WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,151–5,200 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 104 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control No login needed < 6.6.0 Fixed in 6.6.0 CVE-2026-25440 Patchstack
7.5 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-25425 Patchstack
8.5 High PowerPress Podcasting Plugin powerpress SQL Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-24637 Patchstack
7.1 High Redirection for Contact Form 7 Plugin wpcf7-redirect Cross-Site Scripting No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-23970 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
6.5 Medium Bookify Plugin bookify Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-69332 Patchstack
7.1 High Eli's WordCents adSense Widget with Analytics Plugin wordcents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.03.27 CVE-2025-68872 Patchstack
7.1 High Okay Toolkit Plugin okay-toolkit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-68851 Patchstack
7.1 High iRobots.txt SEO Plugin irobotstxt-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-68840 Patchstack
6.3 Medium bunny.net Plugin bunnycdn Broken Access Control ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68049 Patchstack
4.4 Medium PopAd Plugin popad Server-Side Request Forgery ≤ 1.0.4 CVE-2025-60175 Patchstack
7.5 High Projectopia Plugin projectopia-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.25.2 CVE-2025-59133 Patchstack
6.5 Medium Elizaibots Plugin elizaibot-chatbots Cross-Site Scripting ≤ 1.0.2 CVE-2025-15659 Patchstack
5.9 Medium WP Emmet Plugin wp-emmet Cross-Site Scripting ≤ 0.3.4 CVE-2025-15658 Patchstack
6.5 Medium MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control No login needed < 4.7.16 Fixed in 4.7.16 CVE-2025-64215 Patchstack
7.5 High GetPaid Plugin invoicing Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.49 Fixed in 2.8.50 CVE-2026-49064 Patchstack
6.5 Medium Really Simple SSL Plugin really-simple-ssl Broken Access Control ≤ 9.5.9 Fixed in 9.5.10 CVE-2026-48969 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
8.8 High Faust.js Plugin faustwp Authentication Bypass Broken Authentication ≤ 1.8.7 Fixed in 1.8.8 CVE-2026-49062 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack
7.1 High Sliced Invoices Plugin sliced-invoices SQL Injection WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter 3.8.2 CVE-2019-25746 VulnCheck
9.8 Critical Baggage Freight Shipping Australia Plugin baggage-freight Arbitrary File Upload WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload No login needed 0.1.0 CVE-2018-25436 VulnCheck
6.2 Medium Abtest Plugin Local File Inclusion WordPress Plugin Abtest Local File Inclusion via abtest_admin.php No login needed 1.0.6 CVE-2016-20082 VulnCheck
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
6.2 Medium Brandfolder Plugin brandfolder Local File Inclusion WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php No login needed ≤ 3.0 CVE-2016-20080 VulnCheck
6.2 Medium Dharma Booking Plugin dharma-booking Local File Inclusion WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php No login needed ≤ 2.28.3 CVE-2016-20079 VulnCheck
6.2 Medium IMDb Profile Widget Plugin imdb-widget Local File Inclusion WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php No login needed 1.0.8 CVE-2016-20078 VulnCheck
6.2 Medium Photocart Link Plugin photocart-link Local File Inclusion WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php No login needed 1.6 CVE-2016-20077 VulnCheck
8.2 High Answer My Question Plugin answer-my-question SQL Injection Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php No login needed 1.3 CVE-2016-20073 VulnCheck
8.2 High BBS e-Franchise Plugin bbs-e-franchise SQL Injection BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid No login needed 1.1.1 CVE-2016-20072 VulnCheck
8.2 High 404 Redirection Manager Plugin 404-redirection-manager SQL Injection WordPress 404 Redirection Manager Plugin 1.0 SQL Injection No login needed 1.0 CVE-2016-20071 VulnCheck
5.4 Medium Form Builder CP Plugin cp-easy-form-builder Cross-Site Scripting Editor+ Stored XSS via form_structure < 1.2.47 Fixed in 1.2.47 CVE-2026-9278 WPScan
9.8 Critical Advanced Google Maps Plugin Privilege Escalation Unauthenticated Administrator Account Creation No login needed < 6.1.1 Fixed in 6.1.1 CVE-2026-8935 WPScan
5.3 Medium WP Go Maps Plugin wp-google-maps Information Disclosure Unauthenticated Sensitive Information Disclosure via Marker ID No login needed < 10.0.10 Fixed in 10.0.10 CVE-2026-8386 WPScan
5.3 Medium WP Go Maps Plugin wp-google-maps Information Disclosure Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback No login needed < 10.0.10 Fixed in 10.0.10 CVE-2026-8385 WPScan
5.4 Medium Iptanus File Upload Plugin wp-file-upload Arbitrary File Upload File Overwrite via Race Condition < 5.1.7 Fixed in 5.1.7 CVE-2025-15546 WPScan
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
4.3 Medium Meow Gallery Plugin meow-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Shortcode creation ≤ 5.4.4 CVE-2026-1291 Wordfence
6.4 Medium Canvas Plugin canvas Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute ≤ 2.5.2 CVE-2026-9629 Wordfence
4.3 Medium Pagelayer Plugin pagelayer Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' ≤ 2.0.9 CVE-2026-2470 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block ≤ 2.0.9 CVE-2026-3297 Wordfence
6.4 Medium Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter ≤ 3.1.31 CVE-2026-9134 Wordfence
3.4 Low Agile Store Locator Plugin agile-store-locator Path Traversal Admin+ Arbitrary File Read via Path Traversal < 1.6.9 Fixed in 1.6.9 CVE-2026-9062 WPScan
3.5 Low Agile Store Locator Plugin agile-store-locator Cross-Site Scripting Admin+ Stored XSS via logo_name < 1.6.9 Fixed in 1.6.9 CVE-2026-9061 WPScan
7.2 High GPTranslate Plugin gptranslate Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage No login needed ≤ 2.31 CVE-2026-9109 Wordfence
7.5 High WP Ticket Plugin wp-ticket SQL Injection Unauthenticated SQL Injection via WordPress Search 's' Parameter No login needed ≤ 6.0.4 CVE-2026-9848 Wordfence
4.9 Medium WS Optimize – All-in-One Speed Booster & Cache Tools Plugin lws-optimize Path Traversal All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read ≤ 3.3.19 CVE-2026-12089 Wordfence
4.3 Medium Hash Elements Plugin hash-elements Information Disclosure Sensitive Data Exposure ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-24618 Patchstack
3.5 Low Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter < 5.1.5 Fixed in 5.1.5 CVE-2026-9269 WPScan
6.4 Medium The Ultimate Video Player Plugin presto-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute ≤ 4.2.0 CVE-2026-9125 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only