WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,501–6,550 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 131 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Pinterest Site Verification plugin using Meta Tag Plugin pinterest-site-verification Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'post_var' ≤ 1.8 CVE-2026-3142 Wordfence
6.4 Medium Sports Club Management Plugin sports-club-management Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' Attribute ≤ 1.12.9 CVE-2026-4871 Wordfence
9.8 Critical DSGVO Google Web Fonts GDPR Plugin dsgvo-google-web-fonts-gdpr Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'fonturl' Parameter No login needed ≤ 1.1 CVE-2026-3535 Wordfence
6.5 Medium WP Blockade Plugin wp-blockade Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'shortcode' Parameter ≤ 0.9.14 CVE-2026-3480 Wordfence
5.3 Medium Riaxe Product Customizer Plugin riaxe-product-customizer Information Disclosure Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint No login needed ≤ 2.4 CVE-2026-3594 Wordfence
7.5 High ActivityPub Routing Plugin Information Disclosure Unauthenticated Drafts/Scheduled/Pending Posts Disclosure No login needed < 8.0.2 Fixed in 8.0.2 CVE-2026-4338 WPScan
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
6.4 Medium Investi Plugin investi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'maximum-num-years' Shortcode Attribute ≤ 1.0.26 CVE-2026-3600 Wordfence
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode ≤ 3.2.21 CVE-2026-3239 Wordfence
5.3 Medium LTL Freight Quotes – R+L Carriers Edition Plugin ltl-freight-quotes-rl-edition Broken Access Control R+L Carriers Edition <= 3.3.13 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 3.3.13 CVE-2026-3646 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.3.0 CVE-2026-4785 Wordfence
5.3 Medium MainWP Child Reports Plugin mainwp-child-reports Broken Access Control Missing Authorization to Authenticated (Subscriber+) Information Disclosure via Heartbeat API No login needed ≤ 2.2.6 CVE-2026-4299 Wordfence
6.4 Medium Prime Slider Plugin bdthemes-prime-slider-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter ≤ 4.1.10 CVE-2026-4341 Wordfence
9.8 Critical Users manager – PN Plugin userspn Privilege Escalation PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action No login needed ≤ 1.1.15 CVE-2026-4003 Wordfence
6.4 Medium TableOn – WordPress Posts Table Filterable Plugin posts-table-filterable Cross-Site Scripting WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute ≤ 1.0.4.4 CVE-2026-3513 Wordfence
6.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute ≤ 4.3.3 CVE-2026-4333 Wordfence
6.4 Medium LightPress Lightbox Plugin wp-jquery-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'group' Shortcode Attribute ≤ 2.3.4 CVE-2026-4379 Wordfence
6.4 Medium Blubrry PowerPress Plugin powerpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes ≤ 11.15.15 CVE-2026-2988 Wordfence
8.8 High Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed 13.4.6 – 13.5.2.1 CVE-2026-3499 Wordfence
9.8 Critical Everest Forms Plugin everest-forms PHP Object Injection Unauthenticated PHP Object Injection via Form Entry Metadata No login needed ≤ 3.4.3 CVE-2026-3296 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 3.35.5 CVE-2025-14732 Wordfence
6.1 Medium Gravity Forms Plugin gravityforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field No login needed ≤ 2.9.30 CVE-2026-4394 Wordfence
4.7 Medium Gravity Forms Plugin gravityforms Cross-Site Scripting Reflected Cross-Site Scripting via 'form_ids' Parameter No login needed ≤ 2.9.30 CVE-2026-4406 Wordfence
5.4 Medium Download Monitor Plugin download-monitor Cross-Site Request Forgery Cross-Site Request Forgery to Download Path Deletion and Disabling No login needed ≤ 5.1.10 CVE-2026-4401 Wordfence
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation No login needed ≤ 7.8.10.2 CVE-2026-2263 Wordfence
5.4 Medium Smart Slider 3 Plugin smart-slider-3 Broken Access Control Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation ≤ 3.5.1.33 CVE-2026-4065 Wordfence
5.3 Medium Backup Migration Plugin backup-backup Broken Access Control Missing Authorization to Unauthenticated Backup Upload to Offline Storage No login needed ≤ 2.0.0 CVE-2025-14944 Wordfence
5.4 Medium Ocean Extra Plugin ocean-extra Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2026-34903 Patchstack
5.3 Medium LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition Broken Access Control Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control No login needed ≤ 5.2.1 Fixed in 5.2.2 CVE-2026-34899 Patchstack
7.5 High Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Request Forgery No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-34904 Patchstack
7.5 High Under Construction, Coming Soon & Maintenance Mode Plugin under-construction-maintenance-mode Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-34896 Patchstack
5.3 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable Other Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook No login needed ≤ 1.8.9.7 CVE-2026-3177 Wordfence
8.8 High Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter ≤ 2.1.3 CVE-2026-5465 Wordfence
6.5 Medium SQL Chart Builder Plugin SQL Injection Unauthenticated SQL Injection No login needed < 2.3.8 Fixed in 2.3.8 CVE-2026-4079 WPScan
6.5 Medium Link Whisper Free Plugin link-whisper Broken Access Control Unauthenticated Settings and User Meta Update No login needed < 0.9.1 Fixed in 0.9.1 CVE-2026-1900 WPScan
5.4 Medium Popup Box AYS Pro Plugin Cross-Site Scripting Admin+ Stored Cross-Site Scripting (XSS) via CSRF < 5.5.0 Fixed in 5.5.0 CVE-2025-15611 WPScan
9.8 Critical Ninja Forms - File Upload Plugin Arbitrary File Upload File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.26 CVE-2026-0740 Wordfence
6.5 Medium Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting ≤ 3.34 Fixed in 3.35 CVE-2026-34897 Patchstack
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.34 Fixed in 3.35 CVE-2026-34885 Patchstack
8.8 High wpForo Forum Plugin wpforo Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Post Body ≤ 2.4.16 CVE-2026-3666 Wordfence
7.2 High Visitor Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.4 CVE-2026-2936 Wordfence
7.5 High Text to Speech (TTS) by Mementor Plugin text-to-speech-tts Information Disclosure Use of Hardcoded Password to Unauthenticated Remote Database Access No login needed ≤ 1.9.8 CVE-2026-1233 Wordfence
5.3 Medium Listeo-Core - Directory Plugin by Purethemes Plugin Broken Access Control Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload No login needed ≤ 2.0.27 CVE-2025-14938 Wordfence
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields No login needed ≤ 4.16.11 CVE-2026-3309 Wordfence
6.4 Medium WPFunnels Plugin wpfunnels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode ≤ 3.7.9 CVE-2026-0626 Wordfence
7.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Broken Access Control ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass ≤ 4.16.11 CVE-2026-3445 Wordfence
4.3 Medium Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin kadence-blocks Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload ≤ 3.6.3 CVE-2026-2826 Wordfence
6.4 Medium WP Travel Engine - Travel and Tour Booking Plugin wp-travel-engine Cross-Site Scripting Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode ≤ 6.7.5 CVE-2026-2437 Wordfence
7.2 High Widgets for Social Photo Feed Plugin social-photo-feed-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via feed_data No login needed ≤ 1.7.9 CVE-2026-5425 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only