WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,051–6,100 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 122 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium BetterDocs Plugin betterdocs Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-42644 Patchstack
5.9 Medium Image Widget Plugin image-widget Cross-Site Scripting ≤ 4.4.11 Fixed in 4.4.12 CVE-2026-42643 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42642 Patchstack
5.4 Medium Share This Image Plugin share-this-image Server-Side Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-42641 Patchstack
5.3 Medium Complianz – GDPR/CCPA Cookie Consent Plugin complianz-gdpr Broken Access Control GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint No login needed ≤ 7.4.5 CVE-2026-4019 Wordfence
6.5 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-42412 Patchstack
7.3 High SureForms Pro Plugin sureforms-pro Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-42377 Patchstack
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via 'amount' Parameter No login needed ≤ 1.7.06 CVE-2026-4911 Wordfence
6.4 Medium Woostify Plugin woostify Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js Library via data-lity Attribute in Custom HTML Block ≤ 2.5.0 CVE-2026-4805 Wordfence
5.4 Medium Check & Log Email Plugin check-email Cross-Site Scripting Unauthenticated Stored XSS < 2.0.13 Fixed in 2.0.13 CVE-2026-5306 WPScan
6.4 Medium Social Post Embed Plugin social-post-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Threads Embed ≤ 2.0.1 CVE-2026-6809 Wordfence
6.4 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 4.2.8 CVE-2026-6725 Wordfence
6.4 Medium Timeline Blocks for Gutenberg Plugin timeline-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute ≤ 1.1.10 CVE-2026-6551 Wordfence
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability ≤ 5.4.1 CVE-2026-6741 Wordfence
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-42410 Patchstack
9.8 Critical Directorist Social Login Plugin directorist-social-login Privilege Escalation No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-22337 Patchstack
9.3 Critical Directorist Booking Plugin directorist-booking SQL Injection No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-22336 Patchstack
7.7 High Templately Plugin templately Information Disclosure Sensitive Data Exposure ≤ 3.6.1 Fixed in 3.6.2 CVE-2026-42379 Patchstack
8.8 High Highland Software Custom Role Manager Plugin highland-software-custom-role-manager Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.0 CVE-2026-7106 Wordfence
6.4 Medium ITERAS Plugin iteras Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.2 CVE-2026-4078 Wordfence
5.3 Medium Liaison Site Prober Plugin liaison-site-prober Broken Access Control Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint No login needed ≤ 1.2.1 CVE-2026-3569 Wordfence
4.3 Medium Taqnix Plugin taqnix Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJAX Action No login needed ≤ 1.0.3 CVE-2026-3565 Wordfence
4.3 Medium HubSpot All-In-One Marketing - Forms, Popups, Live Chat Plugin leadin Broken Access Control Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure ≤ 11.3.32 CVE-2025-11762 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover No login needed ≤ 1.2.63 CVE-2026-6810 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field ≤ 1.7.1056 CVE-2026-5428 Wordfence
5.3 Medium WP Books Gallery Plugin wp-books-gallery Broken Access Control Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter No login needed ≤ 4.8.0 CVE-2026-5347 Wordfence
8.1 High Drag and Drop File Upload for Contact Form 7 Plugin drag-and-drop-file-upload-for-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass No login needed ≤ 1.1.3 CVE-2026-5364 Wordfence
5.3 Medium ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token' No login needed ≤ 9.1.2 CVE-2026-5488 Wordfence
5.3 Medium Maxi Blocks Plugin maxi-blocks Broken Access Control Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter No login needed ≤ 2.1.8 CVE-2026-2028 Wordfence
4.3 Medium BetterDocs Plugin betterdocs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage ≤ 4.3.11 CVE-2026-6393 Wordfence
9.9 Critical FunnelFormsPro Plugin funnelforms-pro Remote Code Execution ≤ 3.8.1 CVE-2026-39440 Patchstack
6.5 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting ≤ 3.3 Fixed in 3.4 CVE-2025-62110 Patchstack
4.3 Medium ACF Galerie 4 Plugin acf-galerie-4 Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-62104 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
7.2 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process ≤ 9.1.2 CVE-2026-5464 Wordfence
3.5 Low WP reCaptcha by WebDesignBy Plugin Cross-Site Scripting Admin+ Stored XSS < 2.0 Fixed in 2.0 CVE-2026-4512 WPScan
5.3 Medium HT Mega Plugin Information Disclosure Unauthenticated PII Disclosure No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-4106 WPScan
6.4 Medium WP Store Locator Plugin wp-store-locator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta ≤ 2.2.261 CVE-2026-3361 Wordfence
9.8 Critical Breeze Cache Plugin breeze Arbitrary File Upload Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote No login needed ≤ 2.4.4 CVE-2026-3844 Wordfence
5.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML ≤ 3.5.5 CVE-2026-2951 Wordfence
6.4 Medium Social Rocket – Social Sharing Plugin social-rocket Cross-Site Scripting Social Sharing Plugin <= 1.3.4.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via id ≤ 1.3.4.2 CVE-2026-1923 Wordfence
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed < 7.13.2 Fixed in 7.13.2 CVE-2025-58922 Patchstack
6.4 Medium Gallagher Website Design Plugin gallagher-website-design Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'prefix' Shortcode Attribute ≤ 2.6.4 CVE-2026-1913 Wordfence
6.4 Medium Gutentools Plugin gutentools Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes ≤ 1.1.3 CVE-2026-1395 Wordfence
4.3 Medium Emailchef Plugin emailchef Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion ≤ 3.5.1 CVE-2026-1930 Wordfence
6.4 Medium CI HUB Connector Plugin ci-hub-connector Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.2.106 CVE-2026-4353 Wordfence
4.3 Medium Google PageRank Display Plugin google-pagerank-display Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via Settings Page No login needed ≤ 1.4 CVE-2026-6294 Wordfence
6.4 Medium Posts map Plugin posts-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute ≤ 0.1.3 CVE-2026-6236 Wordfence
4.3 Medium DX Unanswered Comments Plugin dx-unanswered-comments Cross-Site Request Forgery Cross-Site Request Forgery via Settings Update No login needed ≤ 1.7 CVE-2026-4138 Wordfence
9.1 Critical Create DB Tables Plugin create-db-tables Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php No login needed ≤ 1.2.1 CVE-2026-4119 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only