WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Depicter Plugin Arbitrary File Upload Editor+ Arbitrary File Upload via ZIP Import < 4.8.0 Fixed in 4.8.0 CVE-2026-15049 WPScan
7.5 High Events Made Easy Plugin events-made-easy Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property ≤ 3.2.5 CVE-2026-75963 Wordfence
8.1 High Resido Theme resido Local File Inclusion No login needed ≤ 1.5 CVE-2026-73387 Patchstack
7.5 High Track Geolocation Of Users Using Contact Form 7 Plugin track-geolocation-of-users-using-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.2 CVE-2026-73386 Patchstack
7.5 High Outranking Plugin Options Plugin outranking Broken Access Control No login needed ≤ 1.1.3 CVE-2026-73385 Patchstack
7.5 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 CVE-2026-73384 Patchstack
7.1 High SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Scripting No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-73354 Patchstack
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting No login needed ≤ 11.1.2 CVE-2026-73184 Patchstack
7.1 High BBQ Pro Plugin bbq-pro Cross-Site Scripting No login needed ≤ 3.9 Fixed in 3.9.1 CVE-2026-73182 Patchstack
8.5 High Community by PeepSo Plugin peepso-core SQL Injection ≤ 9.0.5.2 Fixed in 9.0.5.3 CVE-2026-66668 Patchstack
7.1 High Newsletter Plugin newsletter Cross-Site Scripting No login needed ≤ 9.3.3 Fixed in 9.3.4 CVE-2026-66596 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.5 Fixed in 30.0.6 CVE-2026-61986 Patchstack
8.5 High YITH WooCommerce Membership Premium Plugin yith-woocommerce-membership-premium SQL Injection ≤ 2.33.0 Fixed in 2.33.1 CVE-2026-32552 Patchstack
7.5 High Stitch Express Plugin stitch-express Broken Access Control No login needed ≤ 1.9.0 CVE-2026-73394 Patchstack
7.2 High TranslatePress – Translate Multilingual sites with AI Translation Plugin translatepress-multilingual Cross-Site Scripting Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.2.5 CVE-2026-75981 Wordfence
7.2 High WP Statistics Plugin wp-statistics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter No login needed ≤ 14.16.8 CVE-2026-15780 Wordfence
8.8 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite No login needed 4.8.85 – < 5.4.7 Fixed in 5.4.7 CVE-2026-19842 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via 'page' Parameter No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19056 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via Multiple Parameters No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19055 WPScan
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
8.6 High Product Shortlist Plugin SQL Injection Unauthenticated SQL Injection via get_shortlisted_products No login needed ≤ 1.0.4 CVE-2026-16950 WPScan
8.8 High Simple File List Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Description No login needed ≤ 6.3.11 CVE-2026-16617 WPScan
8.6 High Simple File List Plugin Path Traversal Unauthenticated Arbitrary File Read and Move via Path Traversal No login needed ≤ 6.3.11 CVE-2026-16616 WPScan
7.1 High NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Cross-Site Scripting Reflected XSS via Facebook OAuth Callback No login needed < 4.4.8 Fixed in 4.4.8 CVE-2026-16570 WPScan
7.5 High User Verification Plugin Broken Access Control Unauthenticated Arbitrary Account Lockout via IDOR No login needed ≤ 2.0.47 CVE-2026-14861 WPScan
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
7.2 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Speaker Account Deletion via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13174 WPScan
8.1 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13169 WPScan
8.6 High Dinatur Plugin SQL Injection Unauthenticated SQL Injection via Column Name Injection No login needed ≤ 1.18 CVE-2026-12983 WPScan
8.5 High Advanced File Manager Plugin file-manager-advanced Path Traversal Authenticated Arbitrary File Read and Write via fma_load_fma_ui < 5.4.13 Fixed in 5.4.13 CVE-2026-11565 WPScan
8.1 High Atarim Plugin atarim-visual-collaboration Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta ≤ 5.1.1 CVE-2026-19942 Wordfence
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
7.5 High Starter Templates by Kadence WP Plugin kadence-starter-templates Denial of Service Denial of Service Attack No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-73997 Patchstack
7.5 High Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.11.3 Fixed in 1.8.12 CVE-2026-73994 Patchstack
8.1 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion No login needed ≤ 2.4.11 CVE-2026-73400 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
7.1 High Subscribe2 Plugin subscribe2 Cross-Site Scripting No login needed ≤ 10.46 CVE-2026-73393 Patchstack
7.1 High Site Reviews Plugin site-reviews Cross-Site Scripting No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2026-73382 Patchstack
7.1 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73378 Patchstack
7.5 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73377 Patchstack
7.1 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Cross-Site Scripting No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73375 Patchstack
7.2 High Easy Google Maps Plugin google-maps-easy Local File Inclusion Remote File Inclusion No login needed < 1.14.2 Fixed in 1.14.2 CVE-2026-73367 Patchstack
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-73362 Patchstack
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.1 High Chaty Pro Plugin chaty-pro Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-73360 Patchstack
7.1 High Affiliates Manager Plugin affiliates-manager Cross-Site Scripting No login needed ≤ 2.9.53 Fixed in 2.9.54 CVE-2026-73358 Patchstack
8.2 High Breeze Plugin breeze Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.5.12 Fixed in 2.5.13 CVE-2026-73356 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-73351 Patchstack
8.2 High SupportCandy Plugin supportcandy Authentication Bypass Broken Authentication No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-73350 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only