WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,851–5,900 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 118 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Broadstreet Plugin broadstreet Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.53.1 CVE-2025-9989 Wordfence
6.4 Medium Cost of Goods: Product Cost & Profit Calculator for WooCommerce Plugin cost-of-goods-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2026-6962 Wordfence
5.3 Medium Broadstreet Plugin broadstreet Information Disclosure Authenticated (Subscriber+) Information Disclosure No login needed ≤ 1.53.1 CVE-2025-9987 Wordfence
8.1 High coreActivity: Activity Logging Plugin coreactivity PHP Object Injection Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field No login needed ≤ 3.0 CVE-2026-7635 Wordfence
6.5 Medium Charitable Plugin charitable SQL Injection Authenticated (Custom+) SQL Injection via 's' Search Parameter ≤ 1.8.10.4 CVE-2026-7619 Wordfence
4.3 Medium Broadstreet Plugin broadstreet Broken Access Control Missing Authorization to Authenticated (Subscriber+) Advertiser Creation ≤ 1.53.1 CVE-2025-9988 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed ≤ 4.0.1 CVE-2025-14755 Wordfence
6.5 Medium Advanced Custom Fields: Extended Plugin acf-extended Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.9.2.3 CVE-2025-15463 Wordfence
7.5 High Court Reservation – Manage Your Court Bookings Online Plugin court-reservation SQL Injection Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injection No login needed ≤ 1.10.11 CVE-2026-1250 Wordfence
7.1 High MonsterInsights Plugin google-analytics-for-wordpress Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset ≤ 10.1.2 CVE-2026-5371 Wordfence
5.3 Medium Hustle Plugin wordpress-popup Broken Access Control No login needed ≤ 7.8.10.1 Fixed in 7.8.10.2 CVE-2026-25431 Patchstack
7.7 High WP Travel Plugin wp-travel SQL Injection ≤ 11.4.0 Fixed in 11.5.0 CVE-2026-45218 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.4.0 CVE-2026-45215 Patchstack
8.5 High Xpro Elementor Addons Plugin xpro-elementor-addons SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-45214 Patchstack
7.6 High BEAR Plugin woo-bulk-editor SQL Injection ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2026-45213 Patchstack
5.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control No login needed ≤ 1.4.0.3 Fixed in 1.4.0.4 CVE-2026-45212 Patchstack
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
5.4 Medium Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.2 Fixed in 1.53.2 CVE-2026-45210 Patchstack
8.5 High Views for WPForms Plugin views-for-wpforms-lite SQL Injection ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-42742 Patchstack
8.5 High Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin views-for-ninja-forms SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-42741 Patchstack
4.4 Medium Continually Plugin continually Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'continually_embed_code' Parameter ≤ 4.3.1 CVE-2026-6813 Wordfence
4.4 Medium FastBots Plugin fastbots-ai-chatbots Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.0.12 CVE-2026-6800 Wordfence
4.3 Medium Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter ≤ 1.4.103 CVE-2026-1934 Wordfence
8.2 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.53 Fixed in 1.0.54 CVE-2026-39432 Patchstack
6.4 Medium BJ Lazy Load Plugin bj-lazy-load Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom HTML Block ≤ 1.0.9 CVE-2026-2300 Wordfence
6.1 Medium WP Google Maps Integration Plugin wp-google-maps-integration Cross-Site Scripting Reflected Cross-Site Scripting via 'page' Parameter No login needed ≤ 1.2 CVE-2026-7464 Wordfence
6.4 Medium scratchblocks for WP Plugin scratchblocks-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute ≤ 1.0.1 CVE-2026-6247 Wordfence
6.5 Medium Eight Day Week Print Workflow Plugin eight-day-week-print-workflow SQL Injection Authenticated (Subscriber+) SQL Injection via 'title' Parameter ≤ 1.2.6 CVE-2026-5028 Wordfence
4.3 Medium Skysa Text Ticker App Plugin skysa-text-ticker-app Cross-Site Request Forgery Cross-Site Request Forgery to Settings Modification via 'Save Settings' Form No login needed ≤ 1.4 CVE-2026-6710 Wordfence
6.4 Medium Credits Shortcode Plugin source-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute ≤ 1.2 CVE-2026-6256 Wordfence
4.3 Medium Woo Commerce Minimum Weight Plugin woo-commerce-min-weight Cross-Site Request Forgery Cross-Site Request Forgery via Settings Update Form No login needed ≤ 3.0.1 CVE-2026-6932 Wordfence
5.3 Medium Smart Appointment & Booking Plugin smart-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Cancellation No login needed ≤ 1.0.8 CVE-2026-5693 Wordfence
4.3 Medium Coinbase Commerce for Contact Form 7 Plugin coinbase-commerce-for-contact-form-7 Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter ≤ 1.1.2 CVE-2026-6709 Wordfence
6.4 Medium Advanced Social Media Icons Plugin advanced-social-media-icons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'social' Shortcode ≤ 1.2 CVE-2026-7659 Wordfence
6.4 Medium Voyage Plus Plugin voyage-plus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'post-content' Shortcode ≤ 1.0.6 CVE-2026-5715 Wordfence
4.3 Medium Zawgyi Embed Plugin zawgyi-embed Cross-Site Request Forgery Cross-Site Request Forgery via 'zawgyi_forceCSS' Parameter No login needed ≤ 2.1.1 CVE-2026-7616 Wordfence
6.1 Medium Tm – WordPress Redirection Plugin tm-wordpress-redirection Cross-Site Request Forgery WordPress Redirection <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2026-7561 Wordfence
6.4 Medium Next Date Plugin nextdate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute ≤ 1.0 CVE-2026-4920 Wordfence
4.3 Medium Forms Rb Plugin forms-rb Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via 'form_id' Parameter ≤ 1.1.9 CVE-2026-7050 Wordfence
7.5 High AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator SQL Injection Unauthenticated SQL Injection in getListForTbl() No login needed ≤ 1.4.17 CVE-2026-2993 Wordfence
6.4 Medium Quick Table Plugin quick-table Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute ≤ 1.0.0 CVE-2026-6237 Wordfence
6.4 Medium SP Blog Designer Plugin sp-blog-designer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'design' Attribute ≤ 1.0.0 CVE-2026-4859 Wordfence
7.2 High LifePress Plugin lifepress Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'n' Parameter via lp_update_mds AJAX Action No login needed ≤ 2.2.2 CVE-2026-6690 Wordfence
4.8 Medium GWD Connect Plugin graphic-web-design-inc Broken Access Control Unauthenticated Limited Code Execution via update_agent No login needed ≤ 2.9 CVE-2026-6663 Wordfence
5.3 Medium Slek Gateway for WooCommerce Plugin slek-gateway-for-woocommerce Information Disclosure Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden Fields No login needed ≤ 1.0 CVE-2026-7626 Wordfence
6.1 Medium AzonPost Plugin azonpost Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2026-7437 Wordfence
4.9 Medium WP SEO Structured Data Schema Plugin wp-seo-structured-data-schema Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via '_kcseo_ative_tab' Parameter ≤ 2.8.1 CVE-2026-3604 Wordfence
6.4 Medium Bootstrap Shortcode Plugin bootstrap-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'box' Shortcode ≤ 1.0 CVE-2026-7661 Wordfence
4.3 Medium WP-Redirection Plugin wp-redirection Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.3 CVE-2026-7562 Wordfence
6.4 Medium Fancy Image Show Plugin fancy-image-show Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 9.1 CVE-2026-5340 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only