WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,401–5,450 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 109 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Advanced Access Manager Plugin advanced-access-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 7.1.0 Fixed in 7.1.1 CVE-2026-42674 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.1.41 Fixed in 1.1.42 CVE-2026-42675 Patchstack
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-42676 Patchstack
7.5 High WP Document Revisions Plugin wp-document-revisions Broken Access Control No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-42677 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42678 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Path Traversal Arbitrary File Download ≤ 5.3.8 Fixed in 5.3.9 CVE-2026-42679 Patchstack
9.8 Critical Contest Gallery Pro Plugin contest-gallery-pro Privilege Escalation No login needed ≤ 29.0.1 Fixed in 29.0.2 CVE-2026-42680 Patchstack
7.1 High e2pdf Plugin e2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.32.14 Fixed in 1.32.15 CVE-2026-42681 Patchstack
9.1 Critical wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-42682 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.8 Fixed in 1.8.9 CVE-2026-42683 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.6 Fixed in 14.16.7 CVE-2026-48839 Patchstack
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.6 Fixed in 4.3.7 CVE-2026-48865 Patchstack
9.6 Critical Gravity Forms Plugin gravityforms Arbitrary File Deletion No login needed ≤ 2.10.0.1 Fixed in 2.10.1 CVE-2026-48866 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.4.17 Fixed in 1.4.19 CVE-2026-48879 Patchstack
5.3 Medium Advanced Custom Fields (ACF®) Plugin advanced-custom-fields Broken Access Control Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters No login needed ≤ 6.8.1 CVE-2026-8382 Wordfence
8.8 High Spectra Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes ≤ 2.19.25 CVE-2026-7465 Wordfence
7.5 High Simple History – Track, Log, and Audit WordPress Changes Plugin simple-history Privilege Escalation Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpoint ≤ 5.26.0 CVE-2026-7459 Wordfence
7.5 High GEO my WP Plugin geo-my-wp SQL Injection Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters No login needed ≤ 4.5.5 CVE-2026-9757 Wordfence
9.1 Critical WP Travel Pro Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators No login needed ≤ 10.6.0 CVE-2026-4290 Wordfence
5.3 Medium Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification No login needed ≤ 1.0.271 CVE-2025-12714 Wordfence
5.3 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Price Manipulation PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification) No login needed ≤ 2.4.9 CVE-2026-9189 Wordfence
4.9 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element SQL Injection Authenticated (Administrator+) SQL Injection via 'order' Parameter ≤ 3.28.8 CVE-2026-10039 Wordfence
8.1 High Media Library Assistant Plugin media-library-assistant Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed ≤ 3.35 CVE-2026-6075 Wordfence
7.2 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 0.9.0 CVE-2025-11262 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter ≤ 6.4.15 CVE-2026-9243 Wordfence
9.8 Critical OTP Login With Phone Number, OTP Verification Plugin login-with-phone-number Authentication Bypass Unauthenticated Authentication Bypass via Firebase OTP Verification No login needed 1.8.50 – 1.8.60 CVE-2026-3655 Wordfence
6.4 Medium Simple Divi Shortcode Plugin simple-divi-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.2 CVE-2026-9714 Wordfence
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details ≤ 13.4.1 CVE-2025-14042 Wordfence
9.8 Critical WP Maps Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action No login needed ≤ 6.0.4 CVE-2026-8732 Wordfence
8.8 High WooCommerce Infinite Scroll and Ajax Pagination Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.8 CVE-2025-11993 Wordfence
6.4 Medium StatCounter Plugin official-statcounter-plugin-for-wordpress Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Author Nickname ≤ 2.1.1 CVE-2026-6275 Wordfence
5.3 Medium Breeze Cache Plugin breeze Information Disclosure Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie No login needed ≤ 2.5.2 CVE-2026-2128 Wordfence
4.3 Medium Poll Maker by AYS Plugin poll-maker Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action ≤ 6.3.7 CVE-2026-8995 Wordfence
4.4 Medium Post Snippets Plugin post-snippets Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import ≤ 4.0.19 CVE-2026-7430 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter No login needed ≤ 0.9.2.5 CVE-2026-8809 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation via Form Configuration Injection ≤ 3.29.2 CVE-2026-6226 Wordfence
6.4 Medium Shariff Wrapper Plugin shariff Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 4.6.20 CVE-2026-4334 Wordfence
4.3 Medium Equalize Digital Accessibility Checker Plugin accessibility-checker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Accessibility Issue Modification via edac_insert_ignore_data AJAX Action ≤ 1.42.0 CVE-2026-9015 Wordfence
4.3 Medium Visualizer: Tables and Charts Manager Plugin visualizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions ≤ 3.11.14 CVE-2026-8689 Wordfence
5.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint No login needed ≤ 1.6.11.8 CVE-2026-6937 Wordfence
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute ≤ 1.8.40 CVE-2026-7048 Wordfence
4.3 Medium PDF Embedder Plugin pdf-embedder Information Disclosure Authenticated (Contributor+) Information Exposure via Block Editor Page ≤ 4.9.3 CVE-2026-7526 Wordfence
7.2 High HT Contact Form Plugin ht-contactform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload Field No login needed ≤ 2.8.2 CVE-2026-7052 Wordfence
4.3 Medium 3D Viewer Plugin ar-vr-3d-model-try-on Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via settings REST endpoint ≤ 2.0.1 CVE-2026-8682 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.11.8 CVE-2026-7797 Wordfence
6.1 Medium Easy Updates Manager Plugin stops-core-theme-and-plugin-updates Cross-Site Scripting Reflected Cross-Site Scripting via 'paged' Parameter No login needed ≤ 9.0.20 CVE-2026-7660 Wordfence
4.3 Medium SMTP2GO Plugin smtp2go Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Read/Truncate ≤ 1.16.0 CVE-2026-7621 Wordfence
8.1 High WP Contact Form 7 DB Handler Plugin wp-contact-form-7-db-handler Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed ≤ 3.0 CVE-2026-6455 Wordfence
5.3 Medium Geo Mashup Plugin geo-mashup Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter No login needed ≤ 1.13.19 CVE-2026-7552 Wordfence
6.4 Medium a3 Lazy Load Plugin a3-lazy-load Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Element ≤ 2.7.6 CVE-2026-6427 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only