WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Fluent Boards Pro Plugin fluent-boards-pro PHP Object Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78276 Patchstack
7.2 High FluentCRM Pro Plugin fluentcampaign-pro Privilege Escalation ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78271 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-78261 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
8.5 High ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type SQL Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection ≤ 2.0.63 CVE-2026-32564 Patchstack
8.5 High Kadence Shop Kit Plugin kadence-shop-kit SQL Injection ≤ 3.0.6 Fixed in 3.0.6.1 CVE-2026-32550 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
8.8 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting Unauthenticated Stored XSS via Geocode Event Log No login needed 3.17 – < 3.19.17 Fixed in 3.19.17 CVE-2026-78333 WPScan
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce Plugin Price Manipulation Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart No login needed < 2.1.2 Fixed in 2.1.2 CVE-2026-78137 WPScan
8.8 High Workeera Remote Tech Job Board Plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77018 WPScan
7.7 High Workeera Remote Tech Job Board Plugin Path Traversal Subscriber+ Arbitrary File Read via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77017 WPScan
7.5 High WP OAuth Server Plugin Information Disclosure Unauthenticated OAuth Token and User Data Disclosure via Debug Log File No login needed < 6.3.1 Fixed in 6.3.1 CVE-2026-19715 WPScan
7.2 High Smush Plugin wp-smushit Remote Code Execution Admin+ Network-Wide RCE via Hub Connector on Multisite 3.22.1 – < 4.3.2 Fixed in 4.3.2 CVE-2026-19223 WPScan
7.2 High CMP - Coming Soon & Maintenance Plugin Privilege Escalation Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings < 4.1.18 Fixed in 4.1.18 CVE-2026-13415 WPScan
7.5 High Formidable Charts Plugin Path Traversal Unauthenticated Arbitrary File Read via 'frm_graph' Parameter No login needed ≤ 2.0.1 CVE-2026-15990 Wordfence
8.1 High Classified Listing - Mobile Number Verification Plugin Authentication Bypass Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login No login needed ≤ 1.6.0 CVE-2026-15985 Wordfence
8.8 High Mang Board WP Plugin mangboard Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie ≤ 2.3.7 CVE-2026-75977 Wordfence
7.5 High WooCommerce Lottery Plugin woocommerce-lottery SQL Injection Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters No login needed ≤ 2.2.9 CVE-2026-18884 Wordfence
7.2 High Formidable Forms Plugin formidable Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter No login needed ≤ 6.33.1 CVE-2026-18331 Wordfence
8.7 High Order Tip for WooCommerce Plugin order-tip-woo Arbitrary File Deletion Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax < 1.6.0 Fixed in 1.6.0 CVE-2026-77693 WPScan
7.7 High AI Engine Plugin ai-engine Path Traversal Subscriber+ Arbitrary File Read via 'url' Parameter 3.3.3 – < 3.7.2 Fixed in 3.7.2 CVE-2026-75797 WPScan
7.5 High WP Project Manager Plugin Broken Access Control Unauthenticated Subscriber Account Creation via Trello Import Routes No login needed 2.1.0 – < 4.0.7 Fixed in 4.0.7 CVE-2026-74928 WPScan
7.2 High Pods Plugin pods Remote Code Execution Author+ RCE via Shortcode Display Callback 3.1.0 – < 3.3.9.1 Fixed in 3.3.9.1 CVE-2026-74851 WPScan
8.1 High BlogVault, MalCare and WP Remote Plugin Authentication Bypass Unauthenticated Site Takeover via Connection Key Recovery No login needed 5.16 – < 6.65 Fixed in 6.65 CVE-2026-19718 WPScan
7.2 High WP Fastest Cache Plugin wp-fastest-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via HTTP Host Header No login needed ≤ 1.5.0 CVE-2026-19760 Wordfence
7.5 High WP Fastest Cache Plugin wp-fastest-cache Cross-Site Scripting Unauthenticated Stored XSS via Host Header Cache Poisoning No login needed 0.9.0.3 – < 1.5.1 Fixed in 1.5.1 CVE-2026-74932 WPScan
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
8.8 High All-in-One WP Migration and Backup Plugin all-in-one-wp-migration SQL Injection Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution ≤ 7.109 CVE-2026-19949 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter No login needed ≤ 1.57.0 CVE-2026-18328 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) No login needed ≤ 1.57.0.2 CVE-2026-18323 Wordfence
8.8 High CM Map Locations Plugin cm-map-locations Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action ≤ 2.1.8 CVE-2026-16601 Wordfence
8.1 High Måne Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.7 CVE-2026-78478 Wordfence
8.8 High InfusedWoo Pro Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure ≤ 5.1.17 CVE-2026-19892 Wordfence
7.1 High Stripe Payments Plugin stripe-payments Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-78282 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
7.1 High Toolset Blocks Plugin toolset-blocks Cross-Site Scripting No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2026-78264 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.2.1 Fixed in 5.29.3 CVE-2026-78263 Patchstack
7.3 High WPLegalPages Plugin wplegalpages Authentication Bypass Broken Authentication No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-78259 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
8.8 High MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator Plugin magicai-wp Local File Inclusion AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion ≤ 1.4 CVE-2026-32560 Patchstack
7.1 High Boost Plugin boost Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2026-32556 Patchstack
8.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Arbitrary File Deletion No login needed ≤ 3.7.42 Fixed in 3.7.43 CVE-2026-78284 Patchstack
8.1 High Måne Theme mane Local File Inclusion No login needed ≤ 1.7 CVE-2026-66670 Patchstack
7.1 High Urna Theme urna Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2026-66610 Patchstack
7.5 High WP Cafe Pro Plugin wpcafe-pro Information Disclosure Sensitive Data Exposure No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66585 Patchstack
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.1 High Brave Conversion Engine (PRO) Plugin bravepopup-pro Cross-Site Scripting No login needed ≤ 0.8.6 Fixed in 0.8.7 CVE-2026-32476 Patchstack
8.5 High ProLancer Element Plugin prolancer-element SQL Injection ≤ 1.4.8 CVE-2026-32471 Patchstack
7.1 High ProLancer Element Plugin prolancer-element Broken Access Control ≤ 1.4.8 CVE-2026-28190 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only