WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 551–600 of 2,168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical wpForo Forum Plugin wpforo SQL Injection No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-40798 Patchstack
10.0 Critical GeekyBot Plugin geeky-bot Arbitrary File Upload No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-40772 Patchstack
9.3 Critical Contest Gallery Plugin contest-gallery SQL Injection No login needed ≤ 28.1.6 Fixed in 28.1.7 CVE-2026-40771 Patchstack
9.9 Critical WP-BusinessDirectory Plugin wp-businessdirectory Arbitrary File Upload ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-39591 Patchstack
9.8 Critical Datalogics Ecommerce Delivery Plugin datalogics Privilege Escalation No login needed ≤ 2.6.62 Fixed in 2.6.63 CVE-2026-39583 Patchstack
9.3 Critical SpeakOut! Email Petitions Plugin speakout SQL Injection No login needed ≤ 4.6.5 Fixed in 4.6.5.1 CVE-2026-39530 Patchstack
9.3 Critical GeekyBot Plugin geeky-bot SQL Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-39519 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.152 Fixed in 2.8.154 CVE-2026-39512 Patchstack
9.3 Critical WP Photo Album Plus Plugin wp-photo-album-plus SQL Injection No login needed ≤ 9.1.08.001 Fixed in 9.1.08.002 CVE-2026-39511 Patchstack
9.3 Critical Form Maker by 10Web Plugin form-maker SQL Injection No login needed ≤ 1.15.38 Fixed in 1.15.39 CVE-2026-39502 Patchstack
9.3 Critical Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection No login needed ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39493 Patchstack
9.3 Critical WP Maps Plugin wp-google-map-plugin SQL Injection No login needed ≤ 4.9.1 Fixed in 4.9.2 CVE-2026-39492 Patchstack
9.1 Critical Responsive Slider by MetaSlider Plugin ml-slider Remote Code Execution ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39465 Patchstack
9.3 Critical Feed KuantoKusta for WooCommerce – Free Plugin feed-kuantokusta-for-woocommerce SQL Injection Free plugin <= 5.3 - SQL Injection No login needed ≤ 5.3 Fixed in 5.3.1 CVE-2026-39441 Patchstack
9.8 Critical iControlWP Plugin worpit-admin-dashboard-plugin Privilege Escalation No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2026-34901 Patchstack
9.8 Critical Broadcast Live Video Plugin videowhisper-live-streaming-integration PHP Object Injection No login needed < 7.1.3 Fixed in 7.1.3 CVE-2026-27053 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack
9.8 Critical Baggage Freight Shipping Australia Plugin baggage-freight Arbitrary File Upload WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload No login needed 0.1.0 CVE-2018-25436 VulnCheck
9.8 Critical Advanced Google Maps Plugin Privilege Escalation Unauthenticated Administrator Account Creation No login needed < 6.1.1 Fixed in 6.1.1 CVE-2026-8935 WPScan
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2026-39494 Patchstack
9.3 Critical JoomSport Plugin joomsport-sports-league-results-management SQL Injection No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2026-42647 Patchstack
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Privilege Escalation No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2026-49060 Patchstack
9.8 Critical Doctreat Core Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.6.8 CVE-2025-6254 Wordfence
9.1 Critical Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Arbitrary File Upload Unauthenticated Arbitrary Media Upload No login needed < 1.60 Fixed in 1.60 CVE-2026-9067 WPScan
9.8 Critical Woody Code Snippets Plugin insert-php Remote Code Execution WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API No login needed < 3.3.1 Fixed in 3.3.1 CVE-2017-20251 VulnCheck
9.8 Critical Travelscape Theme travelscape Arbitrary File Upload WordPress Theme Travelscape 1.0.3 Arbitrary File Upload No login needed 1.0.3 CVE-2024-58349 VulnCheck
9.8 Critical Background Image Cropper Plugin background-image-cropper Remote Code Execution WordPress Background Image Cropper 1.2 Remote Code Execution No login needed 1.2 CVE-2024-58348 VulnCheck
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API No login needed ≤ 1.9.4 CVE-2026-10580 Wordfence
10.0 Critical Product Slider Pro for WooCommerce Plugin woo-product-slider-pro Other Backdoor No login needed < 3.5.4 Fixed in 3.5.4 CVE-2026-49777 Patchstack
9.8 Critical Ad Manager WD Plugin Path Traversal WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download No login needed 1.0.11 CVE-2019-25727 VulnCheck
9.8 Critical ARMember Premium Plugin Privilege Escalation Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation No login needed ≤ 7.3.1 CVE-2026-5076 Wordfence
9.3 Critical WP Job Portal Plugin wp-job-portal SQL Injection No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42684 Patchstack
9.8 Critical Masteriyo LMS PRO Plugin learning-management-system-pro Privilege Escalation No login needed ≤ 2.20.0 Fixed in 2.20.1 CVE-2025-53209 Patchstack
9.8 Critical Kirki Plugin kirki Privilege Escalation Unauthenticated Privilege Escalation via 'handle_forgot_password' No login needed 6.0.0 – 6.0.6 CVE-2026-8206 Wordfence
9.3 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-42672 Patchstack
9.8 Critical Contest Gallery Pro Plugin contest-gallery-pro Privilege Escalation No login needed ≤ 29.0.1 Fixed in 29.0.2 CVE-2026-42680 Patchstack
9.1 Critical wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-42682 Patchstack
9.6 Critical Gravity Forms Plugin gravityforms Arbitrary File Deletion No login needed ≤ 2.10.0.1 Fixed in 2.10.1 CVE-2026-48866 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.4.17 Fixed in 1.4.19 CVE-2026-48879 Patchstack
9.1 Critical WP Travel Pro Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators No login needed ≤ 10.6.0 CVE-2026-4290 Wordfence
9.8 Critical OTP Login With Phone Number, OTP Verification Plugin login-with-phone-number Authentication Bypass Unauthenticated Authentication Bypass via Firebase OTP Verification No login needed 1.8.50 – 1.8.60 CVE-2026-3655 Wordfence
9.8 Critical WP Maps Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action No login needed ≤ 6.0.4 CVE-2026-8732 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter No login needed ≤ 0.9.2.5 CVE-2026-8809 Wordfence
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-42761 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation No login needed ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42758 Patchstack
9.9 Critical WebinarIgnition Plugin webinar-ignition Arbitrary File Deletion ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42757 Patchstack
9.9 Critical QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly Plugin quickwebp Arbitrary File Deletion Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion ≤ 3.2.7 Fixed in 3.2.8 CVE-2026-42756 Patchstack
9.3 Critical TableOn Plugin posts-table-filterable SQL Injection No login needed ≤ 1.0.5.1 Fixed in 1.0.6 CVE-2026-42755 Patchstack
9.9 Critical WPify Woo Czech Plugin wpify-woo Arbitrary File Upload ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-42748 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only