WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical WP Super Edit Plugin wp-super-edit Arbitrary File Upload WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload No login needed ≤ 2.5.4 CVE-2021-47965 VulnCheck
9.8 Critical Receive Notifications After Form Submitting – Form Notify for Any Forms Plugin form-notify Authentication Bypass Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth Callback No login needed ≤ 1.1.10 CVE-2026-5229 Wordfence
9.1 Critical InfusedWoo Pro Plugin Broken Access Control Unauthenticated Missing Authorization to Arbitrary Post Deletion via Multiple Parameters No login needed ≤ 5.1.2 CVE-2026-6512 Wordfence
9.8 Critical InfusedWoo Pro Plugin Broken Access Control Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe' No login needed ≤ 5.1.2 CVE-2026-6510 Wordfence
9.8 Critical Career Section Plugin career-section Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7 CVE-2026-6271 Wordfence
9.8 Critical Burst Statistics Plugin burst-statistics Authentication Bypass Authentication Bypass to Admin Account Takeover No login needed 3.4.0 – 3.4.1.1 CVE-2026-8181 Wordfence
9.8 Critical Download From Files Plugin download-from-files Arbitrary File Upload WordPress Download From Files 1.48 Arbitrary File Upload No login needed ≤ 1.48 CVE-2021-47940 VulnCheck
9.8 Critical MStore API Plugin mstore-api Arbitrary File Upload WordPress MStore API 2.0.6 Arbitrary File Upload No login needed 2.0.6 CVE-2021-47933 VulnCheck
9.3 Critical WebinarIgnition Plugin webinar-ignition SQL Injection No login needed ≤ 4.08.253 CVE-2026-40797 Patchstack
9.8 Critical GeekyBot Plugin geeky-bot Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation via 'geekybot_frontendajax' AJAX Action No login needed ≤ 1.2.2 CVE-2026-5294 Wordfence
9.8 Critical Mentoring Plugin Privilege Escalation Unauthenticated Privilege Escalation in mentoring_process_registration No login needed ≤ 1.2.8 CVE-2025-13618 Wordfence
9.8 Critical MoreConvert Pro Plugin smart-wishlist-for-more-convert Authentication Bypass Authentication Bypass via Waitlist Guest Verification Token Reuse No login needed ≤ 1.9.14 CVE-2026-5722 Wordfence
9.8 Critical User Registration Advanced Fields Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6.20 CVE-2026-4882 Wordfence
9.8 Critical User Verification by PickPlugins Plugin user-verification Authentication Bypass Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint No login needed ≤ 2.0.46 CVE-2026-7458 Wordfence
9.8 Critical Temporary Login Plugin temporary-login Authentication Bypass Authentication Bypass to Account Takeover No login needed ≤ 1.0.0 CVE-2026-7567 Wordfence
9.8 Critical Directorist Social Login Plugin directorist-social-login Privilege Escalation No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-22337 Patchstack
9.3 Critical Directorist Booking Plugin directorist-booking SQL Injection No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-22336 Patchstack
9.9 Critical FunnelFormsPro Plugin funnelforms-pro Remote Code Execution ≤ 3.8.1 CVE-2026-39440 Patchstack
9.8 Critical Breeze Cache Plugin breeze Arbitrary File Upload Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote No login needed ≤ 2.4.4 CVE-2026-3844 Wordfence
9.1 Critical Create DB Tables Plugin create-db-tables Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php No login needed ≤ 1.2.1 CVE-2026-4119 Wordfence
9.8 Critical Sendmachine Plugin sendmachine Privilege Escalation Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests No login needed ≤ 1.0.20 CVE-2026-6235 Wordfence
9.8 Critical Essentialplugin Plugins (Various Versions) Plugin Other Injected Backdoor No login needed 1.4.6, 1.5.6, 1.5.7, … CVE-2026-6443 Wordfence
9.8 Critical Riaxe Product Customizer Plugin riaxe-product-customizer Broken Access Control Missing Authorization to Unauthenticated Arbitrary Options Update to Privilege Escalation via 'install-imprint' AJAX Action No login needed ≤ 2.1.2 CVE-2026-3596 Wordfence
9.8 Critical Barcode Scanner (+Mobile App) Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation via Insecure Token Authentication No login needed ≤ 1.11.0 CVE-2026-4880 Wordfence
9.8 Critical Visa Acceptance Solutions Plugin visa-acceptance-solutions Authentication Bypass Unauthenticated Authentication Bypass via Billing Email No login needed ≤ 2.1.0 CVE-2026-3461 Wordfence
9.8 Critical WebStack Theme Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2024 CVE-2026-1555 Wordfence
9.1 Critical LearnPress Plugin learnpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion No login needed ≤ 4.3.2.8 CVE-2026-4365 Wordfence
9.8 Critical Smart Slider 3 Pro Plugin nextend-smart-slider3-pro Remote Code Execution Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit No login needed 3.5.1.35 Fixed in 3.5.1.36 CVE-2026-34424 VulnCheck
9.8 Critical Quick Playground Plugin quick-playground Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.1 CVE-2026-1830 Wordfence
9.8 Critical ProSolution WP Client Plugin prosolution-wp-client Arbitrary File Upload Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess No login needed ≤ 1.9.9 CVE-2026-2942 Wordfence
9.6 Critical Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Remote Code Execution No login needed ≤ 3.2 CVE-2026-39640 Patchstack
9.6 Critical Appointment Plugin appointment Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 3.5.5 CVE-2026-39620 Patchstack
9.6 Critical Busiprof Plugin busiprof Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2026-39619 Patchstack
9.6 Critical Bluestreet Plugin bluestreet Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation No login needed ≤ 1.7.3 CVE-2026-39617 Patchstack
9.8 Critical DSGVO Google Web Fonts GDPR Plugin dsgvo-google-web-fonts-gdpr Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'fonturl' Parameter No login needed ≤ 1.1 CVE-2026-3535 Wordfence
9.8 Critical Users manager – PN Plugin userspn Privilege Escalation PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action No login needed ≤ 1.1.15 CVE-2026-4003 Wordfence
9.8 Critical Everest Forms Plugin everest-forms PHP Object Injection Unauthenticated PHP Object Injection via Form Entry Metadata No login needed ≤ 3.4.3 CVE-2026-3296 Wordfence
9.8 Critical Ninja Forms - File Upload Plugin Arbitrary File Upload File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.26 CVE-2026-0740 Wordfence
9.1 Critical Order Notification for WooCommerce Plugin Authentication Bypass Unauthenticated WooCommerce REST Permission Bypass No login needed < 3.6.3 Fixed in 3.6.3 CVE-2025-15484 WPScan
9.8 Critical Everest Forms Pro Plugin everest-forms Remote Code Execution Unauthenticated Remote Code Execution via Calculation Field No login needed ≤ 1.9.12 CVE-2026-3300 Wordfence
9.8 Critical Contact Form by Supsystic Plugin contact-form-by-supsystic Remote Code Execution Unauthenticated Server-Side Template Injection via Prefill Functionality No login needed ≤ 1.7.36 CVE-2026-4257 Wordfence
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution ≤ <= 8.2.7 Fixed in 8.2.8 CVE-2026-32573 Patchstack
9.3 Critical PublishPress Revisions Plugin revisionary SQL Injection No login needed ≤ <= 3.7.23 Fixed in 3.7.24 CVE-2026-32539 Patchstack
9.9 Critical Green Downloads Plugin halfdata-paypal-green-downloads Arbitrary File Upload ≤ <= 2.08 Fixed in 2.09 CVE-2026-32536 Patchstack
9.9 Critical JetFormBuilder Plugin jetformbuilder Remote Code Execution ≤ <= 3.5.6.1 Fixed in 3.5.6.2 CVE-2026-32525 Patchstack
9.1 Critical Photo Engine Plugin wplr-sync Arbitrary File Upload ≤ <= 6.4.9 Fixed in 6.5.0 CVE-2026-32524 Patchstack
9.9 Critical WPJAM Basic Plugin wpjam-basic Arbitrary File Upload ≤ <= 6.9.2 Fixed in 6.9.2.1 CVE-2026-32523 Patchstack
9.8 Critical RewardsWP Plugin rewardswp Privilege Escalation No login needed ≤ <= 1.0.4 Fixed in 1.0.5 CVE-2026-32520 Patchstack
9.0 Critical Bit SMTP Plugin bit-smtp Authentication Bypass Broken Authentication No login needed ≤ <= 1.2.2 Fixed in 1.2.3 CVE-2026-32519 Patchstack
9.8 Critical Pelicula Theme pelicula-video-production-and-movie-theme PHP Object Injection No login needed ≤ < 1.10 Fixed in 1.10 CVE-2026-32512 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only