WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Shopping Cart & eCommerce Store Plugin wp-easycart Privilege Escalation Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action ≤ 5.9.3 CVE-2026-17553 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15667 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15406 Wordfence
8.8 High FireBox Plugin firebox Remote Code Execution Authenticated (Author+) Remote Code Execution to Privilege Escalation ≤ 3.1.10 CVE-2026-76801 Wordfence
7.2 High Contact Form to DB by BestWebSoft Plugin contact-form-to-db Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter No login needed ≤ 1.7.5 CVE-2026-13359 Wordfence
7.5 High Event Tickets and Registration Plugin event-tickets Broken Access Control Missing Authorization to Unauthenticated Stripe Credentials Update No login needed ≤ 5.27.4 CVE-2026-3174 Wordfence
8.8 High Live Composer Plugin live-composer-page-builder PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Shortcode ≤ 2.1.18 CVE-2026-16502 Wordfence
7.1 High EDD Product Catalog Feed by PixelYourSite Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter ≤ 1.0.2 CVE-2026-9331 Wordfence
7.2 High Hide My WP Ghost Plugin hide-my-wp Server-Side Request Forgery No login needed ≤ 7.0.09 Fixed in 7.0.10 CVE-2026-81806 Patchstack
7.5 High WooCommerce Plugin woocommerce Denial of Service Denial of Service Attack No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-48888 Patchstack
7.1 High Unbounce Landing Pages Plugin unbounce Broken Access Control ≤ 1.1.4 CVE-2026-81781 Patchstack
7.5 High Csomagpontok és szállítási címkék WooCommerce-hez Plugin hungarian-pickup-points-for-woocommerce Broken Access Control No login needed < 4.2.8 Fixed in 4.2.8 CVE-2026-81790 Patchstack
7.1 High Easy Appointments Plugin easy-appointments Cross-Site Scripting No login needed ≤ 4.0.2.1 CVE-2026-81798 Patchstack
7.1 High Open User Map Plugin open-user-map Cross-Site Scripting No login needed ≤ 1.4.50 Fixed in 1.4.51 CVE-2026-84818 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.1 Fixed in 3.6.5.2 CVE-2026-84817 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
7.5 High WP Fusion (Pro) Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter ≤ 3.47.13 CVE-2026-14444 Wordfence
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field No login needed ≤ 3.15.7 CVE-2026-6431 Wordfence
7.5 High Kirki Plugin kirki Cross-Site Scripting Unauthenticated Stored XSS via HTML Entity Decoding No login needed 6.2.1 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84219 WPScan
8.8 High SureCart Plugin surecart Privilege Escalation Subscriber+ Administrator Account Takeover 4.0.0 – < 4.6.3 Fixed in 4.6.3 CVE-2026-18480 WPScan
7.5 High HivePress Authentication Plugin hivepress-authentication Authentication Bypass Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator No login needed ≤ 1.1.4 CVE-2026-18056 Wordfence
8.8 High Nokri – Job Board Theme Broken Access Control Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover ≤ 1.6.4 CVE-2025-9049 Wordfence
8.8 High Abandoned Cart Pro for WooCommerce Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 10.7.1 CVE-2026-81543 Wordfence
7.2 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via IP Address Header No login needed ≤ 1.10.2 CVE-2026-83625 Wordfence
7.2 High QuickCal Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters No login needed ≤ 1.0.20 CVE-2026-15984 Wordfence
7.2 High W3 Total Cache Plugin w3-total-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator No login needed ≤ 2.10.5 CVE-2026-78438 Wordfence
8.8 High Welcart e-Commerce Plugin usc-e-shop Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback No login needed ≤ 2.12.1 CVE-2026-19887 Wordfence
7.2 High SureForms Plugin sureforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload No login needed ≤ 2.12.2 CVE-2026-18406 Wordfence
7.2 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key No login needed ≤ 3.15.1 CVE-2026-19769 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Post Body Field Value No login needed ≤ 2.10.5 CVE-2026-16649 Wordfence
7.2 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed ≤ 6.86 CVE-2026-77830 Wordfence
8.0 High HT Menu Plugin ht-menu-lite Cross-Site Scripting Subscriber+ Stored XSS via Menu Settings < 1.2.7 Fixed in 1.2.7 CVE-2026-84935 WPScan
8.0 High JCH Optimize Plugin jch-optimize Cross-Site Scripting Subscriber+ Stored XSS via getcacheinfo Task Override < 6.0.1 Fixed in 6.0.1 CVE-2026-84934 WPScan
8.6 High Music Store – WordPress eCommerce Plugin music-store SQL Injection WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler No login needed 1.0.245 – < 1.4.5 Fixed in 1.4.5 CVE-2026-82304 WPScan
7.1 High IPGP Visitors Origin Plugin Cross-Site Scripting Reflected XSS No login needed 1.3 – < 1.6 Fixed in 1.6 CVE-2026-81404 WPScan
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation No login needed 5.0.1.8 – < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77826 WPScan
7.5 High JetFormBuilder Plugin Information Disclosure Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19858 WPScan
7.2 High iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more Plugin iubenda-cookie-law-solution Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.13.4 CVE-2026-77263 Wordfence
7.2 High iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more Plugin iubenda-cookie-law-solution Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite No login needed ≤ 3.13.4 CVE-2026-77233 Wordfence
7.5 High LearnDash LMS Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler ≤ 5.1.5 CVE-2026-12483 Wordfence
7.6 High WooCommerce Plugin woocommerce SQL Injection < 11.0 Fixed in 11.0 CVE-2026-57777 Patchstack
7.2 High Hummingbird Plugin Remote Code Execution Admin+ Network-Wide RCE via Hub Connector on Multisite 3.15.0 – < 3.21.2 Fixed in 3.21.2 CVE-2026-19224 WPScan
7.1 High Classified Listing Plugin classified-listing Broken Access Control Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR 5.3.0 – < 6.1.1 Fixed in 6.1.1 CVE-2026-16281 WPScan
7.1 High Quick Event Manager Plugin quick-event-manager Cross-Site Scripting No login needed ≤ 9.17 CVE-2026-84848 Patchstack
7.5 High Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.17 CVE-2026-84847 Patchstack
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
7.1 High BP Better Messages Plugin bp-better-messages Cross-Site Scripting No login needed ≤ 2.15.27 Fixed in 2.15.28 CVE-2026-84812 Patchstack
8.1 High Agentimus – AI SEO, llms.txt & MCP for AI Agents Plugin agentimus Broken Access Control AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control ≤ 1.51.0 Fixed in 1.51.1 CVE-2026-84779 Patchstack
7.5 High Migrate Guru – Site Migration & Cloning Plugin migrate-guru Denial of Service Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack No login needed ≤ 6.65 Fixed in 6.72 CVE-2026-84778 Patchstack
7.4 High Really Simple SSL Plugin really-simple-ssl Authentication Bypass WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84777 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only