WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 5,301–5,350 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | MDJM Event Management | Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter |
≤ 1.7.8.3 |
CVE-2026-7537 |
Wordfence | |
| 6.1 Medium | Ad Inserter | Cross-Site Scripting Reflected Cross-Site Scripting via URL Parameters in iframe Mode No login needed |
≤ 2.8.15 |
CVE-2026-9280 |
Wordfence | |
| 6.6 Medium | LearnPress – Backup & Migration Tool | PHP Object Injection Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload |
≤ 4.1.4 |
CVE-2026-7566 |
Wordfence | |
| 4.9 Medium | LearnPress | Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter |
≤ 4.1.4 |
CVE-2026-7565 |
Wordfence | |
| 4.9 Medium | Smart Slider 3 | Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export |
≤ 3.5.1.36 |
CVE-2026-9197 |
Wordfence | |
| 4.4 Medium | Drag and Drop Multiple File Upload for Contact Form 7 | Arbitrary File Upload Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings |
≤ 1.3.9.7 |
CVE-2026-8991 |
Wordfence | |
| 7.2 High | Integration for Freshsales | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Submission Data No login needed |
≤ 1.0.15 |
CVE-2026-8901 |
Wordfence | |
| 7.2 High | All-In-One Security (AIOS) | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API Request Path No login needed |
≤ 5.4.7 |
CVE-2026-8438 |
Wordfence | |
| 6.4 Medium | Master Addons For Elementor | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) |
≤ 3.1.0 |
CVE-2026-9281 |
Wordfence | |
| 4.3 Medium | Page-list | Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes |
≤ 6.2 |
CVE-2026-9008 |
Wordfence | |
| 4.3 Medium | RSS Aggregator by Feedzy | Broken Access Control Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions |
≤ 5.1.7 |
CVE-2026-8976 |
Wordfence | |
| 4.3 Medium | LatePoint | Cross-Site Request Forgery Cross-Site Request Forgery via invoices__change_status Action No login needed |
≤ 5.6.0 |
CVE-2026-9719 |
Wordfence | |
| 5.3 Medium | Event Monster | Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-8608 |
Wordfence | |
| 4.9 Medium | Quiz and Survey Master (QSM) | SQL Injection Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters |
≤ 11.1.2 |
CVE-2026-6448 |
Wordfence | |
| 4.3 Medium | Charitable | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter |
≤ 1.8.11.1 |
CVE-2026-10038 |
Wordfence | |
| 7.5 High | WP User Manager | Path Traversal Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter No login needed |
≤ 2.9.17 |
CVE-2026-9290 |
Wordfence | |
| 6.4 Medium | Simple SEO Slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.2.8 |
CVE-2026-8900 |
Wordfence | |
| 4.3 Medium | Frontend User Notes | Cross-Site Request Forgery Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action No login needed |
≤ 2.1.1 |
CVE-2026-7047 |
Wordfence | |
| 3.8 Low | Migration, Backup, Staging – WPvivid Backup & Migration | Arbitrary File Deletion WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion |
≤ 0.9.128 |
CVE-2025-12656 |
Wordfence | |
| 6.4 Medium | Express Payment For Stripe | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.28.0 |
CVE-2026-8893 |
Wordfence | |
| 4.3 Medium | Alba Board | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter |
≤ 2.1.3 |
CVE-2026-7523 |
Wordfence | |
| 8.8 High | Admin Columns | PHP Object Injection Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value |
≤ 7.0.18 |
CVE-2026-7654 |
Wordfence | |
| 8.8 High | WP Captcha PRO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload |
≤ 5.38 |
CVE-2026-5411 |
Wordfence | |
| 9.8 Critical | Hippoo Mobile App for WooCommerce | Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API No login needed |
≤ 1.9.4 |
CVE-2026-10580 |
Wordfence | |
| 8.8 High | WP Captcha PRO | Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link |
≤ 5.38 |
CVE-2026-5415 |
Wordfence | |
| 10.0 Critical | Product Slider Pro for WooCommerce | Other Backdoor No login needed |
< 3.5.4 Fixed in 3.5.4 |
CVE-2026-49777 |
Patchstack | |
| 7.2 High | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed |
≤ 6.1.3 |
CVE-2026-10586 |
Wordfence | |
| 8.2 High | Google Review Slider | SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed |
6.1 |
CVE-2019-25745 |
VulnCheck | |
| 5.4 Medium | Popup Builder | Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting |
3.49 |
CVE-2019-25744 |
VulnCheck | |
| 5.4 Medium | Soliloquy Lite | Cross-Site Scripting WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting |
2.5.6 |
CVE-2019-25743 |
VulnCheck | |
| 5.4 Medium | Zoner Real Estate | Cross-Site Scripting WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS |
4.1.1 |
CVE-2019-25742 |
VulnCheck | |
| 4.0 Medium | Contact Form Maker | Cross-Site Request Forgery Contact Form by WD 1.13.1 CSRF to Local File Inclusion No login needed |
1.13.1 |
CVE-2019-25734 |
VulnCheck | |
| 9.8 Critical | Ad Manager WD | Path Traversal WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download No login needed |
1.0.11 |
CVE-2019-25727 |
VulnCheck | |
| 5.3 Medium | WP eMember | Information Disclosure Sensitive Data Exposure No login needed |
≤ v10.2.2 |
CVE-2026-49077 |
Patchstack | |
| 7.6 High | Photo Gallery by 10Web | SQL Injection |
≤ 1.8.41 Fixed in 1.8.42 |
CVE-2026-49771 |
Patchstack | |
| 6.5 Medium | MasterStudy LMS Pro Plus | SQL Injection Authenticated (Instructor+) SQL Injection via 'columns' Parameter |
≤ 4.8.20 |
CVE-2026-8653 |
Wordfence | |
| 7.5 High | SP Project & Document Manager | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function No login needed |
≤ 4.71 |
CVE-2026-10737 |
Wordfence | |
| 8.8 High | School Management | Privilege Escalation |
≤ 93.2.0 |
CVE-2025-15656 |
Patchstack | |
| 7.6 High | School Management | SQL Injection |
≤ 93.2.0 |
CVE-2025-15655 |
Patchstack | |
| 7.1 High | Prague | Cross-Site Scripting No login needed |
≤ 2.2.8 Fixed in 2.2.9 |
CVE-2025-15654 |
Patchstack | |
| 4.3 Medium | EmergencyWP | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.4.2 |
CVE-2026-9732 |
Wordfence | |
| 4.4 Medium | Passeum Ticketing | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting |
≤ 1.0 |
CVE-2026-7421 |
Wordfence | |
| 7.5 High | ARMember Premium | SQL Injection Unauthenticated SQL Injection via 'order' Parameter No login needed |
≤ 7.3.1 |
CVE-2026-5073 |
Wordfence | |
| 9.8 Critical | ARMember Premium | Privilege Escalation Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation No login needed |
≤ 7.3.1 |
CVE-2026-5076 |
Wordfence | |
| 6.5 Medium | ARMember Premium | SQL Injection Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter |
≤ 7.3.1 |
CVE-2026-5074 |
Wordfence | |
| 8.8 High | Content Visibility for Divi Builder | Remote Code Execution Authenticated (Contributor+) Remote Code Execution |
≤ 4.02 |
CVE-2026-1829 |
Wordfence | |
| 7.5 High | BookIt | Authentication Bypass Broken Authentication No login needed |
< 2.5.4.1 Fixed in 2.5.4.1 |
CVE-2026-40780 |
Patchstack | |
| 7.1 High | Wallet System for WooCommerce | Authentication Bypass Broken Authentication |
≤ 2.7.5 Fixed in 2.7.6 |
CVE-2026-42654 |
Patchstack | |
| 5.4 Medium | Elementor Website Builder | Broken Access Control |
≤ 4.1.0 Fixed in 4.1.1 |
CVE-2026-49782 |
Patchstack | |
| 5.4 Medium | Crew HRM | Broken Access Control |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2026-27351 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.