WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 7,351–7,400 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 148 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP ERP Plugin erp SQL Injection ≤ 1.16.10 Fixed in 1.16.11 CVE-2026-31917 Patchstack
5.3 Medium Latest Post Shortcode Plugin latest-post-shortcode Broken Access Control No login needed ≤ 14.2.1 Fixed in 14.2.2 CVE-2026-31916 Patchstack
5.3 Medium Flatsome Plugin flatsome Broken Access Control No login needed ≤ 3.19.6 Fixed in 3.19.7 CVE-2026-31915 Patchstack
4.3 Medium Social Icons Widget & Block Plugin social-icons-widget-by-wpzoom Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation ≤ 4.5.8 CVE-2026-4063 Wordfence
6.4 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings ≤ 5.4.5.0 CVE-2026-3986 Wordfence
5.3 Medium Formidable Forms Plugin formidable Price Manipulation Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter No login needed ≤ 6.28 CVE-2026-2888 Wordfence
5.4 Medium GetGenie Plugin getgenie Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Post Overwrite/Deletion ≤ 4.3.2 CVE-2026-2879 Wordfence
6.4 Medium GetGenie Plugin getgenie Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Stored Cross-Site Scripting via REST API ≤ 4.3.2 CVE-2026-2257 Wordfence
7.5 High Formidable Forms Plugin formidable Broken Access Control Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse No login needed ≤ 6.28 CVE-2026-2890 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
4.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure ≤ 1.6.9.29 CVE-2026-1704 Wordfence
9.8 Critical Pix for WooCommerce Plugin payment-gateway-pix-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.5.0 CVE-2026-3891 Wordfence
6.5 Medium wpDiscuz Plugin wpdiscuz Other No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22216 VulnCheck
4.3 Medium wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Missing CSRF Protection on wpdGetFollowsPage No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22215 VulnCheck
4.4 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Cross-Site Scripting via Unescaped Attachment URLs < 7.6.47 Fixed in 7.6.47 CVE-2026-22210 VulnCheck
5.5 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Cross-Site Scripting via Unescaped Custom CSS in Style Tag < 7.6.47 Fixed in 7.6.47 CVE-2026-22209 VulnCheck
3.7 Low wpDiscuz Plugin wpdiscuz Other Unsanitized Cookie Email Used as wp_mail() Recipient No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22204 VulnCheck
4.9 Medium wpDiscuz Plugin wpdiscuz Information Disclosure Options Export Leaks OAuth Secrets in Plaintext < 7.6.47 Fixed in 7.6.47 CVE-2026-22203 VulnCheck
8.1 High wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Destructive GET Action Deletes All Comments by Email No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22202 VulnCheck
5.3 Medium wpDiscuz Plugin wpdiscuz Other IP Address Spoofing in getIP() No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22201 VulnCheck
8.1 High wpDiscuz Plugin wpdiscuz SQL Injection SQL Injection in getAllSubscriptions() No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22193 VulnCheck
6.1 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Stored Cross-Site Scripting in Inline Comment Preview No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22183 VulnCheck
7.5 High wpDiscuz Plugin wpdiscuz Denial of Service Unauthenticated Email Notification Flood via wpdCheckNotificationType No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22182 VulnCheck
6.1 Medium Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'c' No login needed ≤ 20260217 CVE-2026-2987 Wordfence
4.3 Medium Reading progressbar Plugin reading-progress-bar Cross-Site Scripting Admin+ Stored XSS < 1.3.1 Fixed in 1.3.1 CVE-2026-2687 WPScan
4.3 Medium Timetics Plugin timetics Broken Access Control Unauthenticated Payment/Booking Status Update No login needed < 1.0.52 Fixed in 1.0.52 CVE-2025-15473 WPScan
4.3 Medium LearnPress Plugin learnpress Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering ≤ 4.3.2.8 CVE-2026-3226 Wordfence
7.5 High My Sticky Bar Plugin mystickymenu SQL Injection Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action No login needed ≤ 2.8.6 CVE-2026-3657 Wordfence
7.5 High JetBooking Plugin SQL Injection Unauthenticated SQL Injection via 'check_in_date' Parameter No login needed ≤ 4.0.3 CVE-2026-3496 Wordfence
7.2 High Name Directory Plugin name-directory Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' No login needed ≤ 1.32.1 CVE-2026-3178 Wordfence
4.3 Medium WordPress Core Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API 6.9 – 6.9.1 CVE-2026-3906 Wordfence
7.2 High Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field No login needed ≤ 2.1.7 CVE-2026-3231 Wordfence
6.4 Medium Gravity Forms Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title ≤ 2.9.28 CVE-2026-3492 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation 8.0.0 – 9.0.2 CVE-2026-1992 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Privilege Escalation Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update 7.1.0 – 9.0.2 CVE-2026-1993 Wordfence
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
4.3 Medium Modular Connector Plugin Cross-Site Request Forgery Cross-Site Request Forgery via postConfirmOauth No login needed ≤ 2.5.1 CVE-2026-3903 Wordfence
5.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter ≤ 3.21.0 CVE-2026-2917 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions ≤ 3.21.0 CVE-2026-2918 Wordfence
6.4 Medium Astra Theme astra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta ≤ 4.12.3 CVE-2026-3534 Wordfence
9.8 Critical Datalogics Ecommerce Delivery Plugin datalogics Privilege Escalation Unauthenticated Privilege Escalation No login needed < 2.6.60 Fixed in 2.6.60 CVE-2026-2631 WPScan
8.1 High Divi Booster Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed < 5.0.2 Fixed in 5.0.2 CVE-2026-2626 WPScan
7.1 High DukaPress Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.2.4 CVE-2026-2466 WPScan
5.9 Medium WP Front User Submit Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed < 5.0.6 Fixed in 5.0.6 CVE-2026-1867 WPScan
6.8 Medium Gutena Forms Plugin gutena-forms Broken Access Control Contributor+ Arbitrary Limited Options Update < 1.6.1 Fixed in 1.6.1 CVE-2026-1753 WPScan
7.5 High WP Maps Plugin wp-google-map-plugin SQL Injection Unauthenticated SQL Injection via 'location_id' Parameter No login needed ≤ 4.9.1 CVE-2026-3222 Wordfence
6.4 Medium weForms Plugin weforms Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API ≤ 1.6.27 CVE-2026-2707 Wordfence
6.4 Medium WP ULike Plugin wp-ulike Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 5.0.1 CVE-2026-2358 Wordfence
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass ≤ 1.7.1049 CVE-2025-13067 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only