.1 |
CVE-2025-9519 |
Wordfence | |
| 7.3 High | Soledad | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 8.6.7 |
CVE-2025-8105 |
Wordfence | |
| 7.3 High | Woodmart | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 8.2.3 |
CVE-2025-6744 |
Wordfence | |
| 7.1 High | Arconix Shortcodes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.16 Fixed in 2.1.17 |
CVE-2025-47673 |
Patchstack | |
| 7.2 High | File Manager Advanced Shortcode <= Multiple Versions | Local File Inclusion Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode |
≤ 2.5.4, ≤ 2.5.6 |
CVE-2024-13914 |
Wordfence | |
| 7.3 High | Wolmart | Multi-Vendor Marketplace WooCommerce | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed |
≤ 1.8.11 |
CVE-2024-13793 |
Wordfence | |
| 7.3 High | LayoutBoxx | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 0.3.1 |
CVE-2025-2802 |
Wordfence | |
| 7.3 High | Motors - Car Dealer, Rental & Listing | Arbitrary Shortcode Execution Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 5.6.65 |
CVE-2024-13738 |
Wordfence | |
| 7.3 High | Create custom forms for WordPress with a smart form plugin for smart businesses | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.4 |
CVE-2025-2801 |
Wordfence | |
| 7.2 High | Flickr Shortcode Importer | PHP Object Injection |
≤ 2.2.3 |
CVE-2025-46481 |
Patchstack | |
| 7.1 High | Arconix Shortcodes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.15 Fixed in 2.1.16 |
CVE-2025-24621 |
Patchstack | |
| 7.1 High | Event Espresso – Custom Email Template Shortcode | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-32507 |
Patchstack | |
| 7.1 High | Cool Flipbox – Shortcode & Gutenberg Block | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.8.3 Fixed in 1.9.0 |
CVE-2025-32521 |
Patchstack | |
| 7.1 High | bbPress2 shortcode whitelist | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 2.2.1 |
CVE-2025-39432 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.