WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 1–50 of 2,148 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.3 Critical | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection No login needed |
≤ 2.0.20 Fixed in 2.0.21 |
CVE-2026-103355 |
Patchstack | |
| 9.1 Critical | Beaver Builder Page Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output No login needed |
≤ 2.11.0.5 |
CVE-2026-92084 |
Wordfence | |
| 9.1 Critical | VikAppointments Services Booking Calendar | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter No login needed |
≤ 1.2.21 |
CVE-2026-87115 |
Wordfence | |
| 9.8 Critical | Divi Membership | Privilege Escalation Unauthenticated Privilege Escalation via 'form_id' Parameter No login needed |
≤ 2.2.0 |
CVE-2026-19652 |
Wordfence | |
| 9.8 Critical | WPMobile.App | Privilege Escalation Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter No login needed |
≤ 11.82 |
CVE-2026-94541 |
Wordfence | |
| 9.8 Critical | JSON API Auth | Authentication Bypass Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response No login needed |
≤ 3.1.2 |
CVE-2026-97637 |
Wordfence | |
| 9.1 Critical | Super Forms | Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter No login needed |
≤ 6.3.316 |
CVE-2026-15896 |
Wordfence | |
| 9.8 Critical | Divi Membership | Authentication Bypass Unauthenticated Authentication Bypass via 'paypal_param' Parameter No login needed |
≤ 2.3.0 |
CVE-2026-19660 |
Wordfence | |
| 9.8 Critical | DevKit Pro | Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow No login needed |
≤ 2.3.0 |
CVE-2026-14378 |
Wordfence | |
| 9.3 Critical | WordPress File Upload | Arbitrary File Upload SQL Injection No login needed |
≤ 5.1.10 Fixed in 5.2.0 |
CVE-2026-62071 |
Patchstack | |
| 9.8 Critical | Authorizer | Privilege Escalation No login needed |
≤ 3.15.3 Fixed in 3.16.0 |
CVE-2026-103752 |
Patchstack | |
| 9.8 Critical | Ultimate Multisite | Authentication Bypass Unauthenticated Authentication Bypass via 'checkout_form' Parameter No login needed |
≤ 2.15.0 |
CVE-2026-75957 |
Wordfence | |
| 9.8 Critical | Super Forms | Privilege Escalation Unauthenticated Privilege Escalation via 'role' Parameter No login needed |
≤ 6.3.316 |
CVE-2026-15989 |
Wordfence | |
| 10.0 Critical | BackupSheep | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key No login needed |
≤ 1.8 |
CVE-2026-101148 |
WPScan | |
| 9.1 Critical | Appointment Booking | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field No login needed |
≤ 5.7.0 |
CVE-2026-92966 |
Wordfence | |
| 9.8 Critical | Nested Pages | PHP Object Injection No login needed |
≤ 3.3.2 Fixed in 3.3.3 |
CVE-2026-100512 |
Patchstack | |
| 9.8 Critical | OAuth Single Sign On – SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability No login needed |
≤ 7.1.2 Fixed in 7.1.3 |
CVE-2026-97274 |
Patchstack | |
| 9.8 Critical | Booking Activities | PHP Object Injection No login needed |
≤ 1.18.7.1 Fixed in 1.18.8 |
CVE-2026-97248 |
Patchstack | |
| 9.3 Critical | Books Gallery | SQL Injection No login needed |
≤ 4.8.3 Fixed in 4.8.4 |
CVE-2026-96822 |
Patchstack | |
| 9.8 Critical | Estatik | Privilege Escalation No login needed |
≤ 4.3.5 Fixed in 4.3.6 |
CVE-2026-96350 |
Patchstack | |
| 10.0 Critical | SiteSkite | Remote Code Execution No login needed |
≤ 2.1.8 Fixed in 2.2.0 |
CVE-2026-96349 |
Patchstack | |
| 9.0 Critical | AcyMailing SMTP Newsletter | Remote Code Execution No login needed |
≤ 11.0.5 Fixed in 11.1.0 |
CVE-2026-94389 |
Patchstack | |
| 9.1 Critical | GiveWP | Authentication Bypass Broken Authentication No login needed |
≤ 4.16.9 Fixed in 4.17.0 |
CVE-2026-97196 |
Patchstack | |
| 9.8 Critical | Zella | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
< 2.6.3 Fixed in 2.6.3 |
CVE-2026-75873 |
WPScan | |
| 9.8 Critical | Ultra Addons for Contact Form 7 | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Signature Form Field No login needed |
≤ 3.5.50 |
CVE-2026-82901 |
Wordfence | |
| 9.8 Critical | miniOrange OTP Login, Verification and SMS Notifications | Authentication Bypass Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter No login needed |
≤ 5.5.5 |
CVE-2026-85984 |
Wordfence | |
| 9.8 Critical | Request a Quote for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload via AJAX Popup Handler No login needed |
≤ 2.9.2 |
CVE-2026-18143 |
Wordfence | |
| 9.8 Critical | Automation Web Platform | Privilege Escalation Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter No login needed |
≤ 4.8.6 |
CVE-2026-14281 |
Wordfence | |
| 9.1 Critical | Online Scheduling and Appointment Booking System | Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter No login needed |
≤ 28.2 |
CVE-2026-93399 |
Wordfence | |
| 9.1 Critical | Customer Reviews for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter No login needed |
≤ 5.120.0 |
CVE-2026-89055 |
Wordfence | |
| 9.8 Critical | Visual Composer Website Builder | Local File Inclusion Unauthenticated Local File Inclusion via 'vcv-template' Parameter No login needed |
≤ 45.16.0 |
CVE-2026-12227 |
Wordfence | |
| 9.8 Critical | Paytium: Mollie payment forms & donations | Privilege Escalation Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter No login needed |
≤ 5.0.3 |
CVE-2026-18467 |
Wordfence | |
| 9.3 Critical | Product Filter by WBW | SQL Injection No login needed |
≤ 3.1.7 Fixed in 3.1.8 |
CVE-2026-95601 |
Patchstack | |
| 9.0 Critical | WP OAuth Server | Privilege Escalation Subscriber+ Cross-User Account Takeover via OIDC ID Token Substitution |
< 6.4.0 Fixed in 6.4.0 |
CVE-2026-82843 |
WPScan | |
| 9.0 Critical | YAHMAN Add-ons | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Blog Card Cache No login needed |
< 0.9.31 Fixed in 0.9.31 |
CVE-2026-75799 |
WPScan | |
| 9.8 Critical | Give Tributes | PHP Object Injection Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter No login needed |
≤ 2.3.1 |
CVE-2026-19658 |
Wordfence | |
| 9.8 Critical | Meta Box AIO | Privilege Escalation Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter No login needed |
≤ 4.5.6 |
CVE-2026-13355 |
Wordfence | |
| 9.8 Critical | WooCommerce Online Product Designer 1.7.0 | Arbitrary File Upload < 2.15.0 - Unauthenticated Arbitrary File Upload No login needed |
1.7.0 – < 2.15.0 Fixed in 2.15.0 |
CVE-2026-82187 |
WPScan | |
| 9.8 Critical | Botiga Pro | Privilege Escalation Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route No login needed |
< 1.6.5 Fixed in 1.6.5 |
CVE-2026-86591 |
WPScan | |
| 9.1 Critical | WP Recipe Maker | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content No login needed |
≤ 10.8.1 |
CVE-2026-89274 |
Wordfence | |
| 9.1 Critical | Forminator Forms | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter No login needed |
≤ 1.57.2 |
CVE-2026-92229 |
Wordfence | |
| 9.8 Critical | Gravity Forms | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Hidden File Upload Field No login needed |
≤ 3.1.0.4 |
CVE-2026-84434 |
Wordfence | |
| 9.1 Critical | AF Companion | Arbitrary File Upload Shop Manager+ Arbitrary File Upload to RCE |
< 2.2.0 Fixed in 2.2.0 |
CVE-2026-84738 |
WPScan | |
| 9.8 Critical | Headless Single Sign On | Authentication Bypass Broken Authentication No login needed |
≤ 1.7.0 Fixed in 1.7.1 |
CVE-2026-62108 |
Patchstack | |
| 10.0 Critical | Migratico Lite | Remote Code Execution No login needed |
≤ 2.6.8 Fixed in 2.7.1 |
CVE-2026-62104 |
Patchstack | |
| 9.8 Critical | EduAdmin Booking | Authentication Bypass Broken Authentication No login needed |
≤ 5.4.2 Fixed in 6.0.0 |
CVE-2026-62101 |
Patchstack | |
| 9.0 Critical | wpShopGermany IT-RECHT KANZLEI | Remote Code Execution Unauthenticated RCE via Predictable API Token No login needed |
1.6 – < 2.4 Fixed in 2.4 |
CVE-2026-88795 |
WPScan | |
| 9.8 Critical | Login with QR | Authentication Bypass Unauthenticated Authentication Bypass via 'autologin_code' Parameter No login needed |
≤ 1.0.0 |
CVE-2026-86710 |
WPScan | |
| 9.8 Critical | The Pressengine | Authentication Bypass Unauthenticated Authentication Bypass No login needed |
≤ 1.0 |
CVE-2026-86709 |
WPScan | |
| 9.8 Critical | Private Feed Key | Authentication Bypass Unauthenticated Authentication Bypass via 'feedkey' Parameter No login needed |
≤ 0.1 |
CVE-2026-86707 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.