WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 2,148 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
9.1 Critical Beaver Builder Page Builder Plugin beaver-builder-lite-version Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output No login needed ≤ 2.11.0.5 CVE-2026-92084 Wordfence
9.1 Critical VikAppointments Services Booking Calendar Plugin vikappointments Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter No login needed ≤ 1.2.21 CVE-2026-87115 Wordfence
9.8 Critical Divi Membership Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'form_id' Parameter No login needed ≤ 2.2.0 CVE-2026-19652 Wordfence
9.8 Critical WPMobile.App Plugin wpappninja Privilege Escalation Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter No login needed ≤ 11.82 CVE-2026-94541 Wordfence
9.8 Critical JSON API Auth Plugin json-api-auth Authentication Bypass Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response No login needed ≤ 3.1.2 CVE-2026-97637 Wordfence
9.1 Critical Super Forms Plugin Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter No login needed ≤ 6.3.316 CVE-2026-15896 Wordfence
9.8 Critical Divi Membership Plugin Authentication Bypass Unauthenticated Authentication Bypass via 'paypal_param' Parameter No login needed ≤ 2.3.0 CVE-2026-19660 Wordfence
9.8 Critical DevKit Pro Plugin Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow No login needed ≤ 2.3.0 CVE-2026-14378 Wordfence
9.3 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload SQL Injection No login needed ≤ 5.1.10 Fixed in 5.2.0 CVE-2026-62071 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.3 Fixed in 3.16.0 CVE-2026-103752 Patchstack
9.8 Critical Ultimate Multisite Plugin ultimate-multisite Authentication Bypass Unauthenticated Authentication Bypass via 'checkout_form' Parameter No login needed ≤ 2.15.0 CVE-2026-75957 Wordfence
9.8 Critical Super Forms Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'role' Parameter No login needed ≤ 6.3.316 CVE-2026-15989 Wordfence
10.0 Critical BackupSheep Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key No login needed ≤ 1.8 CVE-2026-101148 WPScan
9.1 Critical Appointment Booking Plugin latepoint Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field No login needed ≤ 5.7.0 CVE-2026-92966 Wordfence
9.8 Critical Nested Pages Plugin wp-nested-pages PHP Object Injection No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-100512 Patchstack
9.8 Critical OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability No login needed ≤ 7.1.2 Fixed in 7.1.3 CVE-2026-97274 Patchstack
9.8 Critical Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.7.1 Fixed in 1.18.8 CVE-2026-97248 Patchstack
9.3 Critical Books Gallery Plugin wp-books-gallery SQL Injection No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-96822 Patchstack
9.8 Critical Estatik Plugin estatik Privilege Escalation No login needed ≤ 4.3.5 Fixed in 4.3.6 CVE-2026-96350 Patchstack
10.0 Critical SiteSkite Plugin siteskite Remote Code Execution No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2026-96349 Patchstack
9.0 Critical AcyMailing SMTP Newsletter Plugin acymailing Remote Code Execution No login needed ≤ 11.0.5 Fixed in 11.1.0 CVE-2026-94389 Patchstack
9.1 Critical GiveWP Plugin give Authentication Bypass Broken Authentication No login needed ≤ 4.16.9 Fixed in 4.17.0 CVE-2026-97196 Patchstack
9.8 Critical Zella Theme Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 2.6.3 Fixed in 2.6.3 CVE-2026-75873 WPScan
9.8 Critical Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Signature Form Field No login needed ≤ 3.5.50 CVE-2026-82901 Wordfence
9.8 Critical miniOrange OTP Login, Verification and SMS Notifications Plugin miniorange-otp-verification Authentication Bypass Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter No login needed ≤ 5.5.5 CVE-2026-85984 Wordfence
9.8 Critical Request a Quote for WooCommerce Plugin get-a-quote-button-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via AJAX Popup Handler No login needed ≤ 2.9.2 CVE-2026-18143 Wordfence
9.8 Critical Automation Web Platform Plugin automation-web-platform Privilege Escalation Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter No login needed ≤ 4.8.6 CVE-2026-14281 Wordfence
9.1 Critical Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter No login needed ≤ 28.2 CVE-2026-93399 Wordfence
9.1 Critical Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter No login needed ≤ 5.120.0 CVE-2026-89055 Wordfence
9.8 Critical Visual Composer Website Builder Plugin visualcomposer Local File Inclusion Unauthenticated Local File Inclusion via 'vcv-template' Parameter No login needed ≤ 45.16.0 CVE-2026-12227 Wordfence
9.8 Critical Paytium: Mollie payment forms & donations Plugin paytium Privilege Escalation Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter No login needed ≤ 5.0.3 CVE-2026-18467 Wordfence
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-95601 Patchstack
9.0 Critical WP OAuth Server Plugin Privilege Escalation Subscriber+ Cross-User Account Takeover via OIDC ID Token Substitution < 6.4.0 Fixed in 6.4.0 CVE-2026-82843 WPScan
9.0 Critical YAHMAN Add-ons Plugin yahman-add-ons Arbitrary File Upload Unauthenticated Arbitrary File Upload via Blog Card Cache No login needed < 0.9.31 Fixed in 0.9.31 CVE-2026-75799 WPScan
9.8 Critical Give Tributes Plugin PHP Object Injection Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter No login needed ≤ 2.3.1 CVE-2026-19658 Wordfence
9.8 Critical Meta Box AIO Plugin Privilege Escalation Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter No login needed ≤ 4.5.6 CVE-2026-13355 Wordfence
9.8 Critical WooCommerce Online Product Designer 1.7.0 Plugin Arbitrary File Upload < 2.15.0 - Unauthenticated Arbitrary File Upload No login needed 1.7.0 – < 2.15.0 Fixed in 2.15.0 CVE-2026-82187 WPScan
9.8 Critical Botiga Pro Plugin Privilege Escalation Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route No login needed < 1.6.5 Fixed in 1.6.5 CVE-2026-86591 WPScan
9.1 Critical WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content No login needed ≤ 10.8.1 CVE-2026-89274 Wordfence
9.1 Critical Forminator Forms Plugin forminator Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter No login needed ≤ 1.57.2 CVE-2026-92229 Wordfence
9.8 Critical Gravity Forms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Hidden File Upload Field No login needed ≤ 3.1.0.4 CVE-2026-84434 Wordfence
9.1 Critical AF Companion Plugin af-companion Arbitrary File Upload Shop Manager+ Arbitrary File Upload to RCE < 2.2.0 Fixed in 2.2.0 CVE-2026-84738 WPScan
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-62108 Patchstack
10.0 Critical Migratico Lite Plugin migratico-lite Remote Code Execution No login needed ≤ 2.6.8 Fixed in 2.7.1 CVE-2026-62104 Patchstack
9.8 Critical EduAdmin Booking Plugin eduadmin-booking Authentication Bypass Broken Authentication No login needed ≤ 5.4.2 Fixed in 6.0.0 CVE-2026-62101 Patchstack
9.0 Critical wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Remote Code Execution Unauthenticated RCE via Predictable API Token No login needed 1.6 – < 2.4 Fixed in 2.4 CVE-2026-88795 WPScan
9.8 Critical Login with QR Plugin Authentication Bypass Unauthenticated Authentication Bypass via 'autologin_code' Parameter No login needed ≤ 1.0.0 CVE-2026-86710 WPScan
9.8 Critical The Pressengine Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.0 CVE-2026-86709 WPScan
9.8 Critical Private Feed Key Plugin Authentication Bypass Unauthenticated Authentication Bypass via 'feedkey' Parameter No login needed ≤ 0.1 CVE-2026-86707 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only