WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 5,401–5,450 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Advanced Access Manager | Authentication Bypass Bypass Vulnerability No login needed |
≤ 7.1.0 Fixed in 7.1.1 |
CVE-2026-42674 |
Patchstack | |
| 7.3 High | Hydra Booking | Broken Access Control No login needed |
≤ 1.1.41 Fixed in 1.1.42 |
CVE-2026-42675 |
Patchstack | |
| 6.5 Medium | myCred | Cross-Site Scripting |
≤ 3.0.4 Fixed in 3.0.5 |
CVE-2026-42676 |
Patchstack | |
| 7.5 High | WP Document Revisions | Broken Access Control No login needed |
< 4.0.0 Fixed in 4.0.0 |
CVE-2026-42677 |
Patchstack | |
| 7.1 High | GiveWP | Cross-Site Scripting No login needed |
≤ 4.14.5 Fixed in 4.14.6 |
CVE-2026-42678 |
Patchstack | |
| 6.5 Medium | Classified Listing | Path Traversal Arbitrary File Download |
≤ 5.3.8 Fixed in 5.3.9 |
CVE-2026-42679 |
Patchstack | |
| 9.8 Critical | Contest Gallery Pro | Privilege Escalation No login needed |
≤ 29.0.1 Fixed in 29.0.2 |
CVE-2026-42680 |
Patchstack | |
| 7.1 High | e2pdf | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.32.14 Fixed in 1.32.15 |
CVE-2026-42681 |
Patchstack | |
| 9.1 Critical | wpForo Forum | Broken Access Control No login needed |
≤ 3.0.6 Fixed in 3.0.7 |
CVE-2026-42682 |
Patchstack | |
| 7.1 High | VikBooking Hotel Booking Engine & PMS | Cross-Site Scripting No login needed |
≤ 1.8.8 Fixed in 1.8.9 |
CVE-2026-42683 |
Patchstack | |
| 7.1 High | WP Statistics | Cross-Site Scripting No login needed |
≤ 14.16.6 Fixed in 14.16.7 |
CVE-2026-48839 |
Patchstack | |
| 7.1 High | LearnPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.3.6 Fixed in 4.3.7 |
CVE-2026-48865 |
Patchstack | |
| 9.6 Critical | Gravity Forms | Arbitrary File Deletion No login needed |
≤ 2.10.0.1 Fixed in 2.10.1 |
CVE-2026-48866 |
Patchstack | |
| 9.8 Critical | AIWU | Privilege Escalation No login needed |
≤ 1.4.17 Fixed in 1.4.19 |
CVE-2026-48879 |
Patchstack | |
| 5.3 Medium | Advanced Custom Fields (ACF®) | Broken Access Control Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters No login needed |
≤ 6.8.1 |
CVE-2026-8382 |
Wordfence | |
| 8.8 High | Spectra Gutenberg Blocks | Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes |
≤ 2.19.25 |
CVE-2026-7465 |
Wordfence | |
| 7.5 High | Simple History – Track, Log, and Audit WordPress Changes | Privilege Escalation Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpoint |
≤ 5.26.0 |
CVE-2026-7459 |
Wordfence | |
| 7.5 High | GEO my WP | SQL Injection Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters No login needed |
≤ 4.5.5 |
CVE-2026-9757 |
Wordfence | |
| 9.1 Critical | WP Travel Pro | Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators No login needed |
≤ 10.6.0 |
CVE-2026-4290 |
Wordfence | |
| 5.3 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification No login needed |
≤ 1.0.271 |
CVE-2025-12714 |
Wordfence | |
| 5.3 Medium | Contact Form 7 – PayPal & Stripe Add-on | Price Manipulation PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification) No login needed |
≤ 2.4.9 |
CVE-2026-9189 |
Wordfence | |
| 4.9 Medium | Frontend Admin by DynamiApps | SQL Injection Authenticated (Administrator+) SQL Injection via 'order' Parameter |
≤ 3.28.8 |
CVE-2026-10039 |
Wordfence | |
| 8.1 High | Media Library Assistant | Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed |
≤ 3.35 |
CVE-2026-6075 |
Wordfence | |
| 7.2 High | Link Whisper Free | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 0.9.0 |
CVE-2025-11262 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter |
≤ 6.4.15 |
CVE-2026-9243 |
Wordfence | |
| 9.8 Critical | OTP Login With Phone Number, OTP Verification | Authentication Bypass Unauthenticated Authentication Bypass via Firebase OTP Verification No login needed |
1.8.50 – 1.8.60 |
CVE-2026-3655 |
Wordfence | |
| 6.4 Medium | Simple Divi Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.2 |
CVE-2026-9714 |
Wordfence | |
| 6.4 Medium | Automotive Car Dealership Business | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details |
≤ 13.4.1 |
CVE-2025-14042 |
Wordfence | |
| 9.8 Critical | WP Maps Pro | Privilege Escalation Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action No login needed |
≤ 6.0.4 |
CVE-2026-8732 |
Wordfence | |
| 8.8 High | WooCommerce Infinite Scroll and Ajax Pagination | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.8 |
CVE-2025-11993 |
Wordfence | |
| 6.4 Medium | StatCounter | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Author Nickname |
≤ 2.1.1 |
CVE-2026-6275 |
Wordfence | |
| 5.3 Medium | Breeze Cache | Information Disclosure Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie No login needed |
≤ 2.5.2 |
CVE-2026-2128 |
Wordfence | |
| 4.3 Medium | Poll Maker by AYS | Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action |
≤ 6.3.7 |
CVE-2026-8995 |
Wordfence | |
| 4.4 Medium | Post Snippets | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import |
≤ 4.0.19 |
CVE-2026-7430 |
Wordfence | |
| 9.8 Critical | Advanced Custom Fields: Extended | Privilege Escalation Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter No login needed |
≤ 0.9.2.5 |
CVE-2026-8809 |
Wordfence | |
| 8.8 High | Frontend Admin by DynamiApps | Privilege Escalation Unauthenticated Privilege Escalation via Form Configuration Injection |
≤ 3.29.2 |
CVE-2026-6226 |
Wordfence | |
| 6.4 Medium | Shariff Wrapper | Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting |
≤ 4.6.20 |
CVE-2026-4334 |
Wordfence | |
| 4.3 Medium | Equalize Digital Accessibility Checker | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Accessibility Issue Modification via edac_insert_ignore_data AJAX Action |
≤ 1.42.0 |
CVE-2026-9015 |
Wordfence | |
| 4.3 Medium | Visualizer: Tables and Charts Manager | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions |
≤ 3.11.14 |
CVE-2026-8689 |
Wordfence | |
| 5.3 Medium | Appointment Booking Calendar | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint No login needed |
≤ 1.6.11.8 |
CVE-2026-6937 |
Wordfence | |
| 6.5 Medium | Photo Gallery by 10Web | SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute |
≤ 1.8.40 |
CVE-2026-7048 |
Wordfence | |
| 4.3 Medium | PDF Embedder | Information Disclosure Authenticated (Contributor+) Information Exposure via Block Editor Page |
≤ 4.9.3 |
CVE-2026-7526 |
Wordfence | |
| 7.2 High | HT Contact Form | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload Field No login needed |
≤ 2.8.2 |
CVE-2026-7052 |
Wordfence | |
| 4.3 Medium | 3D Viewer | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via settings REST endpoint |
≤ 2.0.1 |
CVE-2026-8682 |
Wordfence | |
| 7.5 High | Appointment Booking Calendar | SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed |
≤ 1.6.11.8 |
CVE-2026-7797 |
Wordfence | |
| 6.1 Medium | Easy Updates Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'paged' Parameter No login needed |
≤ 9.0.20 |
CVE-2026-7660 |
Wordfence | |
| 4.3 Medium | SMTP2GO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Read/Truncate |
≤ 1.16.0 |
CVE-2026-7621 |
Wordfence | |
| 8.1 High | WP Contact Form 7 DB Handler | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed |
≤ 3.0 |
CVE-2026-6455 |
Wordfence | |
| 5.3 Medium | Geo Mashup | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter No login needed |
≤ 1.13.19 |
CVE-2026-7552 |
Wordfence | |
| 6.4 Medium | a3 Lazy Load | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Element |
≤ 2.7.6 |
CVE-2026-6427 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.