WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,451–5,500 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 110 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium PeachPay Plugin peachpay-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Unlink No login needed ≤ 1.120.46 CVE-2026-9618 Wordfence
8.8 High GutenBee Plugin gutenbee Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter ≤ 2.20.1 CVE-2026-9227 Wordfence
5.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter No login needed ≤ 5.1.5 CVE-2026-7651 Wordfence
7.2 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User-Agent Header No login needed ≤ 5.4.11 CVE-2026-7634 Wordfence
8.6 High Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-7862 WPScan
4.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Cross-Site Request Forgery Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter No login needed ≤ 3.6.7 CVE-2026-7533 Wordfence
6.4 Medium LiveSmart Video Chat Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2026-9644 Wordfence
8.8 High Crawlomatic Multipage Scraper Post Generator Plugin crawlomatic-multipage-scraper-post-generator Remote Code Execution Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute ≤ 2.7.2 CVE-2026-9009 Wordfence
6.5 Medium Meta Field Block Plugin display-a-meta-field-as-block Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary User Meta Exposure ≤ 1.5.1 CVE-2026-3173 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter ≤ 3.29.2 CVE-2026-7802 Wordfence
4.3 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter ≤ 1.4.6 CVE-2026-9241 Wordfence
4.3 Medium Timetable and Event Schedule by MotoPress Plugin mp-timetable Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function ≤ 2.4.16 CVE-2026-9228 Wordfence
7.2 High Login No Captcha reCAPTCHA Plugin login-recaptcha Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via PHP_SELF No login needed ≤ 1.8.0 CVE-2026-2374 Wordfence
6.5 Medium Independent Analytics Plugin independent-analytics Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Tracking Route No login needed ≤ 2.14.9 CVE-2026-5737 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending ≤ 3.4.7 CVE-2026-4888 Wordfence
4.3 Medium Account Manager for WooCommerce Plugin account-manager-woocommerce Broken Access Control ≤ 2.1.2 CVE-2022-41656 Patchstack
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.9.2 CVE-2026-49054 Patchstack
5.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control No login needed ≤ 3.9.6 CVE-2026-49053 Patchstack
4.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control ≤ 3.9.6 CVE-2026-49052 Patchstack
4.3 Medium WP Meta and Date Remover Plugin wp-meta-and-date-remover Broken Access Control ≤ 2.3.6 CVE-2026-49051 Patchstack
4.3 Medium DearFlip Plugin 3d-flipbook-dflip-lite Broken Access Control ≤ 2.4.27 CVE-2026-49047 Patchstack
8.5 High Duplicate Page and Post Plugin duplicate-wp-page-post SQL Injection ≤ 2.9.5 CVE-2026-49046 Patchstack
6.5 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Cross-Site Scripting ≤ 5.0.2 CVE-2026-49044 Patchstack
4.3 Medium Adminimize Plugin adminimize Broken Access Control ≤ 1.11.11 CVE-2026-49045 Patchstack
4.7 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Open Redirect No login needed ≤ 3.7.0 CVE-2026-49059 Patchstack
4.3 Medium SVG Support Plugin svg-support Broken Access Control ≤ 2.5.14 CVE-2026-48973 Patchstack
7.5 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 Local File Inclusion < 6.19.5 Fixed in 6.19.5 CVE-2026-48972 Patchstack
4.3 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Broken Access Control ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-48971 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2026-42762 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-42761 Patchstack
7.5 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule Authentication Bypass Broken Authentication No login needed ≤ 1.22.25 Fixed in 1.22.26 CVE-2026-42760 Patchstack
7.1 High Affiliate Super Assistent Plugin amazonsimpleadmin Cross-Site Scripting No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2026-42759 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation No login needed ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42758 Patchstack
9.9 Critical WebinarIgnition Plugin webinar-ignition Arbitrary File Deletion ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42757 Patchstack
9.9 Critical QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly Plugin quickwebp Arbitrary File Deletion Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion ≤ 3.2.7 Fixed in 3.2.8 CVE-2026-42756 Patchstack
9.3 Critical TableOn Plugin posts-table-filterable SQL Injection No login needed ≤ 1.0.5.1 Fixed in 1.0.6 CVE-2026-42755 Patchstack
7.1 High Favicon Plugin favicon-by-realfavicongenerator Cross-Site Scripting No login needed ≤ 1.3.46 Fixed in 1.3.47 CVE-2026-42754 Patchstack
7.3 High WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.10 Fixed in 2.11.11 CVE-2026-42753 Patchstack
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.18 Fixed in 2.1.19 CVE-2026-42751 Patchstack
6.5 Medium WPComplete Plugin wpcomplete Cross-Site Scripting ≤ 2.9.5.4 Fixed in 2.9.5.5 CVE-2026-42750 Patchstack
7.1 High Disable Comments for Any Post Types (Remove comments) Plugin comments-plus Authentication Bypass Broken Authentication ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-42749 Patchstack
9.9 Critical WPify Woo Czech Plugin wpify-woo Arbitrary File Upload ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-42748 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-42747 Patchstack
7.3 High Smart Online Order for Clover Plugin clover-online-orders Information Disclosure Sensitive Data Exposure No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-42746 Patchstack
7.3 High Smart Online Order for Clover Plugin clover-online-orders Authentication Bypass Broken Authentication No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-42745 Patchstack
6.5 Medium Ads by WPQuads Plugin quick-adsense-reloaded Other Bypass Vulnerability No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-42744 Patchstack
9.3 Critical Tainacan Plugin tainacan SQL Injection No login needed ≤ 1.0.3 Fixed in 1.1.0 CVE-2026-42740 Patchstack
7.1 High Advanced IP Blocker Plugin advanced-ip-blocker Cross-Site Scripting No login needed ≤ 8.10.7 Fixed in 8.10.8 CVE-2026-42739 Patchstack
7.1 High Smart Online Order for Clover Plugin clover-online-orders Cross-Site Scripting No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-42738 Patchstack
8.6 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Arbitrary File Deletion No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2026-42737 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only