WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2026-74000 Patchstack
5.4 Medium Cooked Plugin cooked Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.16.0 Fixed in 1.16.1 CVE-2026-73999 Patchstack
5.3 Medium Easy Invoice Plugin easy-invoice Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.4.0 CVE-2026-66676 Patchstack
6.5 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66617 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.2.6 Fixed in 2.3.0 CVE-2026-66578 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.3.1 CVE-2026-66577 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.3.3.1 Fixed in 2.3.3.2 CVE-2026-66573 Patchstack
6.5 Medium JetBlog Plugin jet-blog Cross-Site Scripting ≤ 2.4.10 Fixed in 2.4.10.1 CVE-2026-66572 Patchstack
5.3 Medium FluentAuth Plugin fluent-security Other Email Verification Bypass No login needed ≤ 2.1.2 Fixed in 3.0.0 CVE-2026-78296 Patchstack
4.3 Medium Checkout Field Manager Plugin Broken Access Control Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field 7.4.9 – < 7.9.7 Fixed in 7.9.7 CVE-2026-87831 WPScan
4.3 Medium Checkout Field Manager Plugin Broken Access Control Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting 7.8.6 – < 7.9.7 Fixed in 7.9.7 CVE-2026-87829 WPScan
4.9 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Payment Gateway Credential Disclosure 5.3.6 – < 5.6.0 Fixed in 5.6.0 CVE-2026-91019 WPScan
5.3 Medium Motors Plugin motors-car-dealership-classified-listings Information Disclosure Unauthenticated Draft/Private Listing Disclosure No login needed < 1.4.121 Fixed in 1.4.121 CVE-2026-91016 WPScan
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Unauthenticated Popup Deactivation via jltma_popup_disable_expired No login needed 3.0.0 – < 3.1.9 Fixed in 3.1.9 CVE-2026-91015 WPScan
6.8 Medium EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting Author+ Stored XSS via Image Class Attribute Backreference Expansion < 8.7.7 Fixed in 8.7.7 CVE-2026-91011 WPScan
4.3 Medium Invisible Anti-Spam & CAPTCHA Plugin Broken Access Control Subscriber+ Arbitrary Form Submission Deletion 2.0.5 – < 5.1.1 Fixed in 5.1.1 CVE-2026-91010 WPScan
4.3 Medium Active Products Tables for WooCommerce Plugin Cross-Site Request Forgery Subscriber+ Arbitrary Post Title Modification via woot_update_attachment 2.1.2 – < 2.1.3 Fixed in 2.1.3 CVE-2026-91009 WPScan
6.5 Medium Autopay Plugin platnosci-online-blue-media Information Disclosure Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-90923 WPScan
5.3 Medium Paid Member Subscriptions Plugin Price Manipulation Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch No login needed < 3.0.9 Fixed in 3.0.9 CVE-2026-90922 WPScan
4.8 Medium Newsletter Plugin newsletter Information Disclosure Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key No login needed < 9.3.8 Fixed in 9.3.8 CVE-2026-86824 WPScan
6.8 Medium HT Mega Plugin Cross-Site Scripting Contributor+ Stored XSS via Section Headline Tag 3.2.0 – < 3.2.6 Fixed in 3.2.6 CVE-2026-86788 WPScan
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.44 CVE-2026-86311 Wordfence
5.3 Medium All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Other Unauthenticated Insufficient Credential Protection via Authorization Basic Header No login needed ≤ 7.110 CVE-2026-89064 Wordfence
5.4 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post < 9.1.0 Fixed in 9.1.0 CVE-2026-89031 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Information Disclosure Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user < 9.1.0 Fixed in 9.1.0 CVE-2026-89030 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler < 9.1.0 Fixed in 9.1.0 CVE-2026-89029 VulnCheck
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Other Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission No login needed < 1.5.95 Fixed in 1.5.95 CVE-2026-86475 WPScan
5.3 Medium Eventin Plugin wp-event-solution Price Manipulation Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay No login needed < 4.1.24 Fixed in 4.1.24 CVE-2026-84906 WPScan
4.8 Medium Formidable Forms Plugin formidable Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token No login needed 6.34 – < 6.35 Fixed in 6.35 CVE-2026-19857 WPScan
6.1 Medium Royal Elementor Addons Plugin Content Injection Unauthenticated Stored HTML Injection in Form Notification Emails No login needed < 1.7.1067 Fixed in 1.7.1067 CVE-2026-13407 WPScan
5.3 Medium KBoard Plugin Broken Access Control Unauthenticated Board Media Deletion via IDOR No login needed < 6.7 Fixed in 6.7 CVE-2026-88910 WPScan
5.4 Medium WPBot Plugin chatbot Broken Access Control Subscriber+ Claude AI Settings Update 8.7.2 – < 8.7.6 Fixed in 8.7.6 CVE-2026-87959 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Internal Notes Disclosure via Service and Category REST Routes No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87907 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Staff PII Disclosure via Agent REST Route No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87896 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Cross-Site Request Forgery Subscription Cancellation via CSRF No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87860 WPScan
5.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87854 WPScan
5.7 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Denial of Service Subscriber+ DoS via seraph_accel_State Update < 2.29.24 Fixed in 2.29.24 CVE-2026-87828 WPScan
5.3 Medium Newsletter Plugin newsletter Open Redirect Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter No login needed < 9.3.7 Fixed in 9.3.7 CVE-2026-86823 WPScan
6.8 Medium Visualizer Plugin visualizer Cross-Site Scripting Contributor+ Stored XSS via JSON Data Source < 4.0.8 Fixed in 4.0.8 CVE-2026-86784 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Unpublished Course Disclosure via REST API No login needed 4.2.7.1 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86449 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Student Enrollment Disclosure via load_content_via_ajax No login needed 4.4.6 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86447 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Question Bank Disclosure via load_content_via_ajax No login needed 4.2.9 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86445 WPScan
4.3 Medium Formidable Forms Plugin formidable Content Injection Unauthenticated Stored Content Injection via 'updated_by' Parameter No login needed 6.34 – < 6.35 Fixed in 6.35 CVE-2026-85641 WPScan
4.3 Medium Tutor LMS 4.0.0 Plugin Information Disclosure < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-85572 WPScan
4.3 Medium FluentBoards Plugin fluent-boards Information Disclosure Subscriber+ Private Board Membership Disclosure via IDOR < 2.0.15 Fixed in 2.0.15 CVE-2026-85349 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only