WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 8,901 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 4.0.17 Fixed in 4.0.18 CVE-2026-97307 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2026-103062 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.14 Fixed in 14.16.15 CVE-2026-97276 Patchstack
7.1 High Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting No login needed ≤ 3.7.11.1 Fixed in 3.7.12 CVE-2026-103354 Patchstack
8.8 High Ultimate Member Plugin ultimate-member Privilege Escalation ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-96451 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
8.2 High Kirki Plugin kirki Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-103065 Patchstack
8.8 High Smart Manager Plugin smart-manager-for-wp-e-commerce SQL Injection Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter ≤ 8.97.0 CVE-2026-18443 Wordfence
7.5 High WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager SQL Injection Unauthenticated SQL Injection via 'fullRef' Parameter No login needed ≤ 8.7 CVE-2026-96267 Wordfence
8.1 High Nelio Content Plugin nelio-content Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter ≤ 4.5.0 CVE-2026-94505 Wordfence
7.2 High Mail logging Plugin wp-mail-catcher Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message No login needed ≤ 2.1.12 CVE-2026-93889 Wordfence
7.5 High WPCafe Plugin wp-cafe Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting ≤ 3.0.18 CVE-2026-75028 Wordfence
7.2 High WPC Product Options for WooCommerce Plugin wpc-product-options Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name No login needed ≤ 4.0.5 CVE-2026-97660 Wordfence
8.2 High TillKit Plugin tillkit Authentication Bypass Unauthenticated POS Takeover via Hard-Coded Default Manager PIN No login needed < 1.0.5 Fixed in 1.0.5 CVE-2026-91078 WPScan
8.6 High SaveTo Wishlist Lite Plugin saveto-wishlist-lite-for-woocommerce SQL Injection Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-89236 WPScan
8.8 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting Unauthenticated Stored XSS via Comment Content No login needed < 2.9.3 Fixed in 2.9.3 CVE-2026-88783 WPScan
7.5 High WP 2FA Plugin wp-2fa Authentication Bypass Two-Factor Authentication Bypass via TOTP Code Replay < 4.1.0 Fixed in 4.1.0 CVE-2026-103514 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101161 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Non-Numeric Review Rating No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101160 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Cross-Site Scripting Unauthenticated Stored XSS via Review Submission No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101159 WPScan
7.2 High Transliterator Plugin serbian-transliteration Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder No login needed ≤ 2.5.8 CVE-2026-96575 Wordfence
8.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter No login needed ≤ 1.2.30 CVE-2026-101923 Wordfence
7.2 High Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters No login needed ≤ 2.12.2 CVE-2026-87091 Wordfence
7.5 High Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints No login needed ≤ 4.8.3 CVE-2026-97337 Wordfence
7.2 High Magic Tooltips For Contact Form 7 Plugin magic-tooltips-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author No login needed ≤ 1.0.34 CVE-2026-101928 Wordfence
7.2 High Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom Field No login needed ≤ 3.3.11 CVE-2026-96650 Wordfence
7.2 High SEOPress Plugin wp-seopress Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Author Display Name No login needed ≤ 10.2 CVE-2026-96564 Wordfence
7.5 High GeoDirectory Plugin geodirectory SQL Injection Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing No login needed ≤ 2.8.186 CVE-2026-103913 Wordfence
7.2 High Visitor Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header No login needed ≤ 8.16 CVE-2026-97341 Wordfence
7.2 High GD Rating System Plugin gd-rating-system Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX No login needed ≤ 3.7.1 CVE-2026-93430 Wordfence
8.8 High Groundhogg Plugin groundhogg Privilege Escalation Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test ≤ 4.9 CVE-2026-97644 Wordfence
7.2 High Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 5.3.5 CVE-2026-92977 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields ≤ 4.17.4 CVE-2026-92536 Wordfence
7.5 High Ultimate Member Plugin ultimate-member Broken Access Control Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass No login needed ≤ 2.13.1 CVE-2026-93428 Wordfence
7.2 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter No login needed ≤ 2.13.1 CVE-2026-96270 Wordfence
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
7.5 High CodeArt Google MP3 Audio Player Plugin google-mp3-audio-player Path Traversal CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php No login needed ≤ 1.0.11 CVE-2014-125130 VulnCheck
7.2 High JetAppointment Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter No login needed ≤ 2.5.2.1 CVE-2026-93875 Wordfence
7.2 High W3 Total Cache Plugin w3-total-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 2.10.6 CVE-2026-87920 Wordfence
7.2 High No External Links Plugin mihdan-no-external-links Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect No login needed ≤ 5.2.0 CVE-2026-95670 Wordfence
7.2 High Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview No login needed ≤ 4.13.0 CVE-2026-93756 Wordfence
7.2 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) No login needed ≤ 2.9.2 CVE-2026-100107 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action No login needed ≤ 3.6.5.4 CVE-2026-97342 Wordfence
7.2 High Mang Board Plugin mangboard Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter No login needed ≤ 2.4.2 CVE-2026-96871 Wordfence
7.2 High Relevanssi Premium Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter No login needed ≤ 2.31.4 CVE-2026-103426 Wordfence
7.2 High Newsletter Plugin newsletter Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter No login needed ≤ 9.4.0 CVE-2026-96566 Wordfence
7.2 High Download Monitor Plugin download-monitor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor No login needed ≤ 5.2.10 CVE-2026-100182 Wordfence
7.2 High Relevanssi Plugin relevanssi Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 4.28.3 CVE-2026-97641 Wordfence
7.2 High CMB2 Plugin cmb2 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field No login needed ≤ 2.13.1 CVE-2026-102772 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only