WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,801–5,850 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 117 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Deletion No login needed ≤ 2.5.2 CVE-2026-4030 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Export No login needed ≤ 2.5.2 CVE-2026-4029 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Backup Interception No login needed ≤ 2.5.2 CVE-2026-4031 Wordfence
9.1 Critical InfusedWoo Pro Plugin Broken Access Control Unauthenticated Missing Authorization to Arbitrary Post Deletion via Multiple Parameters No login needed ≤ 5.1.2 CVE-2026-6512 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter ≤ 1.7.1058 CVE-2026-6504 Wordfence
5.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter No login needed ≤ 5.1.5 CVE-2026-6145 Wordfence
5.3 Medium MW WP Form Plugin mw-wp-form Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter No login needed ≤ 5.1.2 CVE-2026-6206 Wordfence
6.4 Medium CC Child Pages Plugin cc-child-pages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'more' Parameter ≤ 2.1.1 CVE-2026-6174 Wordfence
7.5 High InfusedWoo Pro Plugin Path Traversal Unauthenticated Arbitrary File Read via 'url' Parameter No login needed ≤ 5.1.2 CVE-2026-6514 Wordfence
6.5 Medium Media Sync Plugin media-sync Path Traversal Authenticated (Author+) Path Traversal via 'sub_dir' and 'media_items' Parameters ≤ 1.4.9 CVE-2026-6670 Wordfence
6.4 Medium Meta Field Block Plugin display-a-meta-field-as-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tagName' Block Attribute ≤ 1.5.2 CVE-2026-6252 Wordfence
7.2 High ManageWP Worker Plugin worker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'MWP-Key-Name' Header No login needed ≤ 4.9.31 CVE-2026-3718 Wordfence
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter No login needed ≤ 6.2.0 CVE-2026-5395 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode ≤ 5.6.8 CVE-2026-3694 Wordfence
8.8 High InfusedWoo Pro Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary User Meta Update ≤ 5.1.2 CVE-2026-6506 Wordfence
4.3 Medium LatePoint Plugin latepoint Cross-Site Request Forgery Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route No login needed ≤ 5.3.2 CVE-2026-5365 Wordfence
6.5 Medium Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin taskbuilder SQL Injection Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter ≤ 5.0.6 CVE-2026-6225 Wordfence
6.5 Medium Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin essential-addons-for-elementor-lite Privilege Escalation Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user ≤ 6.5.13 CVE-2026-5193 Wordfence
8.1 High Motors – Car Dealer, Classifieds & Listing Plugin Arbitrary File Deletion Car Dealer, Classifieds & Listing <= 1.4.107 - Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter ≤ 1.4.107 CVE-2026-3892 Wordfence
9.8 Critical InfusedWoo Pro Plugin Broken Access Control Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe' No login needed ≤ 5.1.2 CVE-2026-6510 Wordfence
9.8 Critical Career Section Plugin career-section Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7 CVE-2026-6271 Wordfence
9.8 Critical Burst Statistics Plugin burst-statistics Authentication Bypass Authentication Bypass to Admin Account Takeover No login needed 3.4.0 – 3.4.1.1 CVE-2026-8181 Wordfence
5.4 Medium WP Encryption - One Click SSL & Force HTTPS Plugin Broken Access Control One Click SSL & Force HTTPS <= 7.8.5.10 - Missing Authorization to Authenticated (Subscriber+) SSL Setup Tampering ≤ 7.8.5.10 CVE-2026-3829 Wordfence
6.1 Medium MapGeo - Interactive Geo Maps Plugin Cross-Site Scripting Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter No login needed ≤ 1.6.27 CVE-2025-15345 Wordfence
6.1 Medium GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'failed_orders' No login needed ≤ 1.4.0 CVE-2026-6417 Wordfence
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter No login needed ≤ 6.1.21 CVE-2026-5396 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget ≤ 6.4.11 CVE-2026-5243 Wordfence
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter ≤ 1.12.4 CVE-2026-5361 Wordfence
4.3 Medium LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Plugin learnpress Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter ≤ 4.3.5 CVE-2026-7648 Wordfence
4.3 Medium My Calendar Plugin my-calendar Broken Access Control Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter ≤ 3.7.9 CVE-2026-7525 Wordfence
6.5 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter ≤ 2.0.7 CVE-2026-5486 Wordfence
6.4 Medium WHOIS Domain Check Plugin powies-whois Cross-Site Scripting Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting 0.9.31 CVE-2020-37225 VulnCheck
5.5 Medium Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS 1.2.3 CVE-2020-37174 VulnCheck
5.5 Medium ultimate-member Plugin Local File Inclusion WordPress Plugin ultimate-member 2.1.3 Local File Inclusion 2.1.3 CVE-2020-37169 VulnCheck
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining ≤ 5.9.8.4 CVE-2026-4609 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Group Settings Modification ≤ 5.9.8.4 CVE-2026-4607 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection Authenticated (Subscriber+) SQL Injection via 'rid' Parameter ≤ 5.9.8.4 CVE-2026-4608 Wordfence
7.2 High Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text No login needed ≤ 2.5.4 CVE-2026-6177 Wordfence
4.3 Medium RTMKit Addons for Elementor Plugin rometheme-for-elementor Broken Access Control Authenticated (Author+) Missing Authorization to Widget Configuration Modification ≤ 2.0.2 CVE-2026-3426 Wordfence
8.8 High RTMKit Addons for Elementor Plugin rometheme-for-elementor Local File Inclusion Authenticated (Author+) Local File Inclusion via 'path' ≤ 2.0.2 CVE-2026-3425 Wordfence
6.5 Medium Avada Builder Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter ≤ 3.15.2 CVE-2026-4782 Wordfence
7.5 High Avada Builder Plugin SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed ≤ 3.15.1 CVE-2026-4798 Wordfence
5.3 Medium Hostinger Reach Plugin hostinger-reach Broken Access Control Missing Authorization to Authenticated (Subscriber+) Integration API Key Update ≤ 1.3.8 CVE-2026-2515 Wordfence
6.4 Medium Snow Monkey Blocks Plugin snow-monkey-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-slick' Attribute ≤ 24.1.11 CVE-2026-3004 Wordfence
5.5 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute ≤ 3.1.6 CVE-2025-14767 Wordfence
5.3 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter No login needed ≤ 3.9.9 CVE-2026-6965 Wordfence
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.3.0 CVE-2025-14033 Wordfence
7.5 High JoomSport Plugin joomsport-sports-league-results-management SQL Injection Unauthenticated SQL Injection via 'sortf' Parameter No login needed ≤ 5.7.7 CVE-2026-6929 Wordfence
5.4 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Delete Arbitrary B2S Post Records via 'postId' Parameter ≤ 8.9.0 CVE-2026-7051 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute ≤ 6.2.1 CVE-2026-6828 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only