WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.12.4 Fixed in 1.6.12.6 CVE-2026-57812 Patchstack
4.3 Medium EduMall Theme edumall Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2026-57797 Patchstack
6.5 Medium Speaker Plugin speaker Cross-Site Scripting ≤ 4.1.13 CVE-2026-57783 Patchstack
5.3 Medium Universal Clocks Plugin universal-clocks Broken Access Control No login needed ≤ 1.2.0 CVE-2026-57782 Patchstack
5.3 Medium MeetingHub Plugin meetinghub Broken Access Control No login needed ≤ 1.25.10 CVE-2026-57781 Patchstack
6.5 Medium Envision Page Builder Plugin envision-page-builder Cross-Site Scripting ≤ 0.22 CVE-2026-57780 Patchstack
5.3 Medium Fascinate Plugin fascinate Broken Access Control No login needed ≤ 1.1.5 CVE-2026-57779 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.36 CVE-2026-57778 Patchstack
5.3 Medium VW Wedding Plugin vw-wedding Broken Access Control No login needed ≤ 1.3.7 CVE-2026-57776 Patchstack
5.3 Medium VW Food Corner Plugin vw-food-corner Broken Access Control No login needed ≤ 1.1.0 CVE-2026-57774 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.4.8 Fixed in 3.4.9 CVE-2026-57711 Patchstack
6.5 Medium Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Authentication Bypass Broken Authentication No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2026-57698 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
6.5 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting ≤ 2.8.11 Fixed in 2.8.12 CVE-2026-57693 Patchstack
5.8 Medium Anti-Malware Security and Brute-Force Firewall Plugin gotmls Cross-Site Scripting No login needed ≤ 4.23.89 Fixed in 4.23.90 CVE-2026-57691 Patchstack
6.5 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Broken Access Control No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57424 Patchstack
6.5 Medium Author Box WP Lens Plugin author-box-for-divi Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-57420 Patchstack
6.5 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 3.1.8 Fixed in 3.1.9 CVE-2026-57419 Patchstack
6.5 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.13 Fixed in 20.8.14 CVE-2026-57418 Patchstack
6.5 Medium ChatBot for eCommerce – WoowBot Plugin woowbot-woocommerce-chatbot Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) ≤ 4.6.1 Fixed in 4.7.0 CVE-2026-57414 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
6.5 Medium Gift Vouchers Plugin gift-voucher Broken Access Control No login needed ≤ 4.6.9 Fixed in 4.7.0 CVE-2026-57412 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2026-57408 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-57406 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2026-57404 Patchstack
6.5 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Cross-Site Scripting ≤ 1.0.51 Fixed in 1.0.52 CVE-2026-57402 Patchstack
6.5 Medium Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-57400 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57395 Patchstack
6.5 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-57393 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57392 Patchstack
6.5 Medium Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-57391 Patchstack
6.5 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.2.167 Fixed in 1.2.168 CVE-2026-57390 Patchstack
6.5 Medium WowAddons Plugin product-addons Broken Access Control No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2026-57377 Patchstack
6.5 Medium MStore API Plugin mstore-api Broken Access Control No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-57375 Patchstack
6.5 Medium reCAPTCHA (v2 & v3) for Asgaros Forum Plugin recaptcha-for-asgaros-forum Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57365 Patchstack
6.5 Medium Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More Plugin better-payment Other Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57364 Patchstack
6.5 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.6.18 CVE-2026-15287 Wordfence
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
5.3 Medium FormLayer Plugin formlayer Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-59519 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.9.9 Fixed in 2.8.0 CVE-2026-59511 Patchstack
5.3 Medium Sendcloud Shipping Plugin sendcloud-connected-shipping Broken Access Control No login needed ≤ 1.0.29 CVE-2026-57760 Patchstack
6.5 Medium Surbma | Yoast SEO Breadcrumb Shortcode Plugin surbma-yoast-breadcrumb-shortcode Cross-Site Scripting ≤ 1.2 CVE-2026-57764 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.7.0 CVE-2026-57763 Patchstack
5.9 Medium Simple URLs Plugin simple-urls Cross-Site Scripting ≤ 151 CVE-2026-57762 Patchstack
6.5 Medium Mosaic Gallery – Advanced Gallery Plugin mosaic-gallery-advanced-gallery Cross-Site Scripting Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2026-57755 Patchstack
6.5 Medium Livemesh Addons for WPBakery Page Builder Plugin addons-for-visual-composer Cross-Site Scripting ≤ 3.9.4 CVE-2026-57754 Patchstack
5.3 Medium Kit (formerly ConvertKit) for WooCommerce Plugin convertkit-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.5 CVE-2026-57753 Patchstack
5.3 Medium ez Form Calculator Premium Plugin ez-form-calculator-premium Broken Access Control No login needed ≤ 2.14.1.2 CVE-2026-57750 Patchstack
6.5 Medium Booked Plugin booked Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-57747 Patchstack
6.5 Medium Flatsome Theme flatsome Broken Access Control ≤ 3.20.5 CVE-2026-57731 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only