WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Easy Appointments Plugin easy-appointments Cross-Site Scripting No login needed ≤ 4.0.2.1 CVE-2026-81798 Patchstack
7.1 High Open User Map Plugin open-user-map Cross-Site Scripting No login needed ≤ 1.4.50 Fixed in 1.4.51 CVE-2026-84818 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.1 Fixed in 3.6.5.2 CVE-2026-84817 Patchstack
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
8.8 High Nokri – Job Board Theme Broken Access Control Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover ≤ 1.6.4 CVE-2025-9049 Wordfence
8.6 High Music Store – WordPress eCommerce Plugin music-store SQL Injection WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler No login needed 1.0.245 – < 1.4.5 Fixed in 1.4.5 CVE-2026-82304 WPScan
5.3 Medium JetPopup Plugin jet-popup Broken Access Control No login needed ≤ 2.0.20.2 Fixed in 2.0.20.3 CVE-2026-27347 Patchstack
6.5 Medium WoodMart Theme woodmart Cross-Site Scripting < 8.3.8 Fixed in 8.3.8 CVE-2026-27086 Patchstack
5.4 Medium WP Rentals Theme wprentals Broken Access Control Insecure Direct Object References (IDOR) < 3.16.0 Fixed in 3.16.0 CVE-2026-27432 Patchstack
7.6 High WooCommerce Plugin woocommerce SQL Injection < 11.0 Fixed in 11.0 CVE-2026-57777 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
5.3 Medium WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-32480 Patchstack
5.4 Medium LearnPress Plugin learnpress Cross-Site Scripting LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles < 4.4.6 Fixed in 4.4.6 CVE-2026-82024 VulnCheck
4.3 Medium LearnPress Plugin learnpress Broken Access Control LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert < 4.4.6 Fixed in 4.4.6 CVE-2026-82023 VulnCheck
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-85304 Patchstack
5.3 Medium Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-85309 Patchstack
5.3 Medium SureForms Plugin sureforms Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.12.5 Fixed in 2.12.6 CVE-2026-85308 Patchstack
5.3 Medium KP Agent Ready Plugin kp-agent-ready Information Disclosure Sensitive Data Exposure No login needed < 1.2.08 Fixed in 1.2.08 CVE-2026-85307 Patchstack
6.5 Medium MountDev AI MCP Connector Plugin mountdev-ai-mcp-connector Broken Access Control ≤ 1.6.5 Fixed in 1.6.6 CVE-2026-85306 Patchstack
5.4 Medium SEOPress Plugin wp-seopress Server-Side Request Forgery ≤ 10.1 Fixed in 10.2 CVE-2026-85305 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
7.1 High Quick Event Manager Plugin quick-event-manager Cross-Site Scripting No login needed ≤ 9.17 CVE-2026-84848 Patchstack
7.5 High Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.17 CVE-2026-84847 Patchstack
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.2.0 CVE-2026-84834 Patchstack
9.8 Critical Bricksforge Plugin bricksforge Privilege Escalation No login needed ≤ 3.1.8.8 Fixed in 3.1.8.9 CVE-2026-84814 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.174 Fixed in 2.8.175 CVE-2026-84813 Patchstack
7.1 High BP Better Messages Plugin bp-better-messages Cross-Site Scripting No login needed ≤ 2.15.27 Fixed in 2.15.28 CVE-2026-84812 Patchstack
8.1 High Agentimus – AI SEO, llms.txt & MCP for AI Agents Plugin agentimus Broken Access Control AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control ≤ 1.51.0 Fixed in 1.51.1 CVE-2026-84779 Patchstack
7.5 High Migrate Guru – Site Migration & Cloning Plugin migrate-guru Denial of Service Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack No login needed ≤ 6.65 Fixed in 6.72 CVE-2026-84778 Patchstack
7.4 High Really Simple SSL Plugin really-simple-ssl Authentication Bypass WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84777 Patchstack
7.5 High MalCare Security Plugin malcare-security Denial of Service Denial of Service Attack No login needed ≤ 6.69 Fixed in 6.72 CVE-2026-84776 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.11 Fixed in 14.16.12 CVE-2026-84774 Patchstack
7.2 High EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting No login needed ≤ 8.7.6 Fixed in 8.7.7 CVE-2026-84773 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
5.3 Medium BookIt Plugin bookit Other Bypass Vulnerability No login needed ≤ 2.6.0.3 Fixed in 2.6.0.4 CVE-2026-84767 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
7.1 High Breadcrumb NavXT Plugin breadcrumb-navxt Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-84765 Patchstack
7.1 High RTMKit Plugin rometheme-for-elementor Cross-Site Scripting No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84763 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Other Bypass Vulnerability No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2026-84762 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery No login needed ≤ 7.9 Fixed in 7.9.1 CVE-2026-84761 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84758 Patchstack
8.2 High WP Compress Plugin wp-compress-image-optimizer Broken Access Control Settings Change No login needed ≤ 7.21.28 Fixed in 7.22.0 CVE-2026-84757 Patchstack
7.1 High WCFM Membership Plugin wc-multivendor-membership Privilege Escalation ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-84756 Patchstack
6.5 Medium Mail Mint Plugin mail-mint Broken Access Control No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84755 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control No login needed ≤ 3.12.13 Fixed in 3.13.0 CVE-2026-84754 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only