WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84753 Patchstack
8.8 High RTMKit Plugin rometheme-for-elementor PHP Object Injection ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84752 Patchstack
9.8 Critical YITH Request a Quote for WooCommerce Premium Plugin yith-woocommerce-request-a-quote-premium Broken Access Control No login needed < 4.46.0 Fixed in 4.46.0 CVE-2026-84238 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2026-84215 Patchstack
7.1 High WP QuickLaTeX Plugin wp-quicklatex Cross-Site Scripting No login needed ≤ 3.8.8 CVE-2026-81776 Patchstack
7.1 High Ninja Forms File Uploads Extension Plugin ninja-forms-uploads Arbitrary File Upload Cross Site Scripting (XSS) No login needed ≤ 3.3.26 CVE-2026-81773 Patchstack
7.1 High Calculation For Contact Form 7 Plugin calculation-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-81300 Patchstack
7.1 High Under Construction Plugin under-construction-page Cross-Site Scripting No login needed ≤ 5.82 Fixed in 5.83 CVE-2026-81295 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-81292 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Graphene Theme graphene Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.6 CVE-2026-81281 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.8 Medium Enfold Theme enfold Cross-Site Scripting No login needed ≤ 8.0 Fixed in 8.1 CVE-2026-84815 Patchstack
6.4 Medium SEOWriting Plugin seowriting Cross-Site Scripting SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload ≤ 1.12.5 CVE-2026-75134 VulnCheck
5.3 Medium Notification Bar Plugin Information Disclosure Unauthenticated Subscriber Data Disclosure No login needed ≤ 1.1.8 CVE-2025-15481 WPScan
5.4 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 6.1.3 Fixed in 6.1.5 CVE-2026-84217 Patchstack
5.3 Medium Rentsyst Plugin rentsyst Broken Access Control No login needed ≤ 2.1.5 CVE-2026-84835 Patchstack
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.3 Medium WP Go Maps Plugin wp-google-maps Denial of Service Denial of Service Attack No login needed ≤ 10.1.08 Fixed in 10.1.09 CVE-2026-84780 Patchstack
5.3 Medium Really Simple SSL Plugin really-simple-ssl Denial of Service Denial of Service Attack No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84775 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
8.8 High Mang Board WP Plugin mangboard Cross-Site Request Forgery No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2026-84770 Patchstack
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.22 Fixed in 4.1.23 CVE-2026-82223 Patchstack
7.1 High Estatik Plugin estatik Cross-Site Scripting No login needed ≤ 4.3.4 CVE-2026-81775 Patchstack
7.5 High WooCommerce Product Attachment Plugin woo-product-attachment Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-81774 Patchstack
8.8 High Ninja Forms - Layout & Styles Plugin ninja-forms-style PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed ≤ 3.0.31 CVE-2026-81772 Patchstack
7.1 High TrustedSite Plugin trustedsite Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2026-81771 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.30 CVE-2026-81770 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.1 CVE-2026-81769 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.1 Fixed in 3.15.2 CVE-2026-81294 Patchstack
7.1 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting No login needed ≤ 5.13.1 Fixed in 5.14 CVE-2026-81289 Patchstack
7.1 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-81288 Patchstack
9.3 Critical WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2026-81286 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
8.8 High WP User Frontend Plugin wp-user-frontend PHP Object Injection ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-81283 Patchstack
7.1 High Login With Ajax Plugin login-with-ajax Cross-Site Scripting No login needed ≤ 4.5.1 CVE-2026-82883 Patchstack
9.8 Critical Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter No login needed ≤ 1.6.6 CVE-2026-18550 Wordfence
10.0 Critical Newspapers X Theme newspapers-x Other Backdoor No login needed 1.0.46 – 1.0.48 Fixed in 1.0.49 CVE-2026-81779 Patchstack
5.4 Medium Post SMTP Plugin post-smtp Broken Access Control Settings Change 4.0.0 – beta.1 Fixed in 4.0.1 CVE-2026-81278 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.2 Fixed in 7.9.0 CVE-2026-82229 Patchstack
8.1 High SiteGround Security Plugin sg-security Authentication Bypass WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-82228 Patchstack
9.8 Critical Tickera Plugin tickera-event-ticketing-system PHP Object Injection No login needed ≤ 3.6.0.2 Fixed in 3.6.0.3 CVE-2026-82226 Patchstack
7.4 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82225 Patchstack
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2026-82224 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82221 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only