WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,301–5,350 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 107 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High MDJM Event Management Plugin mobile-dj-manager Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter ≤ 1.7.8.3 CVE-2026-7537 Wordfence
6.1 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected Cross-Site Scripting via URL Parameters in iframe Mode No login needed ≤ 2.8.15 CVE-2026-9280 Wordfence
6.6 Medium LearnPress – Backup & Migration Tool Plugin learnpress-import-export PHP Object Injection Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload ≤ 4.1.4 CVE-2026-7566 Wordfence
4.9 Medium LearnPress Plugin learnpress-import-export Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter ≤ 4.1.4 CVE-2026-7565 Wordfence
4.9 Medium Smart Slider 3 Plugin smart-slider-3 Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export ≤ 3.5.1.36 CVE-2026-9197 Wordfence
4.4 Medium Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings ≤ 1.3.9.7 CVE-2026-8991 Wordfence
7.2 High Integration for Freshsales Plugin crm-integration-freshworks-any-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Submission Data No login needed ≤ 1.0.15 CVE-2026-8901 Wordfence
7.2 High All-In-One Security (AIOS) Plugin all-in-one-wp-security-and-firewall Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API Request Path No login needed ≤ 5.4.7 CVE-2026-8438 Wordfence
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) ≤ 3.1.0 CVE-2026-9281 Wordfence
4.3 Medium Page-list Plugin page-list Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes ≤ 6.2 CVE-2026-9008 Wordfence
4.3 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions ≤ 5.1.7 CVE-2026-8976 Wordfence
4.3 Medium LatePoint Plugin latepoint Cross-Site Request Forgery Cross-Site Request Forgery via invoices__change_status Action No login needed ≤ 5.6.0 CVE-2026-9719 Wordfence
5.3 Medium Event Monster Plugin event-monster Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action No login needed ≤ 2.1.0 CVE-2026-8608 Wordfence
4.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters ≤ 11.1.2 CVE-2026-6448 Wordfence
4.3 Medium Charitable Plugin charitable Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter ≤ 1.8.11.1 CVE-2026-10038 Wordfence
7.5 High WP User Manager Plugin wp-user-manager Path Traversal Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter No login needed ≤ 2.9.17 CVE-2026-9290 Wordfence
6.4 Medium Simple SEO Slideshow Plugin simple-seo-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.2.8 CVE-2026-8900 Wordfence
4.3 Medium Frontend User Notes Plugin frontend-user-notes Cross-Site Request Forgery Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action No login needed ≤ 2.1.1 CVE-2026-7047 Wordfence
3.8 Low Migration, Backup, Staging – WPvivid Backup & Migration Plugin wpvivid-backuprestore Arbitrary File Deletion WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion ≤ 0.9.128 CVE-2025-12656 Wordfence
6.4 Medium Express Payment For Stripe Plugin wp-stripe-express Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.28.0 CVE-2026-8893 Wordfence
4.3 Medium Alba Board Plugin alba-board Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter ≤ 2.1.3 CVE-2026-7523 Wordfence
8.8 High Admin Columns Plugin codepress-admin-columns PHP Object Injection Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value ≤ 7.0.18 CVE-2026-7654 Wordfence
8.8 High WP Captcha PRO Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.38 CVE-2026-5411 Wordfence
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API No login needed ≤ 1.9.4 CVE-2026-10580 Wordfence
8.8 High WP Captcha PRO Plugin Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link ≤ 5.38 CVE-2026-5415 Wordfence
10.0 Critical Product Slider Pro for WooCommerce Plugin woo-product-slider-pro Other Backdoor No login needed < 3.5.4 Fixed in 3.5.4 CVE-2026-49777 Patchstack
7.2 High Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed ≤ 6.1.3 CVE-2026-10586 Wordfence
8.2 High Google Review Slider Plugin wp-google-places-review-slider SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed 6.1 CVE-2019-25745 VulnCheck
5.4 Medium Popup Builder Plugin popup-builder Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting 3.49 CVE-2019-25744 VulnCheck
5.4 Medium Soliloquy Lite Plugin soliloquy-lite Cross-Site Scripting WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting 2.5.6 CVE-2019-25743 VulnCheck
5.4 Medium Zoner Real Estate Theme Cross-Site Scripting WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS 4.1.1 CVE-2019-25742 VulnCheck
4.0 Medium Contact Form Maker Plugin contact-form-maker Cross-Site Request Forgery Contact Form by WD 1.13.1 CSRF to Local File Inclusion No login needed 1.13.1 CVE-2019-25734 VulnCheck
9.8 Critical Ad Manager WD Plugin Path Traversal WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download No login needed 1.0.11 CVE-2019-25727 VulnCheck
5.3 Medium WP eMember Plugin wp-emember Information Disclosure Sensitive Data Exposure No login needed ≤ v10.2.2 CVE-2026-49077 Patchstack
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
6.5 Medium MasterStudy LMS Pro Plus Plugin SQL Injection Authenticated (Instructor+) SQL Injection via 'columns' Parameter ≤ 4.8.20 CVE-2026-8653 Wordfence
7.5 High SP Project & Document Manager Plugin sp-client-document-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function No login needed ≤ 4.71 CVE-2026-10737 Wordfence
8.8 High School Management Plugin school-management Privilege Escalation ≤ 93.2.0 CVE-2025-15656 Patchstack
7.6 High School Management Plugin school-management SQL Injection ≤ 93.2.0 CVE-2025-15655 Patchstack
7.1 High Prague Plugin prague-plugins Cross-Site Scripting No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-15654 Patchstack
4.3 Medium EmergencyWP Plugin emergencywp Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4.2 CVE-2026-9732 Wordfence
4.4 Medium Passeum Ticketing Plugin passeum-ticketing Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting ≤ 1.0 CVE-2026-7421 Wordfence
7.5 High ARMember Premium Plugin SQL Injection Unauthenticated SQL Injection via 'order' Parameter No login needed ≤ 7.3.1 CVE-2026-5073 Wordfence
9.8 Critical ARMember Premium Plugin Privilege Escalation Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation No login needed ≤ 7.3.1 CVE-2026-5076 Wordfence
6.5 Medium ARMember Premium Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter ≤ 7.3.1 CVE-2026-5074 Wordfence
8.8 High Content Visibility for Divi Builder Plugin content-visibility-for-divi-builder Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 4.02 CVE-2026-1829 Wordfence
7.5 High BookIt Plugin bookit Authentication Bypass Broken Authentication No login needed < 2.5.4.1 Fixed in 2.5.4.1 CVE-2026-40780 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
5.4 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2026-49782 Patchstack
5.4 Medium Crew HRM Plugin hr-management Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-27351 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only