WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Conekta Payment Gateway Plugin conekta-payment-gateway Broken Access Control No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2026-95527 Patchstack
6.5 Medium WP User Frontend Plugin wp-user-frontend Arbitrary File Deletion ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95525 Patchstack
5.3 Medium WP User Frontend Plugin wp-user-frontend Authentication Bypass Bypass Vulnerability No login needed ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95524 Patchstack
6.5 Medium WP User Frontend Plugin wp-user-frontend Authentication Bypass Bypass Vulnerability ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95523 Patchstack
7.6 High Easy Digital Downloads Plugin easy-digital-downloads SQL Injection ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-95522 Patchstack
7.1 High Ninja Forms Plugin ninja-forms Cross-Site Scripting No login needed ≤ 3.15.3 Fixed in 3.15.4 CVE-2026-95515 Patchstack
5.3 Medium Netgsm Plugin netgsm Other Bypass Vulnerability No login needed ≤ 2.10.0 Fixed in 2.10.2 CVE-2026-95514 Patchstack
7.5 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control No login needed ≤ 4.6.0 Fixed in 4.6.3 CVE-2026-95513 Patchstack
6.5 Medium Podcast Importer SecondLine Plugin podcast-importer-secondline Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.8 CVE-2026-94682 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94680 Patchstack
5.4 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2026-94679 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94671 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-94500 Patchstack
6.5 Medium AppMySite Plugin appmysite Broken Access Control No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-94498 Patchstack
8.1 High PublishPress Capabilities Plugin capability-manager-enhanced Cross-Site Request Forgery No login needed ≤ 2.50.1 Fixed in 2.51.0 CVE-2026-94487 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.69 Fixed in 3.1.70 CVE-2026-94461 Patchstack
4.8 Medium Captcha Code Plugin captcha-code-authentication Authentication Bypass Bypass Vulnerability No login needed ≤ 3.32 Fixed in 3.33 CVE-2026-94457 Patchstack
6.5 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Scripting ≤ 2.4.14 Fixed in 2.5.0 CVE-2026-94391 Patchstack
7.1 High Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2026-94179 Patchstack
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2026-94176 Patchstack
7.6 High Email Log Plugin email-log SQL Injection ≤ 2.63 Fixed in 2.64 CVE-2026-94174 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-94168 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.4 Fixed in 6.0.0 CVE-2026-94124 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) ≤ 2.3.17 Fixed in 2.3.18 CVE-2026-94118 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.70 Fixed in 2.1.72 CVE-2026-94080 Patchstack
5.3 Medium WP User Manager Plugin wp-user-manager Broken Access Control No login needed ≤ 2.9.19 Fixed in 2.9.20 CVE-2026-94079 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.3.02.002 Fixed in 9.3.02.003 CVE-2026-93774 Patchstack
8.5 High Mollie Forms Plugin mollie-forms SQL Injection ≤ 2.11.0 Fixed in 2.11.1 CVE-2026-93773 Patchstack
6.5 Medium wpForo Forum Plugin wpforo Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-93772 Patchstack
5.3 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2026-93623 Patchstack
7.1 High WPS Limit Login Plugin wps-limit-login Cross-Site Scripting No login needed ≤ 1.5.9.3 Fixed in 1.5.9.4 CVE-2026-93622 Patchstack
6.5 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Broken Access Control No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-93620 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-93618 Patchstack
6.5 Medium WSP MCP – AI Agents Connector Plugin wsp-mcp-ai-agents-connector Broken Access Control AI Agents Connector plugin <= 2.7.0 - Broken Access Control ≤ 2.7.0 Fixed in 2.7.1 CVE-2026-93529 Patchstack
8.5 High Live Copy Paste for Elementor Plugin live-copy-paste SQL Injection ≤ 1.5.10 Fixed in 1.5.11 CVE-2026-93527 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.4 Fixed in 5.29.5 CVE-2026-93526 Patchstack
4.3 Medium SiteSkite Plugin siteskite Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-93513 Patchstack
5.3 Medium SUMIT Payment Gateway for WooCommerce Plugin woo-payment-gateway-officeguy Authentication Bypass Unauthenticated Payment Confirmation Forgery via bit IPN No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-84091 WPScan
5.3 Medium Paid Member Subscriptions Plugin Authentication Bypass Unauthenticated reCAPTCHA Bypass via Registration Form No login needed 2.0.5 – < 3.1.0 Fixed in 3.1.0 CVE-2026-90950 WPScan
5.3 Medium Paymob for WooCommerce Plugin paymob-for-woocommerce Price Manipulation Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback No login needed < 4.1.14 Fixed in 4.1.14 CVE-2026-87978 WPScan
3.7 Low MPCX Lightbox Plugin Information Disclosure Unauthenticated Non-Public Post Content Disclosure No login needed 1.2.2 – 1.2.5 CVE-2026-87848 WPScan
5.3 Medium Forminator Forms Plugin forminator Other Unauthenticated Post Meta Injection on Submitted Posts No login needed < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87071 WPScan
5.3 Medium Forminator Forms Plugin forminator Other Unauthenticated Poll Vote Limit Bypass via IP Spoofing No login needed < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87070 WPScan
5.6 Medium Ninja Tables Plugin ninja-tables Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source No login needed < 5.2.17 Fixed in 5.2.17 CVE-2026-86612 WPScan
4.8 Medium GTranslate Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Email Translation No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-86604 WPScan
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Comment Content No login needed < 10.8.2 Fixed in 10.8.2 CVE-2026-86601 WPScan
7.5 High Rename wp-login.php to anything you want Plugin rename-wp-loginphp-to-anything-you-want SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed ≤ 2.0.1 CVE-2026-93368 Wordfence
6.5 Medium Advanced Contact form 7 DB Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Information Disclosure via 'acf7db' Shortcode ≤ 2.1.1 CVE-2026-6831 Wordfence
6.4 Medium Getwid Plugin getwid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle' 2.1.3 CVE-2026-5924 Wordfence
3.7 Low NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Information Disclosure Unauthenticated Order Data Disclosure via Quote Request Page No login needed 2.0 – < 2.4.16 Fixed in 2.4.16 CVE-2026-93528 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only