WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Subscriber+ Gift Card Theft and Destruction via Unauthorized Redemption < 3.2.10 Fixed in 3.2.10 CVE-2026-75861 WPScan
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-18042 WPScan
6.8 Medium Content Mask Plugin content-mask Cross-Site Scripting Contributor+ Stored XSS via Post Scripts and Styles 1.7.1 – < 1.8.5.6 Fixed in 1.8.5.6 CVE-2025-15690 WPScan
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode ≤ 10.8.0 CVE-2026-75905 Wordfence
4.3 Medium ilGhera Reviso Exporter for WooCommerce Plugin wc-exporter-for-reviso Broken Access Control Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function ≤ 1.2.3 CVE-2026-8615 Wordfence
5.3 Medium WPFunnels Plugin wpfunnels Broken Access Control Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation via 'wpfnl_load_payment' AJAX Action No login needed ≤ 3.12.13 CVE-2026-84908 Wordfence
4.3 Medium Awesome Support Plugin awesome-support Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter ≤ 6.3.9 CVE-2026-19946 Wordfence
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter ≤ 2.2.1 CVE-2026-19945 Wordfence
5.4 Medium Eventin Plugin wp-event-solution Broken Access Control Missing Authorization to Authenticated (Subscriber+) Notification Flow Management via notification-flow REST API Endpoint ≤ 4.1.17 CVE-2026-11821 Wordfence
6.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter ≤ 4.5.5 CVE-2026-75966 Wordfence
4.9 Medium WP Crowdfunding Plugin wp-crowdfunding SQL Injection Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta ≤ 2.2.1 CVE-2026-19944 Wordfence
4.9 Medium Mail Mint Plugin mail-mint SQL Injection Authenticated (Custom+) SQL Injection via 'status' Parameter ≤ 1.31.0 CVE-2026-19800 Wordfence
6.6 Medium Ninja Forms Plugin ninja-forms PHP Object Injection Authenticated (Administrator+) PHP Object Injection via Form Import ≤ 3.14.6 CVE-2026-11363 Wordfence
6.4 Medium My Calendar Plugin my-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes ≤ 3.8.3 CVE-2026-77187 Wordfence
6.4 Medium My Calendar Plugin my-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'fallback' Shortcode Attribute ≤ 3.8.3 CVE-2026-77186 Wordfence
6.1 Medium User Access Manager Plugin user-access-manager Cross-Site Scripting Reflected Cross-Site Scripting via 'tab_group_section' Parameter No login needed ≤ 2.3.18 CVE-2026-19797 Wordfence
6.1 Medium Product Filter for WooCommerce by WBW Plugin woo-product-filter Cross-Site Scripting Reflected Cross-Site Scripting via 'wpf_fid' Parameter No login needed ≤ 3.4.2 CVE-2026-7804 Wordfence
6.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting ≤ 3.1.11 CVE-2026-13709 Wordfence
5.3 Medium Eventin Plugin wp-event-solution Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Creation and Status Manipulation via 'status' Parameter No login needed ≤ 4.1.22 CVE-2026-12956 Wordfence
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
6.5 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.10.3.1 CVE-2026-18021 Wordfence
6.5 Medium WPML Multilingual CMS Plugin Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ ≤ 4.9.5 CVE-2026-17509 Wordfence
6.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' ≤ 4.3.9.1 CVE-2026-12230 Wordfence
6.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter ≤ 3.3.205 CVE-2026-76931 Wordfence
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
6.5 Medium Email Subscribers & Newsletters Plugin email-subscribers Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field No login needed ≤ 5.9.27 CVE-2026-12757 Wordfence
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion No login needed ≤ 2.2.0 CVE-2026-8279 Wordfence
5.3 Medium Otter Blocks Plugin otter-blocks Broken Access Control Missing Authorization to Unauthenticated Purchase Verification Bypass No login needed ≤ 3.1.7 CVE-2026-4945 Wordfence
5.4 Medium Flamingo Plugin flamingo Broken Access Control Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search ≤ 2.6.2 CVE-2026-12853 Wordfence
6.4 Medium Powerkit Plugin powerkit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing ≤ 3.0.4 CVE-2026-2390 Wordfence
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags No login needed 3.14.10 – < 3.15.2 Fixed in 3.15.2 CVE-2026-80437 WPScan
4.8 Medium Redirection for Contact Form 7 Plugin wpcf7-redirect Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags No login needed 2.2.7 – < 3.2.11 Fixed in 3.2.11 CVE-2026-80439 WPScan
4.8 Medium JetFormBuilder Plugin Content Injection Unauthenticated Email Header Injection via Send Email Action No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19862 WPScan
6.5 Medium JetFormBuilder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19859 WPScan
5.3 Medium B2BKing Plugin Broken Access Control Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection No login needed < 5.2.40 Fixed in 5.2.40 CVE-2026-85038 WPScan
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via Slider Elements' additional_settings < 5.9.9 Fixed in 5.9.9 CVE-2026-84028 WPScan
6.5 Medium SureCart Plugin surecart Broken Access Control Unauthenticated Account Creation with Automatic Login No login needed < 4.7.0 Fixed in 4.7.0 CVE-2026-75793 WPScan
4.3 Medium Real Estate Papi Theme Cross-Site Request Forgery Subscriber+ Plugin Installation ≤ 1.0.5 CVE-2026-13159 WPScan
4.3 Medium Ninja Forms - Save Progress Plugin Broken Access Control Save Progress <= 3.0.30 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Data Deletion via admin-ajax.php with admin_init Hook ≤ 3.0.30 CVE-2026-15550 Wordfence
5.4 Medium LearnDash LMS Plugin Broken Access Control Unauthenticated Arbitrary Course Enrollment via REST Endpoint 4.25.0 – 5.1.6 CVE-2026-12843 Wordfence
6.4 Medium Pods Plugin pods Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute ≤ 3.3.9.1 CVE-2026-76573 Wordfence
4.3 Medium Custom Contact Forms Plugin custom-contact-forms Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters ≤ 7.16 CVE-2026-75018 Wordfence
6.4 Medium Gallery : FooGallery Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute ≤ 3.3.2 CVE-2026-85414 Wordfence
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed ≤ 2.0.17 CVE-2026-75586 Wordfence
5.0 Medium Divi Theme Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter ≤ 4.27.6 CVE-2026-4361 Wordfence
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter ≤ 4.27.6 CVE-2026-3853 Wordfence
6.5 Medium WP File Download Plugin wp-file-download Path Traversal Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter ≤ 6.3.8 CVE-2026-14975 Wordfence
6.1 Medium Beaver Builder Plugin (Pro Version) Plugin Cross-Site Scripting Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter No login needed ≤ 2.11.0.1 CVE-2026-18843 Wordfence
6.8 Medium YT Player Plugin SQL Injection Contributor+ SQLi via ytp_ajax < 2.1.0 Fixed in 2.1.0 CVE-2026-84937 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only