WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 17,624 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Mindio Magic MCP Plugin mindio-magic-mcp Information Disclosure Sensitive Data Exposure ≤ 0.5.6 Fixed in 0.7.1 CVE-2026-104402 Patchstack
6.4 Medium Twenty20 Image Before-After Plugin twenty20 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute ≤ 2.0.5 CVE-2026-92767 Wordfence
6.5 Medium WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode) No login needed ≤ 2.4.3 CVE-2026-100157 Wordfence
5.3 Medium WPCafe Plugin wp-cafe Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete No login needed ≤ 3.0.19 CVE-2026-11601 Wordfence
6.1 Medium WPC Estimated Delivery Date for WooCommerce Plugin wpc-estimated-delivery-date Cross-Site Scripting Reflected Cross-Site Scripting via 'rule_data' Parameter No login needed ≤ 4.0.1 CVE-2026-104313 Wordfence
5.4 Medium WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter ≤ 2.4.3 CVE-2026-103519 Wordfence
6.1 Medium WPFront Notification Bar Plugin wpfront-notification-bar Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI No login needed ≤ 3.5.1 CVE-2026-93896 Wordfence
6.1 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross-Site Scripting via 'thumb_url' Parameter No login needed ≤ 1.8.46 CVE-2026-92974 Wordfence
6.4 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.5.3 CVE-2026-15795 Wordfence
5.4 Medium WPMobile.App Plugin wpappninja Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment No login needed ≤ 11.84 CVE-2026-103421 Wordfence
4.3 Medium Burst Statistics Plugin burst-statistics Authentication Bypass Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token' ≤ 3.7.1 CVE-2026-97343 Wordfence
6.8 Medium Loco Translate Plugin loco-translate Cross-Site Scripting Translator+ Stored XSS via Bundle Configuration < 2.8.9 Fixed in 2.8.9 CVE-2026-94239 WPScan
6.8 Medium Loco Translate Plugin loco-translate Path Traversal Translator+ Limited File Read via 'path' Parameter < 2.8.9 Fixed in 2.8.9 CVE-2026-94238 WPScan
6.3 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Subscriber+ SQLi via get_addon_output_data 1.5.142 – < 2.0.21 Fixed in 2.0.21 CVE-2026-92923 WPScan
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Broken Access Control Unauthenticated Abandoned Cart Modification and Deletion No login needed < 6.3 Fixed in 6.3 CVE-2026-92437 WPScan
6.8 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Contributor+ Stored XSS via Image Gallery Item URL Attribute < 2.9.3 Fixed in 2.9.3 CVE-2026-88782 WPScan
5.3 Medium MetForm Plugin metform Information Disclosure Unauthenticated Form Entry Data Disclosure via REST API No login needed < 4.3.1 Fixed in 4.3.1 CVE-2026-86832 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQLi via 'ucs' Parameter No login needed 1.5.139 – < 2.0.21 Fixed in 2.0.21 CVE-2026-85568 WPScan
6.6 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated Arbitrary File Write via Path Traversal < 2.0.21 Fixed in 2.0.21 CVE-2026-85015 WPScan
6.8 Medium MPG Plugin Path Traversal Editor+ Arbitrary File Read via Project Import < 4.2.3 Fixed in 4.2.3 CVE-2026-103293 WPScan
6.4 Medium WP Ultimate Review Plugin wp-ultimate-review Cross-Site Scripting Author+ Stored XSS via Review Overview Settings < 2.4.4 Fixed in 2.4.4 CVE-2026-101162 WPScan
6.1 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation No login needed ≤ 5.5.1.5 CVE-2026-103909 Wordfence
6.1 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Reflected Cross-Site Scripting via 'woosq-redirect' Parameter No login needed ≤ 4.4.0 CVE-2026-103888 Wordfence
4.9 Medium SEOPress Plugin wp-seopress Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter ≤ 10.2 CVE-2026-101357 Wordfence
6.4 Medium Rich Showcase for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API) ≤ 7.1.3 CVE-2026-100148 Wordfence
5.3 Medium WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons Plugin social-icons-widget-by-wpzoom Information Disclosure Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`… No login needed ≤ 4.7.3 CVE-2026-100149 Wordfence
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter No login needed ≤ 5.0.2 CVE-2026-100152 Wordfence
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget ≤ 1.3.2 CVE-2025-12828 Wordfence
6.4 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write ≤ 3.2.1 CVE-2026-97344 Wordfence
4.3 Medium Alt Text AI Plugin alttext-ai Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Content Modification via atai_enrich_post_content AJAX Action ≤ 1.10.41 CVE-2026-91108 Wordfence
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter ≤ 2.1.6 CVE-2026-11399 Wordfence
6.4 Medium EmbedPress Plugin embedpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute ≤ 4.6.6 CVE-2026-92727 Wordfence
6.1 Medium LearnPress Plugin learnpress Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter No login needed ≤ 4.4.7 CVE-2026-92538 Wordfence
6.1 Medium EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Parameter Key No login needed ≤ 8.7.7 CVE-2026-92826 Wordfence
6.1 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Cross-Site Scripting Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter No login needed ≤ 4.17.4 CVE-2026-92551 Wordfence
6.5 Medium SupportCandy Plugin supportcandy SQL Injection Authenticated (Custom+) SQL Injection via 'sort_by' Parameter ≤ 3.5.3 CVE-2026-94539 Wordfence
6.4 Medium SupportCandy Plugin supportcandy Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name' Parameter ≤ 3.5.3 CVE-2026-94378 Wordfence
6.1 Medium Ivory Search Plugin add-search-to-menu Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 5.5.18 CVE-2026-92243 Wordfence
5.4 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 3.2.19 CVE-2026-100180 Wordfence
6.5 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version SQL Injection Authenticated (Contributor+) SQL Injection via 'fields[][value]' Parameter ≤ 2.11.0.5 CVE-2026-95865 Wordfence
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Search Query No login needed < 5.0.2.1 Fixed in 5.0.2.1 CVE-2026-19856 WPScan
4.3 Medium LearnPress Plugin learnpress Broken Access Control ≤ 4.4.9.1 CVE-2026-39717 Patchstack
4.7 Medium Aculect AI Companion Plugin aculect-ai-companion Open Redirect Unvalidated Redirects and Forwards No login needed ≤ 0.8.1 CVE-2026-39600 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
6.5 Medium WebSamurai Plugin websamurai Broken Access Control ≤ 1.0.7 CVE-2026-39439 Patchstack
6.5 Medium Airano MCP Bridge Plugin airano-mcp-bridge Broken Access Control ≤ 2.11.0 CVE-2026-32585 Patchstack
5.3 Medium Smart One Click Setup – Complete Demo Import & Export Plugin smart-one-click-setup Information Disclosure Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure No login needed ≤ 1.4.3 CVE-2026-32584 Patchstack
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
6.5 Medium ThemeREX Addons Plugin trx_addons Cross-Site Scripting ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102798 Patchstack
5.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.4.9 Fixed in 4.4.9.1 CVE-2026-104403 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only