WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High CP Media Player Plugin audio-and-video-player Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-78281 Patchstack
7.2 High Fluent Boards Pro Plugin fluent-boards-pro PHP Object Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78276 Patchstack
6.8 Medium Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Deletion ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78275 Patchstack
9.1 Critical Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Upload ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78274 Patchstack
6.5 Medium Fluent Boards Pro Plugin fluent-boards-pro Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78273 Patchstack
7.2 High FluentCRM Pro Plugin fluentcampaign-pro Privilege Escalation ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78271 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-78261 Patchstack
9.3 Critical Epayco Plugin epayco-gateway SQL Injection No login needed ≤ 8.4.6 Fixed in 8.4.7 CVE-2026-78260 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed ≤ 2.0.63 CVE-2026-32566 Patchstack
8.5 High ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type SQL Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection ≤ 2.0.63 CVE-2026-32564 Patchstack
8.5 High Kadence Shop Kit Plugin kadence-shop-kit SQL Injection ≤ 3.0.6 Fixed in 3.0.6.1 CVE-2026-32550 Patchstack
9.3 Critical Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro SQL Injection No login needed ≤ 11.17 Fixed in 11.18 CVE-2026-32479 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
5.4 Medium Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress Broken Access Control ≤ 3.20 Fixed in 3.21 CVE-2026-81279 Patchstack
6.4 Medium Password Protect WordPress Lite Plugin password-protect-page Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.21 CVE-2025-9878 Wordfence
7.1 High Stripe Payments Plugin stripe-payments Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-78282 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
9.8 Critical TranslatePress Plugin translatepress-multilingual Privilege Escalation No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-78267 Patchstack
6.5 Medium AutomatorWP Plugin automatorwp Broken Access Control ≤ 5.8.3 Fixed in 5.8.4 CVE-2026-78266 Patchstack
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection No login needed ≤ 6.17.2 Fixed in 6.17.3 CVE-2026-78265 Patchstack
7.1 High Toolset Blocks Plugin toolset-blocks Cross-Site Scripting No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2026-78264 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.2.1 Fixed in 5.29.3 CVE-2026-78263 Patchstack
9.8 Critical WP Project Manager Plugin wedevs-project-manager PHP Object Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-78262 Patchstack
7.3 High WPLegalPages Plugin wplegalpages Authentication Bypass Broken Authentication No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-78259 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed ≤ 2.0.63 CVE-2026-32563 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
8.8 High MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator Plugin magicai-wp Local File Inclusion AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion ≤ 1.4 CVE-2026-32560 Patchstack
9.9 Critical UltimateAI Plugin ultimate_ai Arbitrary File Upload ≤ 3.1.0 CVE-2026-32559 Patchstack
7.1 High Boost Plugin boost Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2026-32556 Patchstack
9.3 Critical Boost Plugin boost SQL Injection No login needed ≤ 2.0.4 CVE-2026-32555 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed ≤ 3.1.8 CVE-2026-32554 Patchstack
6.5 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 Fixed in 2.6.6 CVE-2026-27364 Patchstack
8.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Arbitrary File Deletion No login needed ≤ 3.7.42 Fixed in 3.7.43 CVE-2026-78284 Patchstack
8.1 High Måne Theme mane Local File Inclusion No login needed ≤ 1.7 CVE-2026-66670 Patchstack
9.8 Critical FreightCo Theme freightco PHP Object Injection No login needed ≤ 1.1.15 CVE-2026-66650 Patchstack
9.8 Critical Jawn Theme jawn Privilege Escalation No login needed ≤ 1.4.2 CVE-2026-66648 Patchstack
7.1 High Urna Theme urna Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2026-66610 Patchstack
9.8 Critical WP Cafe Pro Plugin wpcafe-pro Local File Inclusion No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66587 Patchstack
7.5 High WP Cafe Pro Plugin wpcafe-pro Information Disclosure Sensitive Data Exposure No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66585 Patchstack
9.8 Critical Affiliate Pro - Affiliate Program for WooCommerce & Plugin wp-wc-affiliate-program Privilege Escalation Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation No login needed ≤ 8.9.1 CVE-2026-32558 Patchstack
9.3 Critical Woo Essential Plugin woo-essential SQL Injection No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-32551 Patchstack
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.1 High Brave Conversion Engine (PRO) Plugin bravepopup-pro Cross-Site Scripting No login needed ≤ 0.8.6 Fixed in 0.8.7 CVE-2026-32476 Patchstack
8.5 High ProLancer Element Plugin prolancer-element SQL Injection ≤ 1.4.8 CVE-2026-32471 Patchstack
7.1 High ProLancer Element Plugin prolancer-element Broken Access Control ≤ 1.4.8 CVE-2026-28190 Patchstack
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
7.5 High Super Forms Plugin super-forms Path Traversal Arbitrary File Download No login needed ≤ 6.3.315 CVE-2026-28167 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.9 CVE-2026-28166 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only