WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,501–5,550 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 111 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High BP Better Messages Plugin bp-better-messages Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.14.16 Fixed in 2.15.0 CVE-2026-42736 Patchstack
8.2 High KiviCare Plugin kivicare-clinic-management-system Authentication Bypass Broken Authentication No login needed ≤ 4.3.0 Fixed in 4.4.0 CVE-2026-42735 Patchstack
7.1 High WPCS Plugin currency-switcher Cross-Site Scripting No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2026-42733 Patchstack
6.5 Medium Ads by WPQuads Plugin quick-adsense-reloaded Authentication Bypass Broken Authentication No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-42732 Patchstack
8.5 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection ≤ 3.7.29 Fixed in 3.7.30 CVE-2026-42730 Patchstack
7.1 High HT Contact Form 7 Plugin ht-contactform Cross-Site Scripting No login needed ≤ 2.8.2 Fixed in 2.8.3 CVE-2026-42728 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-42725 Patchstack
7.1 High Geo Mashup Plugin geo-mashup Cross-Site Scripting No login needed ≤ 1.13.19 Fixed in 1.13.20 CVE-2026-42734 Patchstack
9.8 Critical miniorange otp verification Plugin miniorange-otp-verification Privilege Escalation No login needed ≤ 5.4.9 Fixed in 5.5.0 CVE-2026-42731 Patchstack
7.1 High PropertyHive Plugin propertyhive Cross-Site Scripting No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2026-42729 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2026-42727 Patchstack
6.5 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control No login needed ≤ 4.4.5 Fixed in 4.4.6 CVE-2026-42726 Patchstack
6.1 Medium MinhNhut Link Gateway Plugin minhnhut-link-gateway Cross-Site Scripting Reflected Cross-Site Scripting via 'url' Parameter No login needed ≤ 3.6.1 CVE-2026-3349 Wordfence
4.4 Medium MinhNhut Link Gateway Plugin minhnhut-link-gateway Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Plugin Settings ≤ 3.6.1 CVE-2026-3348 Wordfence
4.8 Medium myLinksDump Plugin mylinksdump Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'link_title' Parameter ≤ 1.6 CVE-2026-2288 Wordfence
4.8 Medium rexCrawler Plugin rexcrawler Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings ≤ 1.0.15 CVE-2026-2280 Wordfence
6.5 Medium Xpro Elementor Addons - Pro Plugin Path Traversal Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG ≤ 1.4.7 CVE-2025-0898 Wordfence
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.10.8 Fixed in 3.10.9 CVE-2026-48968 Patchstack
6.5 Medium GenerateBlocks Plugin generateblocks Information Disclosure Sensitive Data Exposure ≤ 2.1.0 Fixed in 2.1.1 CVE-2026-48877 Patchstack
7.1 High Themebox - Digital Products Ecommerce Theme themebox Cross-Site Scripting Digital Products Ecommerce theme <= 1.4.2 - Cross Site Scripting (XSS) No login needed ≤ 1.4.2 CVE-2025-52747 Patchstack
7.1 High Felan Framework Plugin felan-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-22741 Patchstack
4.3 Medium MetaMagic SEO Plugin metamagic Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update via Settings Page No login needed ≤ 1.6 CVE-2026-8942 Wordfence
6.4 Medium Github Shortcode Plugin github-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2026-8042 Wordfence
6.1 Medium WP Promoter Plugin wp-promoter Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'popup_width' Parameter No login needed ≤ 1.3 CVE-2026-8906 Wordfence
7.2 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints No login needed ≤ 7.7 CVE-2026-3375 Wordfence
6.1 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Reflected Cross-Site Scripting via 's' Parameter No login needed ≤ 3.4.6 CVE-2026-3001 Wordfence
6.4 Medium WPBakery Page Builder Addons by Livemesh Plugin addons-for-visual-composer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.9.4 CVE-2026-3895 Wordfence
7.2 High Booking Calendar – Event Calendar Plugin Cross-Site Scripting Event Calendar <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.1.6 CVE-2026-8143 Wordfence
7.2 High affiliate-toolkit Plugin affiliate-toolkit-starter Remote Code Execution Authenticated (Editor+) Remote Code Execution ≤ 3.8.4 CVE-2026-6169 Wordfence
4.9 Medium EnvíaloSimple: Email Marketing y Newsletters Plugin envialosimple-email-marketing-y-newsletters-gratis SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 2.4.5 CVE-2026-7618 Wordfence
6.4 Medium Livemesh SiteOrigin Widgets Plugin livemesh-siteorigin-widgets Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.9.2 CVE-2026-3896 Wordfence
6.4 Medium WPBakery Page Builder Addons by Livemesh Plugin addons-for-visual-composer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.9.4 CVE-2026-2030 Wordfence
8.8 High WPCode Plugin insert-headers-and-footers Remote Code Execution Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost ≤ 2.3.5 CVE-2026-8832 Wordfence
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Missing Authorization ≤ 3.9.2 CVE-2026-3897 Wordfence
6.5 Medium Enable jQuery Migrate Helper Plugin enable-jquery-migrate-helper Broken Access Control Missing Authorization to Authenticated (Subscriber+) jQuery Version Downgrade ≤ 1.4.1 CVE-2026-3279 Wordfence
7.1 High EventPress Theme eventpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 22.2 Fixed in 22.2 CVE-2026-6268 WPScan
6.4 Medium Instant-Quote.co Quotation Page Plugin iq-quotation-page Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.3.4 CVE-2026-8884 Wordfence
6.4 Medium Post Categories Gallery Plugin post-category-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.0 CVE-2026-8867 Wordfence
8.1 High Login with NEAR Plugin near-login Authentication Bypass Authentication Bypass via 'account' Parameter No login needed ≤ 0.3.3 CVE-2026-8994 Wordfence
6.4 Medium Auto Thumbnails Plugin automatic-thumbnail Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2026-8899 Wordfence
6.4 Medium hk_shortcode Plugin hk-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute ≤ 1.0 CVE-2026-8886 Wordfence
4.3 Medium Genzel breadcrumbs Plugin genzel-breadcrumbs Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via Plugin Settings Page No login needed ≤ 1.2 CVE-2026-8708 Wordfence
6.4 Medium faq shortocde Plugin faq-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute ≤ 1.0 CVE-2026-8040 Wordfence
6.4 Medium Dideo Plugin wp-dideo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2026-8847 Wordfence
6.4 Medium Responsive Check Plugin responsive-checker-real-time Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.0.3 CVE-2026-8844 Wordfence
5.3 Medium WP Promoter Plugin wp-promoter Broken Access Control Missing Authorization to Unauthenticated Statistics Reset via wpp-reset_stats AJAX Action No login needed ≤ 1.3 CVE-2026-9014 Wordfence
6.1 Medium NS Product icon badge Plugin product-icon-badge Cross-Site Scripting Reflected Cross-Site Scripting via PHP_SELF No login needed ≤ 1.2.4 CVE-2026-8707 Wordfence
4.3 Medium Old Posts Highlighter Plugin old-posts-highlighter Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.3 CVE-2026-7614 Wordfence
6.4 Medium iWR Tooltip Plugin iwr-tooltip Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2026-8894 Wordfence
6.4 Medium Easy Prism Syntax Highlighter Plugin easy-prism-syntax-highlighter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.2 CVE-2026-8875 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only