WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,251–6,300 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 126 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Nexi XPay Plugin cartasi-x-pay Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 8.3.0 CVE-2025-15565 Wordfence
4.3 Medium Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) Plugin Broken Access Control Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 4.1.8 CVE-2026-4109 Wordfence
6.5 Medium Germanized for WooCommerce Plugin woocommerce-germanized Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.20.5 CVE-2026-2582 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
4.4 Medium WholeSale Products Dynamic Pricing Management WooCommerce Plugin wholesale-products-dynamic-pricing-management-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2 CVE-2026-4479 Wordfence
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute ≤ 3.3.5 CVE-2026-4059 Wordfence
6.4 Medium Surbma | Booking.com Plugin surbma-bookingcom-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1 CVE-2026-1607 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box No login needed ≤ 1.15.40 CVE-2026-4388 Wordfence
7.2 High BackWPup Plugin backwpup Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter ≤ 5.6.6 CVE-2026-6227 Wordfence
7.5 High JetEngine Plugin SQL Injection Unauthenticated SQL Injection via '_cct_search' Parameter No login needed ≤ 3.8.6.1 CVE-2026-4352 Wordfence
9.1 Critical LearnPress Plugin learnpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion No login needed ≤ 4.3.2.8 CVE-2026-4365 Wordfence
6.1 Medium User Registration & Membership Plugin user-registration Open Redirect Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter No login needed ≤ 5.1.4 CVE-2026-6203 Wordfence
8.6 High Product Filter for WooCommerce by WBW Plugin woo-product-filter SQL Injection Unauthenticated SQLi No login needed < 3.1.3 Fixed in 3.1.3 CVE-2026-3830 WPScan
6.8 Medium Form Maker Plugin form-maker SQL Injection No login needed < 1.15.38 Fixed in 1.15.38 CVE-2025-15441 WPScan
7.1 High wpForo Forum Plugin wpforo Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter ≤ 3.0.2 CVE-2026-5809 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification ≤ 3.9.7 CVE-2026-3371 Wordfence
5.0 Medium UsersWP Plugin userswp Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop' Parameter ≤ 1.2.58 CVE-2026-4979 Wordfence
8.8 High BuddyPress Groupblog Plugin bp-groupblog Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR ≤ 1.9.3 CVE-2026-5144 Wordfence
6.4 Medium BlockArt Blocks Plugin blockart-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'clientId' Block Attribute ≤ 2.2.15 CVE-2026-3498 Wordfence
7.2 High Optimole Plugin optimole-wp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter No login needed ≤ 4.2.2 CVE-2026-5217 Wordfence
6.5 Medium LifterLMS Plugin lifterlms SQL Injection Authenticated (Custom+) SQL Injection via 'order' Parameter ≤ 9.2.1 CVE-2026-5207 Wordfence
6.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute ≤ 12.8.9 CVE-2026-4895 Wordfence
6.1 Medium Optimole Plugin optimole-wp Cross-Site Scripting Reflected Cross-Site Scripting via Page Profiler URL No login needed ≤ 4.2.3 CVE-2026-5226 Wordfence
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment ≤ 3.9.7 CVE-2026-3358 Wordfence
7.1 High Cerato Plugin cerato Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.18 CVE-2025-58920 Patchstack
8.1 High VideoPro Plugin videopro Local File Inclusion No login needed ≤ 2.3.8.1 CVE-2025-58913 Patchstack
7.5 High Case Theme User Plugin case-theme-user Local File Inclusion No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-5804 Patchstack
7.1 High Gravity SMTP Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall ≤ 2.1.4 CVE-2026-4162 Wordfence
6.5 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Arbitrary Wishlist Renaming via IDOR No login needed < 4.13.0 Fixed in 4.13.0 CVE-2026-4432 WPScan
6.5 Medium YML for Yandex Market Plugin yml-for-yandex-market Remote Code Execution Shop Manager+ RCE via Feed Generation No login needed < 5.0.26 Fixed in 5.0.26 CVE-2025-14545 WPScan
6.4 Medium AddFunc Head & Footer Code Plugin addfunc-head-footer-code Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields ≤ 2.3 CVE-2026-2305 Wordfence
4.3 Medium UsersWP Plugin userswp Broken Access Control Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter ≤ 1.2.58 CVE-2026-4977 Wordfence
6.1 Medium Royal WordPress Backup & Restore Plugin royal-backup-reset Cross-Site Scripting Reflected Cross-Site Scripting via 'wpr_pending_template' Parameter No login needed ≤ 1.0.16 CVE-2026-4305 Wordfence
8.1 High Perfmatters Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter ≤ 2.5.9 CVE-2026-4351 Wordfence
4.3 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Reset No login needed ≤ 3.0.4 CVE-2026-1924 Wordfence
6.4 Medium Webling Plugin webling Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'title' Parameter ≤ 3.9.0 CVE-2026-1263 Wordfence
4.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization to Authenticated (Contributor+) Media File Protection Removal ≤ 3.3.51 CVE-2026-4057 Wordfence
7.5 High Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter No login needed ≤ 3.9.7 CVE-2026-3360 Wordfence
5.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Authentication Bypass Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter No login needed ≤ 5.103.0 CVE-2026-4664 Wordfence
5.4 Medium WP-Optimize Plugin wp-optimize Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation ≤ 4.5.0 CVE-2026-2712 Wordfence
9.8 Critical Smart Slider 3 Pro Plugin nextend-smart-slider3-pro Remote Code Execution Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit No login needed 3.5.1.35 Fixed in 3.5.1.36 CVE-2026-34424 VulnCheck
8.2 High adivaha Travel Plugin adiaha-hotel SQL Injection WordPress adivaha Travel Plugin 2.3 SQL Injection via pid No login needed 2.3 CVE-2023-54359 VulnCheck
6.1 Medium adivaha Travel Plugin adiaha-hotel Cross-Site Scripting WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile No login needed 2.3 CVE-2023-54358 VulnCheck
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
6.4 Medium List category posts Plugin list-category-posts Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode ≤ 0.94.0 CVE-2026-3005 Wordfence
6.4 Medium UsersWP Plugin userswp Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution ≤ 1.2.60 CVE-2026-5742 Wordfence
6.4 Medium Ultimate FAQ Accordion Plugin ultimate-faqs Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content ≤ 2.4.7 CVE-2026-4336 Wordfence
9.8 Critical Quick Playground Plugin quick-playground Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.1 CVE-2026-1830 Wordfence
4.4 Medium Experto Dashboard for WooCommerce Plugin experto-custom-dashboard Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting ≤ 1.0.4 CVE-2026-3574 Wordfence
4.3 Medium MStore API Plugin mstore-api Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update ≤ 4.18.3 CVE-2026-3568 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only