WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 551–600 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Thrive Architect Plugin thrive-visual-editor Cross-Site Scripting No login needed ≤ 10.9.3.1 Fixed in 10.9.3.2 CVE-2026-66694 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.5 Fixed in 4.16.5.1 CVE-2026-66690 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-66664 Patchstack
7.1 High WP Data Access Plugin wp-data-access Cross-Site Scripting No login needed ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-66663 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control ≤ 3.29.10 CVE-2026-66470 Patchstack
7.1 High Events Manager Plugin events-manager Cross-Site Scripting No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2026-66457 Patchstack
7.1 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Scripting File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2026-66440 Patchstack
7.1 High Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting No login needed ≤ 3.2.0.3 Fixed in 3.2.1 CVE-2026-66439 Patchstack
8.1 High Login with phone number Plugin login-with-phone-number Authentication Bypass Bypass vulnerability No login needed ≤ 1.8.70 Fixed in 1.8.71 CVE-2026-65570 Patchstack
8.5 High WP Job Portal Plugin wp-job-portal SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-65569 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.3.3 Fixed in 5.2.3.4 CVE-2026-65565 Patchstack
7.1 High Houzez Property Feed Plugin houzez-property-feed Cross-Site Scripting No login needed ≤ 2.5.48 Fixed in 2.5.49 CVE-2026-65560 Patchstack
7.2 High Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Privilege Escalation ≤ 4.6.0 Fixed in 4.6.1 CVE-2026-65559 Patchstack
7.1 High AnsPress – Question and answer Plugin anspress-question-answer Broken Access Control Question and answer plugin 4.4.4 - Broken Access Control 4.4.4 CVE-2026-65554 Patchstack
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit PHP Object Injection ≤ 3.2.10 Fixed in 3.2.11 CVE-2026-65549 Patchstack
8.5 High Creative Mail Plugin creative-mail-by-constant-contact SQL Injection ≤ 1.6.9 CVE-2026-65547 Patchstack
7.1 High AI Engine Plugin ai-engine Cross-Site Scripting No login needed ≤ 3.6.8 Fixed in 3.6.9 CVE-2026-65545 Patchstack
7.1 High Super Socializer Plugin super-socializer Cross-Site Scripting No login needed ≤ 7.14.5 CVE-2026-65544 Patchstack
7.5 High Vimeo Plugin vimeo Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.2 CVE-2026-65543 Patchstack
8.8 High Super Socializer Plugin super-socializer Authentication Bypass Broken Authentication No login needed ≤ 7.14.5 CVE-2026-65542 Patchstack
7.3 High Staff Training Plugin staff-training Broken Access Control No login needed ≤ 1.0.7 CVE-2026-65541 Patchstack
7.5 High Formidable Forms Signature Online Contract Automation Plugin forms-signature-formidable-online-contract-automation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-65523 Patchstack
7.1 High Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2026-65517 Patchstack
7.1 High AffiliateWP Plugin affiliate-wp Cross-Site Scripting No login needed ≤ 2.35.0 Fixed in 2.35.1 CVE-2026-65515 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65513 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-65509 Patchstack
7.5 High BOX NOW Delivery Croatia Plugin box-now-delivery-croatia Broken Access Control No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2026-65504 Patchstack
7.1 High SiteGuard WP Plugin siteguard Cross-Site Scripting No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-61982 Patchstack
7.1 High Ninja Tables Plugin ninja-tables Cross-Site Scripting No login needed ≤ 5.2.9 Fixed in 5.2.10 CVE-2026-61964 Patchstack
7.1 High Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting No login needed ≤ 3.38 Fixed in 3.39 CVE-2026-61963 Patchstack
7.1 High EmbedPress Plugin embedpress Cross-Site Scripting No login needed ≤ 4.5.6 Fixed in 4.6.0 CVE-2026-61961 Patchstack
7.2 High PublishPress Capabilities Plugin capability-manager-enhanced Privilege Escalation ≤ 2.45.0 Fixed in 2.50.0 CVE-2026-28183 Patchstack
7.1 High Popup Maker Plugin popup-maker Cross-Site Scripting No login needed ≤ 1.23.0 Fixed in 1.24.0 CVE-2026-28177 Patchstack
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.56.0 Fixed in 1.56.1 CVE-2026-28143 Patchstack
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.6.4.1 Fixed in 3.6.4.2 CVE-2026-28140 Patchstack
8.8 High Forminator Plugin forminator Privilege Escalation ≤ 1.56.0 Fixed in 1.56.0.1 CVE-2026-28111 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.13.1 Fixed in 3.8.13.2 CVE-2026-28082 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-66712 Patchstack
7.5 High Breakdance Plugin breakdance Broken Access Control No login needed < 2.7 Fixed in 2.7 CVE-2026-65551 Patchstack
7.2 High FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More Plugin formgent Cross-Site Scripting Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.9.2 CVE-2025-15028 Wordfence
7.1 High WOLF - WordPress Posts Bulk Editor and Manager Plugin Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed < 1.1.0 Fixed in 1.1.0 CVE-2026-14234 WPScan
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.6 Fixed in 30.0.7 CVE-2026-65447 Patchstack
7.1 High Kali Forms Plugin kali-forms Cross-Site Scripting No login needed ≤ 2.4.18 Fixed in 2.4.19 CVE-2026-65446 Patchstack
7.1 High BackWPup Plugin backwpup Cross-Site Scripting No login needed ≤ 5.7.4 Fixed in 5.7.5 CVE-2026-65443 Patchstack
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65441 Patchstack
7.1 High GetGenie Plugin getgenie Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.5.0 CVE-2026-65440 Patchstack
7.1 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting No login needed ≤ 3.5.45 Fixed in 3.5.46 CVE-2026-65439 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only