WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,951–5,000 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 100 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical InPost Gallery Plugin inpost-gallery SQL Injection No login needed ≤ 2.1.4.6 Fixed in 2.1.5 CVE-2026-39574 Patchstack
7.5 High JupiterX Core Plugin jupiterx-core Broken Access Control No login needed ≤ 4.14.1 Fixed in 4.14.2 CVE-2026-39490 Patchstack
7.1 High Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.2 Fixed in 5.2.3 CVE-2026-39437 Patchstack
7.5 High WP Event SOlution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.12 Fixed in 4.1.13 CVE-2025-68045 Patchstack
6.4 Medium File Sharing & Download Manager Plugin user-private-files Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter ≤ 2.1.6 CVE-2026-10093 Wordfence
8.8 High WP Review Slider Pro Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via 'curselrevs' Parameter ≤ 12.6.8 CVE-2026-8444 Wordfence
8.8 High WP Review Slider Pro Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via 'stypes' Parameter ≤ 12.6.8 CVE-2026-8443 Wordfence
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter ≤ 2.0.7 CVE-2026-5149 Wordfence
4.3 Medium Static Block Plugin static-block Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' Attribute ≤ 2.2 CVE-2026-10780 Wordfence
8.8 High Premmerce Dev Tools Plugin premmerce-dev-tools Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation ≤ 2.0 CVE-2026-6933 Wordfence
5.3 Medium Abandoned Contact Form 7 Plugin abandoned-contact-form-7 Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter No login needed ≤ 2.2 CVE-2026-9187 Wordfence
5.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Broken Access Control Missing Authorization to Unauthenticated Zoom SDK Credential Exposure via 'get_auth' AJAX Action No login needed ≤ 4.6.7 CVE-2026-6964 Wordfence
9.6 Critical FastDup Plugin fastdup Path Traversal No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2026-52703 Patchstack
7.1 High SEO Redirection Plugin seo-redirection Cross-Site Scripting No login needed ≤ 9.17 Fixed in 9.18 CVE-2026-52702 Patchstack
8.5 High WCMultiShipping Plugin wc-multishipping SQL Injection ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-52700 Patchstack
7.5 High VikRentCar Plugin vikrentcar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-52699 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 5.0.7 Fixed in 5.0.8 CVE-2026-52697 Patchstack
7.5 High ABC Crypto Checkout Plugin payerurl-crypto-currency-payment-gateway-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-52695 Patchstack
7.5 High Signature Add-On for WooCommerce Plugin woocommerce-digital-signature Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-52694 Patchstack
9.3 Critical eCommerce Product Catalog Plugin ecommerce-product-catalog SQL Injection No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2026-52693 Patchstack
7.5 High Affiliates Manager Plugin affiliates-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 2.9.50 Fixed in 2.9.51 CVE-2026-52692 Patchstack
9.8 Critical OttoKit Plugin suretriggers PHP Object Injection No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2026-49781 Patchstack
8.8 High Dokan Plugin dokan-lite Privilege Escalation ≤ 5.0.2 Fixed in 5.0.3 CVE-2026-49780 Patchstack
9.3 Critical GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites Plugin gptranslate SQL Injection Multilingual AI Translation for WordPress: Automatically Translate Websites plugin <= 2.32.6 - SQL Injection No login needed ≤ 2.32.6 Fixed in 2.32.7 CVE-2026-49776 Patchstack
6.5 Medium Welcart e-Commerce Plugin usc-e-shop Broken Access Control No login needed ≤ 2.11.28 Fixed in 2.11.29 CVE-2026-49775 Patchstack
6.5 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting < 7.5.51.7212 Fixed in 7.5.51.7212 CVE-2026-49773 Patchstack
9.8 Critical WP Travel Engine Plugin wp-travel-engine PHP Object Injection No login needed ≤ 6.7.12 Fixed in 6.8.0 CVE-2026-49770 Patchstack
9.8 Critical wpForo Forum Plugin wpforo PHP Object Injection No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-49769 Patchstack
9.8 Critical Happyforms Plugin happyforms PHP Object Injection No login needed ≤ 1.26.13 Fixed in 1.26.14 CVE-2026-49768 Patchstack
9.9 Critical WP User Manager Plugin wp-user-manager Arbitrary File Deletion ≤ 2.9.16 Fixed in 2.9.17 CVE-2026-49766 Patchstack
9.8 Critical Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp PHP Object Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2026-49765 Patchstack
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.8.6 Fixed in 6.0.8.7 CVE-2026-49764 Patchstack
9.8 Critical Integration for Contact Form 7 HubSpot Plugin cf7-hubspot PHP Object Injection No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2026-49763 Patchstack
7.5 High Shared Files Plugin shared-files Path Traversal No login needed ≤ 1.7.64 Fixed in 1.7.65 CVE-2026-49112 Patchstack
7.5 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Price Manipulation No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2026-49110 Patchstack
9.8 Critical Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-49109 Patchstack
9.8 Critical Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact PHP Object Injection No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2026-49106 Patchstack
9.8 Critical WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49105 Patchstack
9.8 Critical Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-infusionsoft PHP Object Injection No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2026-49104 Patchstack
9.8 Critical WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49085 Patchstack
7.5 High LatePoint Plugin latepoint Privilege Escalation ≤ 5.5.1 Fixed in 5.5.2 CVE-2026-49083 Patchstack
7.4 High Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons Plugin chatway-live-chat Information Disclosure AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin <= 1.4.8 - Sensitive Data Exposure ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-49082 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Other Other Vulnerability Type No login needed ≤ 6.7.10 Fixed in 6.7.11 CVE-2026-49078 Patchstack
7.5 High Knit Pay Plugin knit-pay Broken Access Control No login needed ≤ 9.4.0.0 Fixed in 9.4.0.1 CVE-2026-49070 Patchstack
7.5 High Coupon Affiliates Plugin woo-coupon-usage Information Disclosure Sensitive Data Exposure No login needed ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-49068 Patchstack
9.3 Critical Advanced 301 and 302 Redirect Plugin advanced-301-and-302-redirect SQL Injection No login needed ≤ 1.6.9 Fixed in 1.7.0 CVE-2026-49067 Patchstack
7.5 High Conekta Payment Gateway Plugin conekta-payment-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-49066 Patchstack
8.2 High Hippoo Mobile App for WooCommerce Plugin hippoo Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-49065 Patchstack
7.3 High Listdom Plugin listdom Privilege Escalation No login needed ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-49063 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Path Traversal Arbitrary File Download No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2026-49061 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only