WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 651–700 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
7.5 High Super Forms Plugin super-forms Path Traversal Arbitrary File Download No login needed ≤ 6.3.315 CVE-2026-28167 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.9 CVE-2026-28166 Patchstack
7.1 High Events Made Easy Plugin events-made-easy Cross-Site Scripting No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2026-28162 Patchstack
7.5 High Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Plugin notification-master Broken Access Control Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 CVE-2026-28153 Patchstack
8.1 High Tonda Core Plugin tonda-core Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28152 Patchstack
8.1 High Tonda Theme tonda Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28151 Patchstack
8.1 High Verdure Core Plugin verdure-core Local File Inclusion No login needed ≤ 1.2 CVE-2026-66671 Patchstack
7.6 High FluentCRM Pro Plugin fluentcampaign-pro SQL Injection ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78270 Patchstack
7.1 High Social Media & Share Icons Plugin ultimate-social-media-icons Cross-Site Scripting No login needed ≤ 2.9.9 Fixed in 3.0.0 CVE-2026-66623 Patchstack
7.1 High WPComplete Plugin wpcomplete Cross-Site Scripting No login needed ≤ 2.9.5.6 Fixed in 2.9.5.7 CVE-2026-66599 Patchstack
7.1 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting No login needed ≤ 3.19.16 Fixed in 3.19.17 CVE-2026-66584 Patchstack
8.8 High PPWP – Password Protect Pages Plugin password-protect-page PHP Object Injection Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles ≤ 1.9.18 CVE-2026-0551 Wordfence
8.8 High Security Hardener Plugin security-hardener Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite ≤ 2.4.4 CVE-2026-16149 Wordfence
7.5 High Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Other Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request No login needed ≤ 1.6.21 CVE-2026-2996 Wordfence
8.1 High Firebase Authentication Plugin firebase-authentication Privilege Escalation Unauthenticated Account Takeover via Firebase Email Claim No login needed < 1.7.1 Fixed in 1.7.1 CVE-2026-76793 WPScan
8.8 High Slider Hero Plugin Cross-Site Scripting Unauthenticated Stored XSS via Slider Type Change and Add-Slider Handlers No login needed < 9.1.3 Fixed in 9.1.3 CVE-2026-76789 WPScan
7.2 High Forminator Forms Plugin forminator Remote Code Execution Admin+ Network-Wide RCE via Hub Connector API Key on Multisite 1.40.0 – < 1.57.0.5 Fixed in 1.57.0.5 CVE-2026-19221 WPScan
8.1 High ManageWP Worker Plugin worker Authentication Bypass Unauthenticated Authentication Bypass via Unsigned Auto-Login Parameters No login needed < 4.9.37 Fixed in 4.9.37 CVE-2026-18052 WPScan
8.8 High WPeMatico RSS Feed Fetcher Plugin wpematico Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action ≤ 2.8.24 CVE-2026-19883 Wordfence
7.2 High AI Engine Plugin ai-engine Privilege Escalation Admin+ Multisite Network Administrator Account Takeover via MCP User Tools 2.8.0 – < 3.6.1 Fixed in 3.6.1 CVE-2026-75796 WPScan
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated RCE via Control Character Filename Bypass No login needed < 1.3.9.9 Fixed in 1.3.9.9 CVE-2026-18781 WPScan
7.2 High Dokan Plugin Broken Access Control Shop Manager+ Arbitrary Plugin Installation/Activation via REST API < 5.0.14 Fixed in 5.0.14 CVE-2026-16576 WPScan
7.2 High WPForms Pro Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values No login needed ≤ 2.0.0.2 CVE-2026-18409 Wordfence
7.6 High InfiniteWP Client Plugin iwp-client SQL Injection ≤ 1.13.9 Fixed in 1.13.10 CVE-2026-74011 Patchstack
7.5 High Koji Theme koji Broken Access Control No login needed ≤ 2.2.1 CVE-2026-74020 Patchstack
7.1 High EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 2.4.2 CVE-2026-74019 Patchstack
8.5 High eShipper Commerce Plugin eshipper-commerce SQL Injection ≤ 2.16.13 CVE-2026-74013 Patchstack
8.5 High WP w3all phpBB Plugin wp-w3all-phpbb-integration SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2026-73998 Patchstack
7.1 High NotificationX Pro Plugin notificationx-pro Cross-Site Scripting No login needed ≤ 3.1.4 CVE-2026-68564 Patchstack
7.6 High Leyka Plugin leyka Authentication Bypass Broken Authentication ≤ 3.32.3 CVE-2026-66677 Patchstack
7.1 High Flatastic Theme flatastic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2026-66673 Patchstack
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting No login needed ≤ 1.15.48 CVE-2026-66616 Patchstack
7.1 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2026-66615 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.2 Fixed in 14.2.3 CVE-2026-66614 Patchstack
7.1 High Aora Theme aora Cross-Site Scripting No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2026-66612 Patchstack
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
7.1 High Advance Product Search Plugin th-advance-product-search Cross-Site Scripting No login needed ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-66607 Patchstack
7.1 High SmartSMTP Plugin smart-smtp Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-66606 Patchstack
7.1 High Swatchly – WooCommerce Variation Swatches for Products Plugin swatchly Cross-Site Scripting WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2026-66605 Patchstack
7.1 High GeoDirectory Plugin geodirectory Cross-Site Scripting No login needed ≤ 2.8.173 Fixed in 2.8.174 CVE-2026-66604 Patchstack
7.1 High B2BKing Premium Plugin b2bking Cross-Site Scripting No login needed ≤ 5.6.07 Fixed in 5.6.08 CVE-2026-66598 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.4 Fixed in 6.5.1.5 CVE-2026-66597 Patchstack
8.5 High WordPress Persistent Login Plugin wp-persistent-login SQL Injection ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-66594 Patchstack
7.1 High Tagembed Plugin tagembed-widget Cross-Site Scripting No login needed ≤ 7.4 Fixed in 7.5 CVE-2026-66590 Patchstack
7.1 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-66582 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.14.1 Fixed in 3.8.14.2 CVE-2026-66581 Patchstack
8.1 High Golo Framework Plugin golo-framework Local File Inclusion No login needed < 1.7.5 Fixed in 1.7.5 CVE-2026-28150 Patchstack
8.1 High Shuffle Theme shuffle Local File Inclusion No login needed ≤ 1.8 Fixed in 1.9 CVE-2025-15637 Patchstack
7.5 High Chaplin Theme chaplin Broken Access Control No login needed ≤ 2.6.8 CVE-2026-74021 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only