WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–39 of 39 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Vayu X Theme vayu-x Broken Access Control Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation < 1.0.6 Fixed in 1.0.6 CVE-2026-88797 WPScan
7.2 High PublishPress Capabilities Plugin capability-manager-enhanced Privilege Escalation Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant ≤ 2.50.0 CVE-2026-75927 Wordfence
8.8 High DevKit Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter ≤ 2.3.0 CVE-2026-14357 Wordfence
8.1 High ProfilePress Plugin wp-user-avatar Remote Code Execution ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE No login needed < 4.17.2 Fixed in 4.17.2 CVE-2026-66047 VulnCheck
7.2 High Dokan Plugin Broken Access Control Shop Manager+ Arbitrary Plugin Installation/Activation via REST API < 5.0.14 Fixed in 5.0.14 CVE-2026-16576 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Remote Code Execution Shop Manager+ Arbitrary Plugin Installation < 2.0.1 Fixed in 2.0.1 CVE-2026-15215 WPScan
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.2 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action ≤ 2.0.0 CVE-2026-15397 Wordfence
8.8 High Divi Torque Lite Plugin addons-for-divi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint No login needed ≤ 4.2.3 CVE-2026-4275 Wordfence
7.2 High Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder Plugin popup-maker Broken Access Control Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation ≤ 1.22.0 CVE-2026-8848 Wordfence
8.8 High Thim Core Plugin thim-core Broken Access Control Arbitrary plugin Installation ≤ 2.3.3 CVE-2025-53345 Patchstack
7.2 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process ≤ 9.1.2 CVE-2026-5464 Wordfence
7.1 High Gravity SMTP Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall ≤ 2.1.4 CVE-2026-4162 Wordfence
8.8 High Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' ≤ 1.6.4 CVE-2026-4326 Wordfence
8.8 High SpicePress Plugin spicepress Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.3.2.5 CVE-2026-39621 Patchstack
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation 8.0.0 – 9.0.2 CVE-2026-1992 Wordfence
8.8 High WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation Plugin optin Broken Access Control Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.4.24 CVE-2026-1720 Wordfence
8.8 High Orderable Plugin orderable Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.20.0 CVE-2026-0974 Wordfence
7.2 High CTX Feed – WooCommerce Product Feed Manager Plugin webappick-product-feed-for-woocommerce Broken Access Control WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation ≤ 6.6.11 CVE-2025-12975 Wordfence
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed 0.2.5.6 – 0.2.5.9 CVE-2025-12821 Wordfence
8.8 High WowRevenue Plugin revenue Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 2.1.3 CVE-2026-2001 Wordfence
8.1 High Stallion Theme stallion Local File Inclusion No login needed ≤ 1.17 CVE-2025-58927 Patchstack
8.8 High Classified Pro Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.0.14 CVE-2025-10706 Wordfence
8.8 High GSheetConnector For Gravity Forms Plugin gsheetconnector-gravity-forms Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.3.27 CVE-2025-8593 Wordfence
8.1 High Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Installation ≤ 3.4.3 CVE-2025-8565 Wordfence
8.1 High Inspiro Theme inspiro Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed ≤ 2.1.2 CVE-2025-8592 Wordfence
8.8 High B Slider- Gutenberg Slider Block for WP Plugin b-slider Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation ≤ 1.1.30 CVE-2025-8418 Wordfence
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed ≤ 0.2.5.4 CVE-2025-1305 Wordfence
8.8 High Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.4.64 CVE-2025-2807 Wordfence
8.8 High Animation Addons for Elementor Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.6 CVE-2025-1639 Wordfence
8.8 High Pubnews Theme pubnews Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.0.7 CVE-2024-10578 Wordfence
8.1 High Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Broken Access Control Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 6.44 CVE-2024-10781 Wordfence
8.8 High PostX Plugin ultimate-post Broken Access Control Missing Authorization to Arbitrary Plugin Installation/Activation ≤ 4.1.16 CVE-2024-10728 Wordfence
8.8 High Th Shop Mania Theme th-shop-mania Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.4.9 CVE-2024-10674 Wordfence
8.8 High Top Store Theme top-store Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.5.4 CVE-2024-10673 Wordfence
8.8 High Pie Register - Basic Plugin pie-register Broken Access Control Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 3.8.3.4 CVE-2024-6069 Wordfence
7.6 High Crafthemes Demo Import Plugin crafthemes-demo-import Broken Access Control Arbitrary plugin Installation ≤ 3.3 Fixed in 4.0 CVE-2024-34800 Patchstack
8.8 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.18.0 Fixed in 2.18.1 CVE-2024-30485 Patchstack
8.8 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.17.0 Fixed in 2.18.0 CVE-2024-25092 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only