WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,901–5,950 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 119 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Rate Star Review Vote Plugin rate-star-review Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter ≤ 1.6.4 CVE-2026-4301 Wordfence
6.4 Medium Shortcodely Plugin shortcodely Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_area' Shortcode Attribute ≤ 1.0.1 CVE-2026-6913 Wordfence
6.1 Medium Pricing Tables for WP Plugin awesome-pricing-tables-lite-by-optimalplugins Cross-Site Scripting Reflected Cross-Site Scripting via 'page' Parameter No login needed ≤ 1.1.0 CVE-2026-6808 Wordfence
5.3 Medium HEL Online Classroom: AI-powered Online Classrooms Plugin hel-online-classroom Broken Access Control Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter No login needed ≤ 1.0.3 CVE-2026-6708 Wordfence
7.3 High Custom CSS JS PHP Plugin SQL Injection Unauthenticated SQL Injection to RCE No login needed 2.0.7 – 2.0.7 CVE-2026-6433 WPScan
6.4 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting WordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL 1.4.2 CVE-2021-47951 VulnCheck
5.4 Medium Payments Plugin GetPaid Plugin invoicing Content Injection WordPress GetPaid Plugin 2.4.6 HTML Injection via Help Text 2.4.6 CVE-2021-47948 VulnCheck
8.2 High Survey & Poll Plugin SQL Injection WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params No login needed 1.5.7.3 CVE-2021-47941 VulnCheck
9.8 Critical Download From Files Plugin download-from-files Arbitrary File Upload WordPress Download From Files 1.48 Arbitrary File Upload No login needed ≤ 1.48 CVE-2021-47940 VulnCheck
9.8 Critical MStore API Plugin mstore-api Arbitrary File Upload WordPress MStore API 2.0.6 Arbitrary File Upload No login needed 2.0.6 CVE-2021-47933 VulnCheck
6.4 Medium Filterable Portfolio Gallery Plugin fg-gallery Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS 1.0 CVE-2021-47929 VulnCheck
6.4 Medium WP Symposium Pro Plugin wp-symposium-pro Cross-Site Scripting WordPress Plugin WP Symposium Pro 2021.10 Stored XSS via wps_admin_forum_add_name 2021.10 CVE-2021-47927 VulnCheck
6.4 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Scripting WordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price 5.8.2 CVE-2021-47924 VulnCheck
6.4 Medium Slider by Soliloquy Plugin soliloquy-lite Cross-Site Scripting WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS 2.6.2 CVE-2021-47922 VulnCheck
6.4 Medium AccessPress Social Icons Plugin accesspress-social-icons Cross-Site Scripting WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS 1.8.2 CVE-2021-47910 VulnCheck
5.4 Medium WordPress Plugin AAWP Plugin Cross-Site Scripting WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter 3.16 CVE-2022-50970 VulnCheck
6.4 Medium IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Scripting WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS 2.26.7 CVE-2022-50961 VulnCheck
6.1 Medium International Sms For Contact Form Plugin cf7-international-sms-integration Cross-Site Scripting WordPress International Sms Contact Form 7 Integration 1.2 XSS No login needed 1.2 CVE-2022-50960 VulnCheck
6.1 Medium Contact Form Builder Plugin contact-forms-builder Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed 1.6.1 CVE-2022-50959 VulnCheck
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php No login needed 9.1 CVE-2022-50958 VulnCheck
6.2 Medium amministrazione-aperta Plugin amministrazione-aperta Path Traversal WordPress Plugin amministrazione-aperta 3.7.3 Local File Read No login needed 3.7.3 CVE-2022-50956 VulnCheck
4.3 Medium Curtain Plugin curtain Cross-Site Request Forgery WordPress Plugin Curtain 1.0.2 Cross-site Request Forgery 1.0.2 CVE-2022-50955 VulnCheck
6.2 Medium cab-fare-calculator Plugin cab-fare-calculator Local File Inclusion WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion No login needed 1.0.3 CVE-2022-50954 VulnCheck
6.4 Medium Videos sync PDF Plugin Cross-Site Scripting WordPress Plugin Videos sync PDF 1.7.4 Stored XSS 1.7.4 CVE-2022-50949 VulnCheck
6.4 Medium Testimonial Slider and Showcase Plugin testimonial-slider-and-showcase Cross-Site Scripting WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS 2.2.6 CVE-2022-50947 VulnCheck
6.4 Medium Netroics Blog Posts Grid Plugin netroics-blog-posts-grid Cross-Site Scripting WordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS 1.0 CVE-2022-50946 VulnCheck
5.3 Medium Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin logtivity Information Disclosure Unauthenticated Information Disclosure via REST API No login needed ≤ 3.3.6 CVE-2026-8198 Wordfence
5.3 Medium LatePoint Plugin latepoint Privilege Escalation Unauthenticated Account Takeover via Weak Password Recovery Mechanism No login needed ≤ 5.5.0 CVE-2026-7652 Wordfence
6.4 Medium Sky Addons Plugin sky-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Script ≤ 3.3.2 CVE-2026-7475 Wordfence
6.4 Medium NMR Strava activities Plugin nmr-strava-activities Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.14 CVE-2026-5341 Wordfence
6.4 Medium E2Pdf – Export Pdf Tool Plugin e2pdf Cross-Site Scripting Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.32.17 CVE-2026-7650 Wordfence
7.2 High Auto Affiliate Links Plugin wp-auto-affiliate-links Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'url' Parameter No login needed ≤ 6.8.8 CVE-2026-7330 Wordfence
8.8 High User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 4.3.1 CVE-2026-5127 Wordfence
8.6 High SureTriggers Plugin SQL Injection Unauthenticated SQLi No login needed < 1.1.23 Fixed in 1.1.23 CVE-2026-4935 WPScan
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-27415 Patchstack
5.3 Medium PDF Poster Plugin pdf-poster Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.5.0 CVE-2026-27416 Patchstack
5.9 Medium WEN Logo Slider Plugin wen-logo-slider Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5 CVE-2025-62127 Patchstack
5.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control No login needed < 5.6.8 Fixed in 5.6.8 CVE-2025-66105 Patchstack
7.6 High Team Member Plugin team-showcase-supreme SQL Injection ≤ 8.5 Fixed in 8.6 CVE-2025-68060 Patchstack
5.4 Medium WPGraphQL Plugin wp-graphql Cross-Site Request Forgery No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-68604 Patchstack
5.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Information Disclosure Sensitive Data Exposure No login needed ≤ 3.20.8 Fixed in 3.21.0 CVE-2026-25468 Patchstack
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed < 1.7.1053 Fixed in 1.7.1053 CVE-2026-25436 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting < 1.7.1053 Fixed in 1.7.1053 CVE-2026-27421 Patchstack
8.1 High WP-Optimize Plugin wp-optimize Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta ≤ 4.5.2 CVE-2026-7252 Wordfence
8.8 High Slider Revolution Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url 7.0.0 – 7.0.10 CVE-2026-6692 Wordfence
7.5 High BetterDocs Pro Plugin SQL Injection Unauthenticated SQL Injection via Encyclopedia 'limit' Parameter No login needed ≤ 3.7.0 CVE-2026-4348 Wordfence
6.5 Medium Forminator Forms Plugin forminator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded Hook ≤ 1.53.0 CVE-2026-6214 Wordfence
6.5 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Unauthenticated Arbitrary Appointment View, Modification and Deletion No login needed ≤ 1.6.10.6 CVE-2026-4807 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only