WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print Job No login needed ≤ 6.5.2 CVE-2026-84279 Wordfence
6.1 Medium JetFormBuilder Plugin jetformbuilder Cross-Site Scripting Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field No login needed ≤ 3.6.5.3 CVE-2026-92212 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta No login needed ≤ 6.5.2 CVE-2026-84281 Wordfence
7.2 High AMP for WP Plugin accelerated-mobile-pages Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation No login needed ≤ 1.1.16 CVE-2026-83591 Wordfence
6.4 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') ≤ 2.8.181 CVE-2026-93897 Wordfence
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
4.0 Medium Link Library Plugin link-library Server-Side Request Forgery Unauthenticated SSRF via Reciprocal Link Validation No login needed 7.8.8 – < 7.9.6 Fixed in 7.9.6 CVE-2026-78397 WPScan
4.1 Medium Link Library Plugin link-library Path Traversal Contributor+ Path Traversal via 'filepath' Parameter < 7.9.6 Fixed in 7.9.6 CVE-2026-78394 WPScan
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links No login needed < 7.9.6 Fixed in 7.9.6 CVE-2026-78393 WPScan
6.4 Medium CSS & JavaScript Toolbox Plugin css-javascript-toolbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox Shortcode ≤ 12.0.6 CVE-2025-14814 Wordfence
4.3 Medium Spectra Legacy – Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Information Disclosure Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.20.0 CVE-2026-16302 Wordfence
6.5 Medium Custom Thank You Page for WooCommerce Plugin wc-custom-thank-you Broken Access Control Missing Authorization to Unauthenticated Settings Export and Settings Reset No login needed ≤ 1.1.2 CVE-2026-4806 Wordfence
4.3 Medium MailerLite – Signup forms (official) Plugin official-mailerlite-sign-up-forms Broken Access Control Signup forms (official) <= 1.7.21 - Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion ≤ 1.7.21 CVE-2026-3253 Wordfence
5.4 Medium Kirki – Freeform Page Builder, Website Builder & Customizer Plugin kirki Server-Side Request Forgery Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter No login needed ≤ 6.2.0 CVE-2026-18335 Wordfence
9.8 Critical Visual Composer Website Builder Plugin visualcomposer Local File Inclusion Unauthenticated Local File Inclusion via 'vcv-template' Parameter No login needed ≤ 45.16.0 CVE-2026-12227 Wordfence
6.4 Medium WP Multilang – Translation and Multilingual Plugin Cross-Site Scripting Translation and Multilingual Plugin <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content ≤ 2.4.31 CVE-2026-15731 Wordfence
8.8 High YOP Poll Plugin yop-poll Privilege Escalation Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route No login needed ≤ 7.0.10 CVE-2026-85682 Wordfence
7.5 High eesy_ID2WP – Publish InDesign HTML5 Plugin Path Traversal Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter No login needed ≤ 1.0.3 CVE-2026-77193 Wordfence
4.3 Medium Events Manager Plugin events-manager Information Disclosure Subscriber+ Unpublished Event and Location Disclosure via 'owner' Parameter 7.4.1 – < 7.4.5 Fixed in 7.4.5 CVE-2026-93662 WPScan
2.7 Low Events Manager Plugin events-manager Broken Access Control Contributor+ Arbitrary Ticket Overwrite via IDOR < 7.4.5 Fixed in 7.4.5 CVE-2026-93661 WPScan
6.8 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting Contributor+ Stored XSS via Word to Category < 2.8.26 Fixed in 2.8.26 CVE-2026-89005 WPScan
2.7 Low WPeMatico RSS Feed Fetcher Plugin wpematico Information Disclosure Contributor+ Campaign Configuration and Log Disclosure via IDOR < 2.8.26 Fixed in 2.8.26 CVE-2026-89004 WPScan
6.8 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting Contributor+ Stored XSS via Campaign Item Preview < 2.8.26 Fixed in 2.8.26 CVE-2026-89002 WPScan
4.3 Medium MasterStudy LMS Plugin Broken Access Control Subscriber+ Lesson Completion Record Creation < 3.7.50 Fixed in 3.7.50 CVE-2026-88847 WPScan
5.3 Medium MasterStudy LMS 2.3.0 Plugin Broken Access Control < 3.7.50 - Unauthenticated Account Creation with Registration Disabled No login needed 2.3.0 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88846 WPScan
4.3 Medium MasterStudy LMS 2.3.0 Plugin Broken Access Control < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import 2.3.0 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88845 WPScan
7.2 High MasterStudy LMS 3.5.29 Plugin Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget 3.5.29 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88843 WPScan
3.5 Low The Post Grid Plugin the-post-grid Content Injection Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening < 7.9.5 Fixed in 7.9.5 CVE-2026-84151 WPScan
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Quiz Answer Key Disclosure < 3.4.2 Fixed in 3.4.2 CVE-2026-82850 WPScan
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Arbitrary User Course Progress Disclosure via IDOR < 3.4.2 Fixed in 3.4.2 CVE-2026-82849 WPScan
6.5 Medium 10Web Booster Plugin tenweb-speed-optimizer Information Disclosure Unauthenticated Connection Secret Disclosure and Deletion No login needed < 2.34.0 Fixed in 2.34.0 CVE-2026-82195 WPScan
7.5 High wpForo Forum Plugin wpforo PHP Object Injection Subscriber+ PHP Object Injection via Profile Fields < 3.1.6 Fixed in 3.1.6 CVE-2026-80513 WPScan
6.8 Medium CMB2 Plugin cmb2 Privilege Escalation Subscriber+ Arbitrary Option Corruption via oEmbed Handler < 2.13.0 Fixed in 2.13.0 CVE-2026-80338 WPScan
6.8 Medium WPForms Lite Plugin Broken Access Control Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent No login needed 1.8.8.2 – < 2.0.2 Fixed in 2.0.2 CVE-2026-74991 WPScan
9.8 Critical Paytium: Mollie payment forms & donations Plugin paytium Privilege Escalation Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter No login needed ≤ 5.0.3 CVE-2026-18467 Wordfence
8.8 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields ≤ 2.4.17 CVE-2026-86583 Wordfence
8.1 High EthPress Plugin ethpress Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 2.3.5 CVE-2026-19125 Wordfence
7.6 High W4 Post List Plugin w4-post-list SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-96826 Patchstack
7.5 High Loops & Logic Plugin tangible-loops-and-logic Broken Access Control No login needed ≤ 4.2.4 Fixed in 4.3.0 CVE-2026-95604 Patchstack
7.2 High Reycob Product Import Export Plugin reycob-product-import-export PHP Object Injection ≤ 2.3.0 Fixed in 2.4.0 CVE-2026-95603 Patchstack
6.5 Medium YITH WooCommerce Request A Quote Plugin yith-woocommerce-request-a-quote Broken Access Control Insecure Direct Object References (IDOR) No login needed < 4.46.1 Fixed in 4.46.1 CVE-2026-95602 Patchstack
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-95601 Patchstack
5.3 Medium TrustedLogin Connector Plugin trustedlogin-connector Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2026-95600 Patchstack
7.6 High Ultimeter Plugin ultimeter SQL Injection ≤ 3.0.8 Fixed in 3.1.0 CVE-2026-95593 Patchstack
5.3 Medium Team Plugin tlp-team Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-95592 Patchstack
7.1 High Tainacan Plugin tainacan SQL Injection ≤ 1.2.0 Fixed in 1.3.0 CVE-2026-95590 Patchstack
6.5 Medium Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting ≤ 3.5.50 Fixed in 3.5.51 CVE-2026-95586 Patchstack
6.5 Medium PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) ≤ 11.4.1 Fixed in 11.4.2 CVE-2026-95530 Patchstack
7.1 High Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting No login needed ≤ 5.5.1.1 Fixed in 5.5.1.2 CVE-2026-95529 Patchstack
7.1 High Core Web Vitals & PageSpeed Booster Plugin core-web-vitals-pagespeed-booster Cross-Site Scripting No login needed ≤ 1.0.31 Fixed in 1.0.32 CVE-2026-95528 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only