WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85131 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget < 1.7.9 Fixed in 1.7.9 CVE-2026-84088 WPScan
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Non-Public Comment Content Disclosure via IDOR No login needed 1.46 – < 1.66 Fixed in 1.66 CVE-2026-82125 WPScan
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output No login needed < 1.66 Fixed in 1.66 CVE-2026-82124 WPScan
5.3 Medium Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report Information Disclosure Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78474 WPScan
5.3 Medium Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Ticket Price Rewrite via order_token No login needed < 4.1.24 Fixed in 4.1.24 CVE-2026-77702 WPScan
4.1 Medium WP Import Export Lite Plugin wp-import-export-lite Server-Side Request Forgery Admin+ SSRF via Import URL Handling < 3.9.33 Fixed in 3.9.33 CVE-2026-76559 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite Cross-Site Scripting Contributor+ Stored DOM XSS via Custom Field Names < 3.9.33 Fixed in 3.9.33 CVE-2026-76558 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite SQL Injection Authenticated SQLi via Import Options < 3.9.33 Fixed in 3.9.33 CVE-2026-76557 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite SQL Injection Authenticated SQLi via Export Filter Rules < 3.9.33 Fixed in 3.9.33 CVE-2026-76556 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite Information Disclosure Authenticated Sensitive File Disclosure via Existing File Import Path Traversal < 3.9.33 Fixed in 3.9.33 CVE-2026-76555 WPScan
6.5 Medium WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Deletion Authenticated Arbitrary Directory Deletion via Template Path Traversal < 3.9.33 Fixed in 3.9.33 CVE-2026-76553 WPScan
6.1 Medium Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots Plugin bp-better-messages Cross-Site Scripting Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter No login needed ≤ 2.15.22 CVE-2026-18555 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter ≤ 5.9.6 CVE-2026-5920 Wordfence
6.4 Medium Advanced Popups Plugin advanced-popups Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field ≤ 1.2.3 CVE-2026-11996 Wordfence
6.5 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Custom+) SQL Injection via 'order_by' Parameter ≤ 1.5.4 CVE-2026-16588 Wordfence
5.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter No login needed ≤ 2.8.16 CVE-2026-11984 Wordfence
6.5 Medium JWT Authentication for WP REST APIs Plugin wp-rest-api-authentication Authentication Bypass miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade No login needed < 4.8.0 Fixed in 4.8.0 CVE-2026-89027 VulnCheck
5.1 Medium design-scuole-wordpress-theme Theme Content Injection HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme 1.0 – 2.17.3 CVE-2026-89307 ENISA
5.1 Medium design-scuole-wordpress-theme Theme Cross-Site Scripting Reflected XSS in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.18.2 CVE-2026-87793 ENISA
6.4 Medium Bridge - Creative Multipurpose Theme Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute ≤ 30.8.9.1 CVE-2026-15609 Wordfence
6.4 Medium Job Postings Plugin job-postings Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter ≤ 2.8.1 CVE-2026-18063 Wordfence
6.5 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter ≤ 3.7.7 CVE-2026-89141 Wordfence
6.4 Medium Eventin Plugin wp-event-solution Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter ≤ 4.1.23 CVE-2026-15402 Wordfence
5.3 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Unauthenticated Unpublished Listing Disclosure via map_infowindow No login needed ≤ 1.5.7 CVE-2026-18232 WPScan
6.8 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings ≤ 1.5.7 CVE-2026-16593 WPScan
5.3 Medium 3D FlipBook Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed ≤ 1.16.20 CVE-2026-15758 Wordfence
5.4 Medium Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors Plugin publishpress-authors Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter ≤ 4.15.0 CVE-2026-85657 Wordfence
6.4 Medium ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets Plugin shopengine Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter ≤ 4.9.5 CVE-2026-85575 Wordfence
4.3 Medium Really Simple Security Plugin really-simple-ssl Broken Access Control Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler < 9.8.2 Fixed in 9.8.2 CVE-2026-82519 VulnCheck
4.3 Medium Quads Ads Manager for Google AdSense Plugin quick-adsense-reloaded Price Manipulation Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL 3.0.4 – < 3.0.5 Fixed in 3.0.5 CVE-2026-89050 WPScan
5.3 Medium Bookit Plugin bookit-for-cal-com Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed < 2.6.0.1 Fixed in 2.6.0.1 CVE-2026-88995 WPScan
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
5.4 Medium Simple Membership Plugin simple-membership Privilege Escalation Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref < 4.7.8 Fixed in 4.7.8 CVE-2026-88764 WPScan
4.7 Medium User Registration & Membership Plugin user-registration Open Redirect Unauthenticated Open Redirect via Login Redirect Parameters No login needed < 5.2.8 Fixed in 5.2.8 CVE-2026-80072 WPScan
5.3 Medium Social Contact Form (FormyChat) Plugin Information Disclosure Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry No login needed < 2.15.8 Fixed in 2.15.8 CVE-2026-77773 WPScan
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter ≤ 2.4.9 CVE-2026-10148 Wordfence
6.5 Medium Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp SQL Injection Authenticated (Subscriber+) SQL Injection via Parameter Name ≤ 5.1.24 CVE-2026-77161 Wordfence
5.3 Medium DT LMS Plugin dt-lms-lite Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions No login needed ≤ 1.1 CVE-2026-11355 Wordfence
6.5 Medium MPG Plugin multiple-pages-generator-by-porthas SQL Injection Unauthenticated SQL Injection via URL Path ≤ 4.2.1 CVE-2026-85198 Wordfence
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed ≤ 1.7.1066 CVE-2026-17585 Wordfence
4.9 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control Contributor+ Arbitrary Product Deletion via Shortcode < 3.1.1 Fixed in 3.1.1 CVE-2026-87919 WPScan
5.3 Medium WPBot Plugin chatbot Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed < 8.5.7 Fixed in 8.5.7 CVE-2026-87918 WPScan
5.3 Medium WPBot Plugin chatbot Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed 8.4.9 – < 8.6.0 Fixed in 8.6.0 CVE-2026-87916 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87892 WPScan
6.5 Medium Rox Appointment Booking Plugin rox-appointment-booking Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87891 WPScan
4.3 Medium Client Invoicing by Sprout Invoices Plugin Broken Access Control Subscriber+ Private Note Overwrite via si_edit_private_note < 20.8.16 Fixed in 20.8.16 CVE-2026-87797 WPScan
6.8 Medium WP Highlight Box Plugin Cross-Site Scripting Contributor+ Stored XSS via highlight-box Shortcode ≤ 1.0 CVE-2026-86790 WPScan
4.3 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84024 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only