WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 601–650 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | WPLP Cookie Consent | Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed |
< 4.4.4 Fixed in 4.4.4 |
CVE-2026-85131 |
WPScan | |
| 6.8 Medium | Xpro Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget |
< 1.7.9 Fixed in 1.7.9 |
CVE-2026-84088 |
WPScan | |
| 5.3 Medium | Schema & Structured Data for WP & AMP | Information Disclosure Unauthenticated Non-Public Comment Content Disclosure via IDOR No login needed |
1.46 – < 1.66 Fixed in 1.66 |
CVE-2026-82125 |
WPScan | |
| 5.3 Medium | Schema & Structured Data for WP & AMP | Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output No login needed |
< 1.66 Fixed in 1.66 |
CVE-2026-82124 |
WPScan | |
| 5.3 Medium | Ni WooCommerce Sales Report | Information Disclosure Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter No login needed |
< 4.2.0 Fixed in 4.2.0 |
CVE-2026-78474 |
WPScan | |
| 5.3 Medium | Eventin | Broken Access Control Unauthenticated Ticket Price Rewrite via order_token No login needed |
< 4.1.24 Fixed in 4.1.24 |
CVE-2026-77702 |
WPScan | |
| 4.1 Medium | WP Import Export Lite | Server-Side Request Forgery Admin+ SSRF via Import URL Handling |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76559 |
WPScan | |
| 6.8 Medium | WP Import Export Lite | Cross-Site Scripting Contributor+ Stored DOM XSS via Custom Field Names |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76558 |
WPScan | |
| 6.8 Medium | WP Import Export Lite | SQL Injection Authenticated SQLi via Import Options |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76557 |
WPScan | |
| 6.8 Medium | WP Import Export Lite | SQL Injection Authenticated SQLi via Export Filter Rules |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76556 |
WPScan | |
| 6.8 Medium | WP Import Export Lite | Information Disclosure Authenticated Sensitive File Disclosure via Existing File Import Path Traversal |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76555 |
WPScan | |
| 6.5 Medium | WP Import Export Lite | Arbitrary File Deletion Authenticated Arbitrary Directory Deletion via Template Path Traversal |
< 3.9.33 Fixed in 3.9.33 |
CVE-2026-76553 |
WPScan | |
| 6.1 Medium | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | Cross-Site Scripting Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter No login needed |
≤ 2.15.22 |
CVE-2026-18555 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter |
≤ 5.9.6 |
CVE-2026-5920 |
Wordfence | |
| 6.4 Medium | Advanced Popups | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field |
≤ 1.2.3 |
CVE-2026-11996 |
Wordfence | |
| 6.5 Medium | WP Directory Kit | SQL Injection Authenticated (Custom+) SQL Injection via 'order_by' Parameter |
≤ 1.5.4 |
CVE-2026-16588 |
Wordfence | |
| 5.3 Medium | Ad Inserter | Broken Access Control Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter No login needed |
≤ 2.8.16 |
CVE-2026-11984 |
Wordfence | |
| 6.5 Medium | JWT Authentication for WP REST APIs | Authentication Bypass miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade No login needed |
< 4.8.0 Fixed in 4.8.0 |
CVE-2026-89027 |
VulnCheck | |
| 5.1 Medium | design-scuole-wordpress-theme | Content Injection HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme |
1.0 – 2.17.3 |
CVE-2026-89307 |
ENISA | |
| 5.1 Medium | design-scuole-wordpress-theme | Cross-Site Scripting Reflected XSS in WordPress theme design-scuole-wordpress-theme No login needed |
1.0 – 2.18.2 |
CVE-2026-87793 |
ENISA | |
| 6.4 Medium | Bridge - Creative Multipurpose | Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute |
≤ 30.8.9.1 |
CVE-2026-15609 |
Wordfence | |
| 6.4 Medium | Job Postings | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter |
≤ 2.8.1 |
CVE-2026-18063 |
Wordfence | |
| 6.5 Medium | AI Engine | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter |
≤ 3.7.7 |
CVE-2026-89141 |
Wordfence | |
| 6.4 Medium | Eventin | Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter |
≤ 4.1.23 |
CVE-2026-15402 |
Wordfence | |
| 5.3 Medium | WP Directory Kit | Information Disclosure Unauthenticated Unpublished Listing Disclosure via map_infowindow No login needed |
≤ 1.5.7 |
CVE-2026-18232 |
WPScan | |
| 6.8 Medium | WP Directory Kit | SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings |
≤ 1.5.7 |
CVE-2026-16593 |
WPScan | |
| 5.3 Medium | 3D FlipBook | Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed |
≤ 1.16.20 |
CVE-2026-15758 |
Wordfence | |
| 5.4 Medium | Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter |
≤ 4.15.0 |
CVE-2026-85657 |
Wordfence | |
| 6.4 Medium | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets | Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter |
≤ 4.9.5 |
CVE-2026-85575 |
Wordfence | |
| 4.3 Medium | Really Simple Security | Broken Access Control Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler |
< 9.8.2 Fixed in 9.8.2 |
CVE-2026-82519 |
VulnCheck | |
| 4.3 Medium | Quads Ads Manager for Google AdSense | Price Manipulation Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL |
3.0.4 – < 3.0.5 Fixed in 3.0.5 |
CVE-2026-89050 |
WPScan | |
| 5.3 Medium | Bookit | Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed |
< 2.6.0.1 Fixed in 2.6.0.1 |
CVE-2026-88995 |
WPScan | |
| 4.2 Medium | rtMedia for WordPress, BuddyPress and bbPress | Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR |
< 4.7.12 Fixed in 4.7.12 |
CVE-2026-88912 |
WPScan | |
| 5.4 Medium | Simple Membership | Privilege Escalation Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref |
< 4.7.8 Fixed in 4.7.8 |
CVE-2026-88764 |
WPScan | |
| 4.7 Medium | User Registration & Membership | Open Redirect Unauthenticated Open Redirect via Login Redirect Parameters No login needed |
< 5.2.8 Fixed in 5.2.8 |
CVE-2026-80072 |
WPScan | |
| 5.3 Medium | Social Contact Form (FormyChat) | Information Disclosure Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry No login needed |
< 2.15.8 Fixed in 2.15.8 |
CVE-2026-77773 |
WPScan | |
| 6.4 Medium | Booking for Appointments and Events Calendar – Amelia | Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter |
≤ 2.4.9 |
CVE-2026-10148 |
Wordfence | |
| 6.5 Medium | Smart Marketing SMS and Newsletters Forms | SQL Injection Authenticated (Subscriber+) SQL Injection via Parameter Name |
≤ 5.1.24 |
CVE-2026-77161 |
Wordfence | |
| 5.3 Medium | DT LMS | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions No login needed |
≤ 1.1 |
CVE-2026-11355 |
Wordfence | |
| 6.5 Medium | MPG | SQL Injection Unauthenticated SQL Injection via URL Path |
≤ 4.2.1 |
CVE-2026-85198 |
Wordfence | |
| 5.3 Medium | Royal Addons for Elementor | Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed |
≤ 1.7.1066 |
CVE-2026-17585 |
Wordfence | |
| 4.9 Medium | Product XML Feed Manager for WooCommerce | Broken Access Control Contributor+ Arbitrary Product Deletion via Shortcode |
< 3.1.1 Fixed in 3.1.1 |
CVE-2026-87919 |
WPScan | |
| 5.3 Medium | WPBot | Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed |
< 8.5.7 Fixed in 8.5.7 |
CVE-2026-87918 |
WPScan | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed |
8.4.9 – < 8.6.0 Fixed in 8.6.0 |
CVE-2026-87916 |
WPScan | |
| 5.3 Medium | Rox Appointment Booking | Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed |
1.0.9 – < 1.2.3 Fixed in 1.2.3 |
CVE-2026-87894 |
WPScan | |
| 5.3 Medium | Rox Appointment Booking | Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed |
< 1.2.0 Fixed in 1.2.0 |
CVE-2026-87892 |
WPScan | |
| 6.5 Medium | Rox Appointment Booking | Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed |
< 1.2.0 Fixed in 1.2.0 |
CVE-2026-87891 |
WPScan | |
| 4.3 Medium | Client Invoicing by Sprout Invoices | Broken Access Control Subscriber+ Private Note Overwrite via si_edit_private_note |
< 20.8.16 Fixed in 20.8.16 |
CVE-2026-87797 |
WPScan | |
| 6.8 Medium | WP Highlight Box | Cross-Site Scripting Contributor+ Stored XSS via highlight-box Shortcode |
≤ 1.0 |
CVE-2026-86790 |
WPScan | |
| 4.3 Medium | BEAR - Bulk Editor and Products Manager Professional for WooCommerce | Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed |
< 1.2.2 Fixed in 1.2.2 |
CVE-2026-84024 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.