WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.7 Low Pie Register Plugin pie-register Information Disclosure Unauthenticated User Email Disclosure via Invitation Code No login needed < 3.8.4.14 Fixed in 3.8.4.14 CVE-2026-96962 WPScan
3.7 Low MetForm Plugin metform Information Disclosure Unauthenticated Debug File Disclosure via HubSpot Forms Integration No login needed 2.2.1 – < 4.3.1 Fixed in 4.3.1 CVE-2026-86834 WPScan
3.7 Low WP Ultimate CSV Importer Plugin wp-ultimate-csv-importer Information Disclosure Unauthenticated Imported Data Disclosure via Predictable Log Path No login needed < 9.2 Fixed in 9.2 CVE-2026-80518 WPScan
3.5 Low WP Ultimate CSV Importer Plugin wp-ultimate-csv-importer Cross-Site Scripting Admin+ Stored XSS via ZIP Import SVG Upload 7.17 – < 9.2 Fixed in 9.2 CVE-2026-80517 WPScan
3.7 Low Booking Calendar Plugin booking Other Race Condition No login needed ≤ 11.8.4 CVE-2026-39601 Patchstack
3.1 Low Otter Blocks Plugin otter-blocks Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget ≤ 3.2.6 CVE-2026-102002 Wordfence
3.1 Low Motors – Car Dealership & Classified Listings Plugin Broken Access Control Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured < 1.4.124 Fixed in 1.4.124 CVE-2026-91023 WPScan
3.1 Low If-So Dynamic Content Plugin if-so Cross-Site Scripting Editor+ Stored XSS via Conversion Name 1.9.9 – < 1.10.2 Fixed in 1.10.2 CVE-2026-87973 WPScan
2.7 Low Astra Theme astra Content Injection ≤ 4.13.12 Fixed in 4.14.0 CVE-2026-27085 Patchstack
2.7 Low Media Library Organizer Plugin media-library-organizer Broken Access Control Contributor+ Arbitrary Taxonomy Term Creation 2.0.4 – < 2.1.4 Fixed in 2.1.4 CVE-2026-94297 WPScan
3.4 Low Safe Redirect Manager Plugin safe-redirect-manager Open Redirect Open Redirect via Wildcard Redirect Rules No login needed < 2.3.0 Fixed in 2.3.0 CVE-2026-88791 WPScan
3.5 Low Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting Editor+ Stored XSS via Taxonomy Term Fields < 1.67 Fixed in 1.67 CVE-2026-82127 WPScan
3.8 Low Bookly Plugin Information Disclosure Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR < 28.3 Fixed in 28.3 CVE-2026-86839 WPScan
2.7 Low MCP Server Plugin Information Disclosure Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route < 1.8.2 Fixed in 1.8.2 CVE-2026-96526 WPScan
2.7 Low MCP Server Plugin Broken Access Control Contributor+ Workflow Modification and Deletion via Missing Ownership Check < 1.8.2 Fixed in 1.8.2 CVE-2026-96525 WPScan
2.7 Low Events Manager Plugin events-manager Broken Access Control Contributor+ Arbitrary Ticket Overwrite via IDOR < 7.4.5 Fixed in 7.4.5 CVE-2026-93661 WPScan
2.7 Low WPeMatico RSS Feed Fetcher Plugin wpematico Information Disclosure Contributor+ Campaign Configuration and Log Disclosure via IDOR < 2.8.26 Fixed in 2.8.26 CVE-2026-89004 WPScan
3.5 Low The Post Grid Plugin the-post-grid Content Injection Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening < 7.9.5 Fixed in 7.9.5 CVE-2026-84151 WPScan
3.7 Low MPCX Lightbox Plugin Information Disclosure Unauthenticated Non-Public Post Content Disclosure No login needed 1.2.2 – 1.2.5 CVE-2026-87848 WPScan
3.7 Low NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Information Disclosure Unauthenticated Order Data Disclosure via Quote Request Page No login needed 2.0 – < 2.4.16 Fixed in 2.4.16 CVE-2026-93528 WPScan
3.3 Low WC Fields Factory Plugin wc-fields-factory Information Disclosure Contributor+ Arbitrary Post Cloning and Private Content Disclosure < 4.1.11 Fixed in 4.1.11 CVE-2026-93507 WPScan
2.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Unpublished Event Disclosure via mpwem_load_event_list 5.3.6 – < 5.7.3 Fixed in 5.7.3 CVE-2026-91077 WPScan
3.7 Low Paid Member Subscriptions Plugin Broken Access Control Unauthenticated In-Flight Checkout State Deletion via pms_process_payment No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-90951 WPScan
3.7 Low Forminator Forms Plugin forminator Broken Access Control Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link No login needed 1.17.1 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87074 WPScan
3.1 Low Forminator Forms Plugin forminator Broken Access Control Subscriber+ Form Stripe Field Migration via migrate_stripe 1.38.1 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87069 WPScan
3.8 Low The Events Calendar Plugin the-events-calendar Broken Access Control Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes 6.15.16.1 – < 6.17.5 Fixed in 6.17.5 CVE-2026-84743 WPScan
2.7 Low The Events Calendar Plugin the-events-calendar Broken Access Control Contributor+ Content Publication via TEC V1 REST API 6.15.0 – < 6.17.5 Fixed in 6.17.5 CVE-2026-84742 WPScan
3.7 Low To Do List Member Plugin Content Injection Unauthenticated Content Injection via Import No login needed 1.4 – 1.6 CVE-2026-86802 WPScan
3.7 Low TikTok Plugin tiktok-for-business Broken Access Control Unauthenticated OAuth Code Redemption No login needed 1.2.0 – < 1.4.2 Fixed in 1.4.2 CVE-2026-92965 WPScan
2.7 Low Meow Gallery Plugin meow-gallery Information Disclosure Author+ Draft and Private Post Disclosure via fetch_posts < 5.5.5 Fixed in 5.5.5 CVE-2026-92423 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Plugin Image Settings Update < 4.5.0 Fixed in 4.5.0 CVE-2026-81654 WPScan
2.7 Low NextGEN Gallery Plugin Information Disclosure Contributor+ Image Metadata Disclosure via IDOR 3.59.5 – < 4.5.0 Fixed in 4.5.0 CVE-2026-81652 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81651 WPScan
3.8 Low Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-92420 WPScan
3.7 Low Secure Custom Fields Plugin secure-custom-fields Broken Access Control Unauthenticated Post Modification via Front-End Form ID Substitution No login needed < 6.9.4 Fixed in 6.9.4 CVE-2026-92403 WPScan
3.5 Low Business Name Generator Plugin Cross-Site Scripting Admin+ Stored XSS via Button Color Setting ≤ 1.3 CVE-2025-15698 WPScan
2.7 Low Bookit Plugin bookit-for-cal-com Information Disclosure Bookit Staff+ Appointment PII Disclosure < 2.6.0.5 Fixed in 2.6.0.5 CVE-2026-89008 WPScan
2.7 Low Bookit Plugin bookit-for-cal-com Broken Access Control Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization < 2.6.0.5 Fixed in 2.6.0.5 CVE-2026-89007 WPScan
2.7 Low MasterStudy LMS 3.6.2 Plugin Information Disclosure < 3.7.50 - Instructor+ Student PII Disclosure via IDOR 3.6.2 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88844 WPScan
3.8 Low King Addons for Elementor Plugin king-addons Broken Access Control Author+ Missing Authorization via Image Optimizer 51.1.56 – < 51.1.81 Fixed in 51.1.81 CVE-2026-84904 WPScan
2.7 Low King Addons for Elementor Plugin king-addons Information Disclosure Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode < 51.1.81 Fixed in 51.1.81 CVE-2026-84903 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Order Status Manipulation via IDOR < 3.7.50 Fixed in 3.7.50 CVE-2026-81340 WPScan
3.7 Low Robokassa payment gateway for Woocommerce Plugin robokassa Price Manipulation Unauthenticated Payment Bypass via Forged JWT Callback No login needed < 1.8.9 Fixed in 1.8.9 CVE-2026-91017 WPScan
3.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel No login needed 5.3.6 – < 5.3.8 Fixed in 5.3.8 CVE-2026-91008 WPScan
2.7 Low Comments Import & Export Plugin comments-import-export-woocommerce Information Disclosure Author+ Comment PII Disclosure via Export 2.1.11 – < 2.5.4 Fixed in 2.5.4 CVE-2026-87836 WPScan
3.7 Low LearnPress Plugin learnpress Information Disclosure Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint No login needed 4.4.3 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86446 WPScan
3.8 Low FluentBoards Plugin fluent-boards Broken Access Control Board Member+ Board Membership and Public Access Modification < 2.0.15 Fixed in 2.0.15 CVE-2026-89328 WPScan
3.8 Low FluentBoards Plugin fluent-boards Authentication Bypass Board Member+ Comment Author Spoofing via 'comment_by' Parameter < 2.0.15 Fixed in 2.0.15 CVE-2026-89327 WPScan
3.7 Low LearnPress Plugin learnpress Information Disclosure Unauthenticated Order Data Disclosure via lp_download_order No login needed 4.3.2.8 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86448 WPScan
3.7 Low Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint No login needed 4.1.5 – < 4.1.24 Fixed in 4.1.24 CVE-2026-84907 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only