WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93341 VulnCheck
7.6 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar SQL Injection WordPress Notification Bar plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 Fixed in 2.0.4 CVE-2026-94117 Patchstack
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
4.9 Medium Product Feed Manager for WooCommerce Plugin webappick-product-feed-for-woocommerce Path Traversal Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter ≤ 6.6.43 CVE-2026-15095 Wordfence
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute ≤ 6.8.0 CVE-2026-9231 Wordfence
7.2 High WPC Product Bundles for WooCommerce Plugin woo-product-bundle Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter No login needed ≤ 8.6.6 CVE-2026-93836 Wordfence
4.3 Medium WP User Manager Plugin wp-user-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connect Callback ≤ 2.9.18 CVE-2026-18345 Wordfence
4.3 Medium WP-CRM System Plugin wp-crm-system Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter ≤ 3.4.6 CVE-2026-9004 Wordfence
4.3 Medium ThumbPress Plugin image-sizes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation ≤ 6.2.1 CVE-2026-7622 Wordfence
5.3 Medium Handily Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_publishbale_key' Parameter No login needed ≤ 1.0.3 CVE-2025-14487 Wordfence
6.5 Medium BM Content Builder Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read < 3.17.1 Fixed in 3.17.1 CVE-2025-1280 Wordfence
7.2 High WP Yelp Review Slider Plugin wp-yelp-review-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) No login needed ≤ 9.2 CVE-2026-93778 Wordfence
8.1 High WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter ≤ 2.4.2 CVE-2026-92235 Wordfence
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Action / Forged comment_author_email Cookie ≤ 3.1.5 CVE-2026-91092 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter ≤ 4.0.7 CVE-2026-18439 Wordfence
7.1 High WP Table Builder Plugin wp-table-builder Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter ≤ 2.2.1 CVE-2026-6922 Wordfence
4.4 Medium Hostel Plugin hostel Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localization file URL Setting ≤ 1.1.8 CVE-2026-1645 Wordfence
4.3 Medium RW Elephant Rental Inventory Plugin rw-elephant-rental-inventory Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'toggle_cache' AJAX Action ≤ 2.3.13 CVE-2026-4123 Wordfence
8.8 High BM Content Builder Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion < 3.17.1 Fixed in 3.17.1 CVE-2025-1281 Wordfence
8.1 High HUSKY Plugin woocommerce-products-filter Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed ≤ 1.4.4 CVE-2026-92969 Wordfence
5.3 Medium PixelPlay Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter No login needed ≤ 1.0.2 CVE-2025-14486 Wordfence
5.3 Medium Image Buzz Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Parameter No login needed ≤ 1.0.3 CVE-2025-14484 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content ≤ 2.1.21 CVE-2026-16778 Wordfence
4.3 Medium Custom Field Template Plugin custom-field-template Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter ≤ 2.7.8 CVE-2026-12995 Wordfence
7.5 High Ninja Forms Plugin ninja-forms PHP Object Injection Unauthenticated PHP Object Injection via CSV Export No login needed 3.15.3 – < 3.15.4 Fixed in 3.15.4 CVE-2026-91827 WPScan
8.8 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin No login needed 3.15.3 – < 3.15.4 Fixed in 3.15.4 CVE-2026-92438 WPScan
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed ≤ 3.15.3 CVE-2026-94504 Wordfence
7.2 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel No login needed ≤ 3.3.5 CVE-2026-89412 Wordfence
6.8 Medium Text Styler Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.1.1 CVE-2026-88788 WPScan
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter No login needed ≤ 11.8.3 CVE-2026-93655 Wordfence
7.2 High CMP Plugin cmp-coming-soon-maintenance Privilege Escalation Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action ≤ 4.1.17 CVE-2026-12470 Wordfence
6.4 Medium Contextual Related Posts Plugin contextual-related-posts Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter ≤ 4.4.1 CVE-2026-85653 Wordfence
9.8 Critical Give Tributes Plugin PHP Object Injection Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter No login needed ≤ 2.3.1 CVE-2026-19658 Wordfence
9.8 Critical Meta Box AIO Plugin Privilege Escalation Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter No login needed ≤ 4.5.6 CVE-2026-13355 Wordfence
5.4 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute < 3.1.70 Fixed in 3.1.70 CVE-2026-93339 VulnCheck
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-92400 WPScan
3.7 Low To Do List Member Plugin Content Injection Unauthenticated Content Injection via Import No login needed 1.4 – 1.6 CVE-2026-86802 WPScan
6.5 Medium GiveWP Plugin give Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Donor Name No login needed 4.13.2 – < 4.16.9 Fixed in 4.16.9 CVE-2026-85113 WPScan
5.3 Medium RestroPress Plugin restropress Price Manipulation Unauthenticated Price Manipulation via Cart Add-ons No login needed < 3.4.6 Fixed in 3.4.6 CVE-2026-85010 WPScan
9.8 Critical WooCommerce Online Product Designer 1.7.0 Plugin Arbitrary File Upload < 2.15.0 - Unauthenticated Arbitrary File Upload No login needed 1.7.0 – < 2.15.0 Fixed in 2.15.0 CVE-2026-82187 WPScan
3.7 Low TikTok Plugin tiktok-for-business Broken Access Control Unauthenticated OAuth Code Redemption No login needed 1.2.0 – < 1.4.2 Fixed in 1.4.2 CVE-2026-92965 WPScan
7.2 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Custom Role Privilege Escalation to Administrator via Frontend Importer < 2.5.2 Fixed in 2.5.2 CVE-2026-92541 WPScan
7.2 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Custom Role Privilege Escalation to Administrator via caller_can_promote_users 2.4.16 – < 2.5.2 Fixed in 2.5.2 CVE-2026-92540 WPScan
2.7 Low Meow Gallery Plugin meow-gallery Information Disclosure Author+ Draft and Private Post Disclosure via fetch_posts < 5.5.5 Fixed in 5.5.5 CVE-2026-92423 WPScan
6.5 Medium Meow Gallery Plugin meow-gallery Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route No login needed < 5.5.5 Fixed in 5.5.5 CVE-2026-92422 WPScan
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery Arbitrary Sign-up Deletion via CSRF No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-92410 WPScan
5.3 Medium Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Booking Data Tampering No login needed 1.3.4 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87840 WPScan
7.5 High Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Arbitrary Comment Deletion No login needed 1.1.8 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87839 WPScan
6.6 Medium Forminator Forms Plugin forminator Privilege Escalation Authenticated Privilege Escalation via Quiz Lead-Form Import 1.57.0 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87068 WPScan
8.5 High Forminator Forms Plugin forminator Remote Code Execution Authenticated RCE via XML-RPC PHP Object Injection 1.57.0.7 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87067 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only