WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 5,851–5,900 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.4 Medium | Broadstreet | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.53.1 |
CVE-2025-9989 |
Wordfence | |
| 6.4 Medium | Cost of Goods: Product Cost & Profit Calculator for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.1.0 |
CVE-2026-6962 |
Wordfence | |
| 5.3 Medium | Broadstreet | Information Disclosure Authenticated (Subscriber+) Information Disclosure No login needed |
≤ 1.53.1 |
CVE-2025-9987 |
Wordfence | |
| 8.1 High | coreActivity: Activity Logging | PHP Object Injection Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field No login needed |
≤ 3.0 |
CVE-2026-7635 |
Wordfence | |
| 6.5 Medium | Charitable | SQL Injection Authenticated (Custom+) SQL Injection via 's' Search Parameter |
≤ 1.8.10.4 |
CVE-2026-7619 |
Wordfence | |
| 4.3 Medium | Broadstreet | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Advertiser Creation |
≤ 1.53.1 |
CVE-2025-9988 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed |
≤ 4.0.1 |
CVE-2025-14755 |
Wordfence | |
| 6.5 Medium | Advanced Custom Fields: Extended | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 0.9.2.3 |
CVE-2025-15463 |
Wordfence | |
| 7.5 High | Court Reservation – Manage Your Court Bookings Online | SQL Injection Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injection No login needed |
≤ 1.10.11 |
CVE-2026-1250 |
Wordfence | |
| 7.1 High | MonsterInsights | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset |
≤ 10.1.2 |
CVE-2026-5371 |
Wordfence | |
| 5.3 Medium | Hustle | Broken Access Control No login needed |
≤ 7.8.10.1 Fixed in 7.8.10.2 |
CVE-2026-25431 |
Patchstack | |
| 7.7 High | WP Travel | SQL Injection |
≤ 11.4.0 Fixed in 11.5.0 |
CVE-2026-45218 |
Patchstack | |
| 5.3 Medium | WP EasyPay | Information Disclosure Sensitive Data Exposure No login needed |
≤ 4.3.0 Fixed in 4.4.0 |
CVE-2026-45215 |
Patchstack | |
| 8.5 High | Xpro Elementor Addons | SQL Injection |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-45214 |
Patchstack | |
| 7.6 High | BEAR | SQL Injection |
≤ 1.1.7.1 Fixed in 1.1.8 |
CVE-2026-45213 |
Patchstack | |
| 5.3 Medium | Asset CleanUp: Page Speed Booster | Broken Access Control No login needed |
≤ 1.4.0.3 Fixed in 1.4.0.4 |
CVE-2026-45212 |
Patchstack | |
| 8.5 High | APIExperts Square for WooCommerce | SQL Injection |
≤ 4.7.1 Fixed in 4.7.2 |
CVE-2026-45211 |
Patchstack | |
| 5.4 Medium | Broadstreet Ads | Broken Access Control |
≤ 1.52.2 Fixed in 1.53.2 |
CVE-2026-45210 |
Patchstack | |
| 8.5 High | Views for WPForms | SQL Injection |
≤ 3.4.6 Fixed in 3.4.7 |
CVE-2026-42742 |
Patchstack | |
| 8.5 High | Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend | SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection |
≤ 3.3.2 Fixed in 3.3.3 |
CVE-2026-42741 |
Patchstack | |
| 4.4 Medium | Continually | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'continually_embed_code' Parameter |
≤ 4.3.1 |
CVE-2026-6813 |
Wordfence | |
| 4.4 Medium | FastBots | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.0.12 |
CVE-2026-6800 |
Wordfence | |
| 4.3 Medium | Motors – Car Dealership & Classified Listings | Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter |
≤ 1.4.103 |
CVE-2026-1934 |
Wordfence | |
| 8.2 High | Timetics | Broken Access Control No login needed |
≤ 1.0.53 Fixed in 1.0.54 |
CVE-2026-39432 |
Patchstack | |
| 6.4 Medium | BJ Lazy Load | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom HTML Block |
≤ 1.0.9 |
CVE-2026-2300 |
Wordfence | |
| 6.1 Medium | WP Google Maps Integration | Cross-Site Scripting Reflected Cross-Site Scripting via 'page' Parameter No login needed |
≤ 1.2 |
CVE-2026-7464 |
Wordfence | |
| 6.4 Medium | scratchblocks for WP | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute |
≤ 1.0.1 |
CVE-2026-6247 |
Wordfence | |
| 6.5 Medium | Eight Day Week Print Workflow | SQL Injection Authenticated (Subscriber+) SQL Injection via 'title' Parameter |
≤ 1.2.6 |
CVE-2026-5028 |
Wordfence | |
| 4.3 Medium | Skysa Text Ticker App | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Modification via 'Save Settings' Form No login needed |
≤ 1.4 |
CVE-2026-6710 |
Wordfence | |
| 6.4 Medium | Credits Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute |
≤ 1.2 |
CVE-2026-6256 |
Wordfence | |
| 4.3 Medium | Woo Commerce Minimum Weight | Cross-Site Request Forgery Cross-Site Request Forgery via Settings Update Form No login needed |
≤ 3.0.1 |
CVE-2026-6932 |
Wordfence | |
| 5.3 Medium | Smart Appointment & Booking | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Cancellation No login needed |
≤ 1.0.8 |
CVE-2026-5693 |
Wordfence | |
| 4.3 Medium | Coinbase Commerce for Contact Form 7 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter |
≤ 1.1.2 |
CVE-2026-6709 |
Wordfence | |
| 6.4 Medium | Advanced Social Media Icons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'social' Shortcode |
≤ 1.2 |
CVE-2026-7659 |
Wordfence | |
| 6.4 Medium | Voyage Plus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'post-content' Shortcode |
≤ 1.0.6 |
CVE-2026-5715 |
Wordfence | |
| 4.3 Medium | Zawgyi Embed | Cross-Site Request Forgery Cross-Site Request Forgery via 'zawgyi_forceCSS' Parameter No login needed |
≤ 2.1.1 |
CVE-2026-7616 |
Wordfence | |
| 6.1 Medium | Tm – WordPress Redirection | Cross-Site Request Forgery WordPress Redirection <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.2 |
CVE-2026-7561 |
Wordfence | |
| 6.4 Medium | Next Date | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute |
≤ 1.0 |
CVE-2026-4920 |
Wordfence | |
| 4.3 Medium | Forms Rb | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via 'form_id' Parameter |
≤ 1.1.9 |
CVE-2026-7050 |
Wordfence | |
| 7.5 High | AI Chatbot & Workflow Automation by AIWU | SQL Injection Unauthenticated SQL Injection in getListForTbl() No login needed |
≤ 1.4.17 |
CVE-2026-2993 |
Wordfence | |
| 6.4 Medium | Quick Table | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute |
≤ 1.0.0 |
CVE-2026-6237 |
Wordfence | |
| 6.4 Medium | SP Blog Designer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'design' Attribute |
≤ 1.0.0 |
CVE-2026-4859 |
Wordfence | |
| 7.2 High | LifePress | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'n' Parameter via lp_update_mds AJAX Action No login needed |
≤ 2.2.2 |
CVE-2026-6690 |
Wordfence | |
| 4.8 Medium | GWD Connect | Broken Access Control Unauthenticated Limited Code Execution via update_agent No login needed |
≤ 2.9 |
CVE-2026-6663 |
Wordfence | |
| 5.3 Medium | Slek Gateway for WooCommerce | Information Disclosure Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden Fields No login needed |
≤ 1.0 |
CVE-2026-7626 |
Wordfence | |
| 6.1 Medium | AzonPost | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.3 |
CVE-2026-7437 |
Wordfence | |
| 4.9 Medium | WP SEO Structured Data Schema | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via '_kcseo_ative_tab' Parameter |
≤ 2.8.1 |
CVE-2026-3604 |
Wordfence | |
| 6.4 Medium | Bootstrap Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'box' Shortcode |
≤ 1.0 |
CVE-2026-7661 |
Wordfence | |
| 4.3 Medium | WP-Redirection | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.3 |
CVE-2026-7562 |
Wordfence | |
| 6.4 Medium | Fancy Image Show | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 9.1 |
CVE-2026-5340 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.