WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 451–500 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Real 3D Flipbook Plugin real3d-flipbook-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute ≤ 5.1.1 CVE-2026-15098 Wordfence
6.1 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Reflected Cross-Site Scripting via 'data' Dynamic Content Tag No login needed ≤ 4.14.0 CVE-2026-87917 Wordfence
6.5 Medium Custom Field Template Plugin custom-field-template SQL Injection Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter ≤ 2.7.8 CVE-2026-9855 Wordfence
5.3 Medium Ibtana – Ecommerce Product Addons Plugin ibtana-ecommerce-product-addons Broken Access Control Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action No login needed ≤ 0.4.7.7 CVE-2026-1984 Wordfence
4.7 Medium WP Ghost (Hide My WP Ghost) Plugin hide-my-wp Open Redirect Unauthenticated Open Redirect via 'redirect_to' Parameter No login needed ≤ 7.0.02 CVE-2026-7527 Wordfence
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Cross-Site Scripting via User Input ≤ 4.5.13 CVE-2026-5400 Wordfence
4.9 Medium GoPay for WooCommerce Plugin gopay-gateway SQL Injection Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter ≤ 1.0.36 CVE-2026-75959 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order' Parameter ≤ 2.5.3 CVE-2026-13200 Wordfence
4.4 Medium OTP Login & Register Woocommerce Plugin mobile-login-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'fb-config' Setting ≤ 2.7.3 CVE-2026-12402 Wordfence
6.4 Medium WP Composer Plugin page-builder-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode ≤ 1.0.5 CVE-2026-2422 Wordfence
6.5 Medium Wow Elements Addons for Elementor Plugin wow-elements-addons-for-elementor Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting No login needed ≤ 1.11.2 CVE-2026-1641 Wordfence
6.1 Medium SSL Zen Plugin ssl-zen Cross-Site Scripting Reflected Cross-Site Scripting via 'uri' and 'host' Parameters No login needed ≤ 4.7.42 CVE-2026-15463 Wordfence
6.5 Medium Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action ≤ 3.12.27 CVE-2026-9232 Wordfence
4.3 Medium Search Atlas SEO Plugin metasync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function ≤ 2.6.23 CVE-2026-15946 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order_by' Parameter ≤ 2.5.3 CVE-2026-13191 Wordfence
4.9 Medium WP Optimizer Plugin wp-optimizer SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 2.5.0 CVE-2026-6295 Wordfence
6.4 Medium AppMySite Plugin appmysite Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler ≤ 3.15.3 CVE-2026-13770 Wordfence
5.3 Medium Payment Gateway of Stripe for WooCommerce Plugin payment-gateway-stripe-and-woocommerce-integration Other Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint No login needed ≤ 5.0.8 CVE-2026-9832 Wordfence
4.3 Medium BlockSpare - Gutenberg Site Builder Blocks & Starter Sites Plugin blockspare Broken Access Control Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation ≤ 4.2.6 CVE-2026-1242 Wordfence
4.3 Medium Search Atlas SEO Plugin metasync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter ≤ 2.6.23 CVE-2026-15947 Wordfence
5.3 Medium Bread Plugin bread Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.9.12 CVE-2026-4792 Wordfence
4.3 Medium VW Writer Blog Theme vw-writer-blog Broken Access Control Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset ≤ 1.3.8 CVE-2026-2278 Wordfence
4.3 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler ≤ 2.0.11 CVE-2026-11899 Wordfence
6.1 Medium WP Customer Reviews Plugin wp-customer-reviews Cross-Site Scripting Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter No login needed ≤ 3.7.8 CVE-2026-11608 Wordfence
4.3 Medium Flex Import Plugin flex-import Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions ≤ 3.0 CVE-2026-9615 Wordfence
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Broken Access Control Unauthenticated Broken Access Control in REST API No login needed < 6.1.1 Fixed in 6.1.1 CVE-2026-92435 WPScan
5.3 Medium Rede Itaú for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Manipulation via PIX Webhook No login needed 3.6.1 – < 5.4.7 Fixed in 5.4.7 CVE-2026-92430 WPScan
5.5 Medium Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Account Modification and Deletion via IDOR < 1.2.4 Fixed in 1.2.4 CVE-2026-92425 WPScan
4.7 Medium Hydra Booking 1.1.0 Plugin Broken Access Control < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 1.1.0 – < 1.2.3 Fixed in 1.2.3 CVE-2026-92421 WPScan
6.5 Medium WPGraphQL Smart Cache Plugin wpgraphql-smart-cache Broken Access Control Unauthenticated Persisted Query Registration and Alias Squatting No login needed < 2.3.2 Fixed in 2.3.2 CVE-2026-92099 WPScan
4.8 Medium Bookly Plugin Information Disclosure Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR No login needed 28.1 – < 28.2 Fixed in 28.2 CVE-2026-91847 WPScan
6.5 Medium Ultimate Addons for Contact Form 7 Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Signature Field No login needed 3.2.4 – < 3.5.51 Fixed in 3.5.51 CVE-2026-84750 WPScan
5.5 Medium JetFormBuilder Plugin Arbitrary File Deletion Admin+ Arbitrary File Deletion via Server-Side Validation Callback 3.5.6.2 – < 3.6.5.3 Fixed in 3.6.5.3 CVE-2026-19860 WPScan
4.3 Medium Nimble Builder Plugin Information Disclosure Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins ≤ 3.3.8 CVE-2026-16557 WPScan
6.1 Medium Pochipp Plugin pochipp Cross-Site Scripting Reflected Cross-Site Scripting via 'keyword' Parameter No login needed ≤ 1.20.2 CVE-2026-92967 Wordfence
4.4 Medium WP2Social Auto Publish Plugin facebook-auto-publish Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter ≤ 2.4.12 CVE-2026-12042 Wordfence
5.3 Medium Better Messages Plugin bp-better-messages Information Disclosure Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register No login needed ≤ 2.15.33 CVE-2026-89093 Wordfence
6.1 Medium Tutor LMS Plugin tutor Cross-Site Scripting Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters No login needed ≤ 4.0.8 CVE-2026-89081 Wordfence
6.5 Medium Better Messages Plugin bp-better-messages Broken Access Control Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint ≤ 2.15.33 CVE-2026-89334 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter ≤ 4.0.8 CVE-2026-88944 Wordfence
6.5 Medium Divi Essentials Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action ≤ 5.8.1 CVE-2026-15760 Wordfence
4.3 Medium SEO Booster Plugin seo-booster Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() ≤ 7.4.7 CVE-2026-15660 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter ≤ 4.0.8 CVE-2026-89333 Wordfence
6.4 Medium WPComplete Plugin wpcomplete Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute ≤ 2.9.9.0 CVE-2026-77820 Wordfence
6.4 Medium Popup Maker Plugin popup-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via post_title ≤ 1.24.0 CVE-2026-15797 Wordfence
5.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint ≤ 10.8.1 CVE-2026-90884 Wordfence
4.4 Medium CSS & JavaScript Toolbox Plugin css-javascript-toolbox Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields ≤ 12.0.6 CVE-2025-13533 Wordfence
6.1 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 1.11 CVE-2026-92249 Wordfence
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute ≤ 1.8.44 CVE-2026-85652 Wordfence
4.3 Medium WP Easy Pay Plugin wp-easy-pay Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 4.5.0 CVE-2026-12739 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only