WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Hot Coffee Theme hot-coffee PHP Object Injection No login needed ≤ 1.7 CVE-2025-69108 Patchstack
9.8 Critical Fusion Builder Plugin fusion-builder PHP Object Injection No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-54194 Patchstack
9.9 Critical Kids Online Store Theme kids-online-store Arbitrary File Upload ≤ 0.8.9 Fixed in 0.9.0 CVE-2026-40750 Patchstack
9.3 Critical The Events Calendar Plugin the-events-calendar SQL Injection No login needed 6.15.12 – 6.16.2 Fixed in 6.16.3 CVE-2026-49772 Patchstack
9.9 Critical RD Station Plugin integracao-rd-station Remote Code Execution ≤ 5.6.0 Fixed in 5.7.0 CVE-2026-49774 Patchstack
9.3 Critical GEO my Plugin geo-my-wp SQL Injection No login needed ≤ 4.5.5 Fixed in 4.5.5.1 CVE-2026-52715 Patchstack
9.3 Critical InPost Gallery Plugin inpost-gallery SQL Injection No login needed ≤ 2.1.4.6 Fixed in 2.1.5 CVE-2026-39574 Patchstack
9.6 Critical FastDup Plugin fastdup Path Traversal No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2026-52703 Patchstack
9.3 Critical eCommerce Product Catalog Plugin ecommerce-product-catalog SQL Injection No login needed ≤ 3.5.5 Fixed in 3.5.6 CVE-2026-52693 Patchstack
9.8 Critical OttoKit Plugin suretriggers PHP Object Injection No login needed ≤ 1.1.27 Fixed in 1.1.28 CVE-2026-49781 Patchstack
9.3 Critical GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites Plugin gptranslate SQL Injection Multilingual AI Translation for WordPress: Automatically Translate Websites plugin <= 2.32.6 - SQL Injection No login needed ≤ 2.32.6 Fixed in 2.32.7 CVE-2026-49776 Patchstack
9.8 Critical WP Travel Engine Plugin wp-travel-engine PHP Object Injection No login needed ≤ 6.7.12 Fixed in 6.8.0 CVE-2026-49770 Patchstack
9.8 Critical wpForo Forum Plugin wpforo PHP Object Injection No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-49769 Patchstack
9.8 Critical Happyforms Plugin happyforms PHP Object Injection No login needed ≤ 1.26.13 Fixed in 1.26.14 CVE-2026-49768 Patchstack
9.9 Critical WP User Manager Plugin wp-user-manager Arbitrary File Deletion ≤ 2.9.16 Fixed in 2.9.17 CVE-2026-49766 Patchstack
9.8 Critical Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp PHP Object Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2026-49765 Patchstack
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.8.6 Fixed in 6.0.8.7 CVE-2026-49764 Patchstack
9.8 Critical Integration for Contact Form 7 HubSpot Plugin cf7-hubspot PHP Object Injection No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2026-49763 Patchstack
9.8 Critical Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-49109 Patchstack
9.8 Critical Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact PHP Object Injection No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2026-49106 Patchstack
9.8 Critical WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49105 Patchstack
9.8 Critical Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-infusionsoft PHP Object Injection No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2026-49104 Patchstack
9.8 Critical WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49085 Patchstack
9.3 Critical Advanced 301 and 302 Redirect Plugin advanced-301-and-302-redirect SQL Injection No login needed ≤ 1.6.9 Fixed in 1.7.0 CVE-2026-49067 Patchstack
9.3 Critical JS Help Desk Plugin js-support-ticket SQL Injection No login needed ≤ 3.0.9 Fixed in 3.1.0 CVE-2026-48886 Patchstack
9.1 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.9 Fixed in 1.2.0 CVE-2026-48881 Patchstack
10.0 Critical Easy Invoice Plugin easy-invoice Remote Code Execution No login needed ≤ 2.1.19 Fixed in 2.1.20 CVE-2026-48836 Patchstack
9.3 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl SQL Injection No login needed ≤ 5.1.0 Fixed in 5.2.0 CVE-2026-45439 Patchstack
9.3 Critical WP Data Access Plugin wp-data-access SQL Injection No login needed ≤ 5.5.70 Fixed in 5.5.71 CVE-2026-42665 Patchstack
9.3 Critical GD Rating System Plugin gd-rating-system SQL Injection No login needed ≤ 3.6.2 Fixed in 3.7 CVE-2026-42639 Patchstack
9.3 Critical Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce SQL Injection No login needed ≤ 4.5.1 Fixed in 4.5.2 CVE-2026-42386 Patchstack
9.3 Critical Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection No login needed ≤ 3.15.0.1 Fixed in 3.15.0.2 CVE-2026-42381 Patchstack
9.3 Critical wpForo Forum Plugin wpforo SQL Injection No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-40798 Patchstack
10.0 Critical GeekyBot Plugin geeky-bot Arbitrary File Upload No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-40772 Patchstack
9.3 Critical Contest Gallery Plugin contest-gallery SQL Injection No login needed ≤ 28.1.6 Fixed in 28.1.7 CVE-2026-40771 Patchstack
9.9 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Upload ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-39591 Patchstack
9.8 Critical Datalogics Ecommerce Delivery Plugin datalogics Privilege Escalation No login needed ≤ 2.6.62 Fixed in 2.6.63 CVE-2026-39583 Patchstack
9.3 Critical SpeakOut! Email Petitions Plugin speakout SQL Injection No login needed ≤ 4.6.5 Fixed in 4.6.5.1 CVE-2026-39530 Patchstack
9.3 Critical GeekyBot Plugin geeky-bot SQL Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-39519 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.152 Fixed in 2.8.154 CVE-2026-39512 Patchstack
9.3 Critical WP Photo Album Plus Plugin wp-photo-album-plus SQL Injection No login needed ≤ 9.1.08.001 Fixed in 9.1.08.002 CVE-2026-39511 Patchstack
9.3 Critical Form Maker by 10Web Plugin form-maker SQL Injection No login needed ≤ 1.15.38 Fixed in 1.15.39 CVE-2026-39502 Patchstack
9.3 Critical Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection No login needed ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39493 Patchstack
9.3 Critical WP Maps Plugin wp-google-map-plugin SQL Injection No login needed ≤ 4.9.1 Fixed in 4.9.2 CVE-2026-39492 Patchstack
9.1 Critical Responsive Slider by MetaSlider Plugin ml-slider Remote Code Execution ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39465 Patchstack
9.3 Critical Feed KuantoKusta for WooCommerce – Free Plugin feed-kuantokusta-for-woocommerce SQL Injection Free plugin <= 5.3 - SQL Injection No login needed ≤ 5.3 Fixed in 5.3.1 CVE-2026-39441 Patchstack
9.8 Critical iControlWP Plugin worpit-admin-dashboard-plugin Privilege Escalation No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2026-34901 Patchstack
9.8 Critical Broadcast Live Video Plugin videowhisper-live-streaming-integration PHP Object Injection No login needed < 7.1.3 Fixed in 7.1.3 CVE-2026-27053 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only