WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 751–800 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | MarketKing | Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX |
< 2.1.72 Fixed in 2.1.72 |
CVE-2026-93341 |
VulnCheck | |
| 7.6 High | HashBar – WordPress Notification Bar | SQL Injection WordPress Notification Bar plugin <= 2.0.3 - SQL Injection |
≤ 2.0.3 Fixed in 2.0.4 |
CVE-2026-94117 |
Patchstack | |
| 7.3 High | Taxi Booking Manager for WooCommerce | Authentication Bypass Broken Authentication No login needed |
< 2.0.8 Fixed in 2.0.8 |
CVE-2026-93928 |
Patchstack | |
| 4.9 Medium | Product Feed Manager for WooCommerce | Path Traversal Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter |
≤ 6.6.43 |
CVE-2026-15095 |
Wordfence | |
| 7.5 High | WP Travel Engine | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute |
≤ 6.8.0 |
CVE-2026-9231 |
Wordfence | |
| 7.2 High | WPC Product Bundles for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter No login needed |
≤ 8.6.6 |
CVE-2026-93836 |
Wordfence | |
| 4.3 Medium | WP User Manager | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connect Callback |
≤ 2.9.18 |
CVE-2026-18345 |
Wordfence | |
| 4.3 Medium | WP-CRM System | Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter |
≤ 3.4.6 |
CVE-2026-9004 |
Wordfence | |
| 4.3 Medium | ThumbPress | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation |
≤ 6.2.1 |
CVE-2026-7622 |
Wordfence | |
| 5.3 Medium | Handily | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_publishbale_key' Parameter No login needed |
≤ 1.0.3 |
CVE-2025-14487 |
Wordfence | |
| 6.5 Medium | BM Content Builder | Path Traversal Authenticated (Subscriber+) Arbitrary File Read |
< 3.17.1 Fixed in 3.17.1 |
CVE-2025-1280 |
Wordfence | |
| 7.2 High | WP Yelp Review Slider | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) No login needed |
≤ 9.2 |
CVE-2026-93778 |
Wordfence | |
| 8.1 High | WP Ultimate Review | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter |
≤ 2.4.2 |
CVE-2026-92235 |
Wordfence | |
| 4.3 Medium | wpForo Forum | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Action / Forged comment_author_email Cookie |
≤ 3.1.5 |
CVE-2026-91092 |
Wordfence | |
| 4.3 Medium | Tutor LMS | Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter |
≤ 4.0.7 |
CVE-2026-18439 |
Wordfence | |
| 7.1 High | WP Table Builder | Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter |
≤ 2.2.1 |
CVE-2026-6922 |
Wordfence | |
| 4.4 Medium | Hostel | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localization file URL Setting |
≤ 1.1.8 |
CVE-2026-1645 |
Wordfence | |
| 4.3 Medium | RW Elephant Rental Inventory | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'toggle_cache' AJAX Action |
≤ 2.3.13 |
CVE-2026-4123 |
Wordfence | |
| 8.8 High | BM Content Builder | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
< 3.17.1 Fixed in 3.17.1 |
CVE-2025-1281 |
Wordfence | |
| 8.1 High | HUSKY | Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed |
≤ 1.4.4 |
CVE-2026-92969 |
Wordfence | |
| 5.3 Medium | PixelPlay | Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter No login needed |
≤ 1.0.2 |
CVE-2025-14486 |
Wordfence | |
| 5.3 Medium | Image Buzz | Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Parameter No login needed |
≤ 1.0.3 |
CVE-2025-14484 |
Wordfence | |
| 6.4 Medium | Live Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content |
≤ 2.1.21 |
CVE-2026-16778 |
Wordfence | |
| 4.3 Medium | Custom Field Template | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter |
≤ 2.7.8 |
CVE-2026-12995 |
Wordfence | |
| 7.5 High | Ninja Forms | PHP Object Injection Unauthenticated PHP Object Injection via CSV Export No login needed |
3.15.3 – < 3.15.4 Fixed in 3.15.4 |
CVE-2026-91827 |
WPScan | |
| 8.8 High | Ninja Forms | Cross-Site Scripting Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin No login needed |
3.15.3 – < 3.15.4 Fixed in 3.15.4 |
CVE-2026-92438 |
WPScan | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed |
≤ 3.15.3 |
CVE-2026-94504 |
Wordfence | |
| 7.2 High | TranslatePress | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel No login needed |
≤ 3.3.5 |
CVE-2026-89412 |
Wordfence | |
| 6.8 Medium | Text Styler | Cross-Site Scripting Contributor+ Stored XSS |
≤ 1.1.1 |
CVE-2026-88788 |
WPScan | |
| 6.1 Medium | Booking Calendar | Cross-Site Scripting Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter No login needed |
≤ 11.8.3 |
CVE-2026-93655 |
Wordfence | |
| 7.2 High | CMP | Privilege Escalation Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action |
≤ 4.1.17 |
CVE-2026-12470 |
Wordfence | |
| 6.4 Medium | Contextual Related Posts | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter |
≤ 4.4.1 |
CVE-2026-85653 |
Wordfence | |
| 9.8 Critical | Give Tributes | PHP Object Injection Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter No login needed |
≤ 2.3.1 |
CVE-2026-19658 |
Wordfence | |
| 9.8 Critical | Meta Box AIO | Privilege Escalation Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter No login needed |
≤ 4.5.6 |
CVE-2026-13355 |
Wordfence | |
| 5.4 Medium | Ditty | Cross-Site Scripting Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute |
< 3.1.70 Fixed in 3.1.70 |
CVE-2026-93339 |
VulnCheck | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-92400 |
WPScan | |
| 3.7 Low | To Do List Member | Content Injection Unauthenticated Content Injection via Import No login needed |
1.4 – 1.6 |
CVE-2026-86802 |
WPScan | |
| 6.5 Medium | GiveWP | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Donor Name No login needed |
4.13.2 – < 4.16.9 Fixed in 4.16.9 |
CVE-2026-85113 |
WPScan | |
| 5.3 Medium | RestroPress | Price Manipulation Unauthenticated Price Manipulation via Cart Add-ons No login needed |
< 3.4.6 Fixed in 3.4.6 |
CVE-2026-85010 |
WPScan | |
| 9.8 Critical | WooCommerce Online Product Designer 1.7.0 | Arbitrary File Upload < 2.15.0 - Unauthenticated Arbitrary File Upload No login needed |
1.7.0 – < 2.15.0 Fixed in 2.15.0 |
CVE-2026-82187 |
WPScan | |
| 3.7 Low | TikTok | Broken Access Control Unauthenticated OAuth Code Redemption No login needed |
1.2.0 – < 1.4.2 Fixed in 1.4.2 |
CVE-2026-92965 |
WPScan | |
| 7.2 High | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via Frontend Importer |
< 2.5.2 Fixed in 2.5.2 |
CVE-2026-92541 |
WPScan | |
| 7.2 High | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via caller_can_promote_users |
2.4.16 – < 2.5.2 Fixed in 2.5.2 |
CVE-2026-92540 |
WPScan | |
| 2.7 Low | Meow Gallery | Information Disclosure Author+ Draft and Private Post Disclosure via fetch_posts |
< 5.5.5 Fixed in 5.5.5 |
CVE-2026-92423 |
WPScan | |
| 6.5 Medium | Meow Gallery | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route No login needed |
< 5.5.5 Fixed in 5.5.5 |
CVE-2026-92422 |
WPScan | |
| 4.3 Medium | Sign-up Sheets | Cross-Site Request Forgery Arbitrary Sign-up Deletion via CSRF No login needed |
< 2.4.0 Fixed in 2.4.0 |
CVE-2026-92410 |
WPScan | |
| 5.3 Medium | Tripzzy | Broken Access Control Unauthenticated Booking Data Tampering No login needed |
1.3.4 – < 1.5.1 Fixed in 1.5.1 |
CVE-2026-87840 |
WPScan | |
| 7.5 High | Tripzzy | Broken Access Control Unauthenticated Arbitrary Comment Deletion No login needed |
1.1.8 – < 1.5.1 Fixed in 1.5.1 |
CVE-2026-87839 |
WPScan | |
| 6.6 Medium | Forminator Forms | Privilege Escalation Authenticated Privilege Escalation via Quiz Lead-Form Import |
1.57.0 – < 1.57.2.1 Fixed in 1.57.2.1 |
CVE-2026-87068 |
WPScan | |
| 8.5 High | Forminator Forms | Remote Code Execution Authenticated RCE via XML-RPC PHP Object Injection |
1.57.0.7 – < 1.57.2.1 Fixed in 1.57.2.1 |
CVE-2026-87067 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.