WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,201–6,250 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 125 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium WP Docs Plugin wp-docs Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_options[icon_size]' ≤ 2.2.9 CVE-2026-3878 Wordfence
6.1 Medium CodeColorer Plugin codecolorer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'class' attribute in 'cc' Comment Shortcode No login needed ≤ 0.10.1 CVE-2026-4032 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode ≤ 7.4.9 CVE-2026-3885 Wordfence
6.4 Medium WP YouTube Lyte Plugin wp-youtube-lyte Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode ≤ 1.7.29 CVE-2026-3299 Wordfence
9.8 Critical Barcode Scanner (+Mobile App) Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation via Insecure Token Authentication No login needed ≤ 1.11.0 CVE-2026-4880 Wordfence
4.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription ≤ 4.16.12 CVE-2026-4949 Wordfence
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium YouTube Showcase Plugin youtube-showcase Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-15636 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.6.0 CVE-2025-15635 Patchstack
4.3 Medium Userpro Plugin userpro Cross-Site Request Forgery No login needed ≤ 5.1.11 Fixed in 5.1.11 CVE-2025-53444 Patchstack
6.1 Medium Product Pricing Table by WooBeWoo Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion No login needed ≤ 1.1.0 CVE-2026-1852 Wordfence
4.3 Medium MyRewards Plugin woorewards Broken Access Control ≤ 5.7.3 Fixed in 5.7.4 CVE-2026-40786 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2026-40778 Patchstack
8.1 High Contact Form by WPForms Plugin wpforms-lite Cross-Site Request Forgery No login needed ≤ 1.10.0.2 Fixed in 1.10.0.3 CVE-2026-40764 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed ≤ 1.7.1056 Fixed in 1.7.1057 CVE-2026-40763 Patchstack
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
5.3 Medium Nelio AB Testing Plugin nelio-ab-testing Information Disclosure Sensitive Data Exposure No login needed ≤ 8.2.8 Fixed in 8.3.0 CVE-2026-40742 Patchstack
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
5.3 Medium COMPE Plugin compe-woo-compare-products Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-40737 Patchstack
6.5 Medium Categories Images Plugin categories-images Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2026-40734 Patchstack
5.3 Medium ThemeGrill Demo Importer Plugin themegrill-demo-importer Broken Access Control No login needed ≤ 2.0.0.6 Fixed in 2.0.0.7 CVE-2026-40730 Patchstack
4.3 Medium 3D viewer – Embed 3D Models Plugin 3d-viewer Broken Access Control Embed 3D Models plugin <= 1.8.5 - Broken Access Control ≤ 1.8.5 Fixed in 1.8.6 CVE-2026-40729 Patchstack
4.3 Medium Magazine Blocks Plugin magazine-blocks Broken Access Control ≤ 1.8.3 Fixed in 1.8.4 CVE-2026-40728 Patchstack
6.4 Medium Power Charts Plugin wpgo-power-charts-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 0.1.0 CVE-2026-4011 Wordfence
7.2 High Accessibly Plugin otm-accessibly Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widget Source Injection via REST API No login needed ≤ 3.0.3 CVE-2026-3643 Wordfence
6.4 Medium WM JqMath Plugin wm-jqmath Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute ≤ 1.3 CVE-2026-3998 Wordfence
5.3 Medium MetForm Pro Plugin Price Manipulation Unauthenticated Payment Amount Manipulation via 'mf-calculation' No login needed ≤ 3.9.7 CVE-2026-1782 Wordfence
6.1 Medium OPEN-BRAIN Plugin open-brain Cross-Site Request Forgery No login needed ≤ 0.5.0 CVE-2026-4091 Wordfence
5.3 Medium Katalogportal-pdf-sync Widget Plugin katalogportal-pdf-sync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Information Disclosure via 'katalogportal_shortcodePrinter' AJAX Action No login needed ≤ 1.0.0 CVE-2026-3649 Wordfence
9.8 Critical Visa Acceptance Solutions Plugin visa-acceptance-solutions Authentication Bypass Unauthenticated Authentication Bypass via Billing Email No login needed ≤ 2.1.0 CVE-2026-3461 Wordfence
6.4 Medium Coachific Shortcode Plugin coachific-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'userhash' Shortcode Attribute ≤ 1.0 CVE-2026-4005 Wordfence
4.3 Medium Petje.af Plugin petje-af Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Action No login needed ≤ 2.1.8 CVE-2026-4002 Wordfence
5.3 Medium e-shot Plugin e-shot-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX No login needed ≤ 1.0.2 CVE-2026-3642 Wordfence
6.4 Medium WP Circliful Plugin wp-circliful Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.2 CVE-2026-3659 Wordfence
7.2 High Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.1.5 CVE-2026-5694 Wordfence
6.4 Medium VI: Include Post By Plugin vi-include-post-by Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_container' Shortcode Attribute ≤ 0.4.200706 CVE-2026-5717 Wordfence
8.8 High Login as User Plugin one-click-login-as-user Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie ≤ 1.0.1 CVE-2026-5617 Wordfence
4.3 Medium Inquiry form to posts or pages Plugin inquiry-form-to-posts-or-pages Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'inq_header' Parameter No login needed ≤ 1.0 CVE-2026-6293 Wordfence
9.8 Critical WebStack Theme Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2024 CVE-2026-1555 Wordfence
5.4 Medium Avada (Fusion) Builder Plugin Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution ≤ 3.15.1 CVE-2026-1509 Wordfence
5.3 Medium Advanced Custom Fields (ACF®) Plugin advanced-custom-fields Broken Access Control Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters No login needed ≤ 6.7.0 CVE-2026-4812 Wordfence
4.3 Medium Avada (Fusion) Builder Plugin Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference ≤ 3.15.1 CVE-2026-1541 Wordfence
7.2 High Age Verification & Identity Verification by Token of Trust Plugin token-of-trust Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'description' Parameter No login needed ≤ 3.32.3 CVE-2026-2834 Wordfence
4.4 Medium List View Google Calendar Plugin list-view-google-calendar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Event Description ≤ 7.4.3 CVE-2026-2396 Wordfence
5.3 Medium 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Broken Access Control PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure No login needed ≤ 1.16.17 CVE-2026-1314 Wordfence
6.5 Medium Eleganzo Theme Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary Directory Deletion ≤ 1.2 CVE-2025-15470 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only