WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 801–850 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor PHP Object Injection Subscriber+ PHP Object Injection < 2.0.20 Fixed in 2.0.20 CVE-2026-85017 WPScan
6.8 Medium Kirki Plugin kirki Cross-Site Scripting Author+ Stored XSS via Unsanitized SVG Upload 6.0.0 – < 6.3.1 Fixed in 6.3.1 CVE-2026-84223 WPScan
8.1 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation Unauthenticated Privilege Escalation via Account Matching No login needed 4.8.43 – < 6.0.0 Fixed in 6.0.0 CVE-2026-82842 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Plugin Image Settings Update < 4.5.0 Fixed in 4.5.0 CVE-2026-81654 WPScan
4.2 Medium NextGEN Gallery Plugin Broken Access Control Authenticated Arbitrary Gallery Image Deletion via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81653 WPScan
2.7 Low NextGEN Gallery Plugin Information Disclosure Contributor+ Image Metadata Disclosure via IDOR 3.59.5 – < 4.5.0 Fixed in 4.5.0 CVE-2026-81652 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81651 WPScan
7.2 High NextGEN Gallery Plugin Arbitrary File Upload Authenticated Arbitrary File Upload via ZIP Import < 4.5.0 Fixed in 4.5.0 CVE-2026-81650 WPScan
4.1 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Server-Side Request Forgery Admin+ SSRF via bp_avatar < 2.4.5 Fixed in 2.4.5 CVE-2026-16542 WPScan
6.8 Medium Master Slider Plugin master-slider Cross-Site Scripting Contributor+ Stored XSS via ms_slider Shortcode Attributes ≤ 3.11.2 CVE-2026-14844 WPScan
4.3 Medium Partial Shipment for Woocommerce Plugin wc-partial-shipment Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions ≤ 3.4 CVE-2026-9858 Wordfence
4.7 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Reflected Cross-Site Scripting via ESI 'esi' Parameter No login needed ≤ 7.9 CVE-2026-76579 Wordfence
4.3 Medium Datalogics Ecommerce Delivery Plugin datalogics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping) ≤ 2.6.65 CVE-2026-9613 Wordfence
6.4 Medium YS LeadGen – Popups, Opt-ins & Lead Capture Plugin ysleadgen Broken Access Control Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input ≤ 2.1.4 CVE-2026-1256 Wordfence
4.3 Medium Empik for Woocommerce Plugin empik-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action ≤ 1.5.1 CVE-2026-9766 Wordfence
5.3 Medium WordLift Plugin wordlift Information Disclosure Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints No login needed ≤ 3.54.10 CVE-2026-9289 Wordfence
7.5 High YS LeadGen – Popups, Opt-ins & Lead Capture Plugin ysleadgen Information Disclosure Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action No login needed ≤ 2.1.4 CVE-2026-1255 Wordfence
5.3 Medium TikTok Plugin tiktok-for-business Broken Access Control Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter No login needed ≤ 1.4.1 CVE-2026-18346 Wordfence
6.4 Medium Gum Addon for Elementor Plugin gum-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting ≤ 1.3.15 CVE-2026-8354 Wordfence
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input ≤ 4.5.13 CVE-2026-5410 Wordfence
6.4 Medium Real 3D Flipbook Plugin real3d-flipbook-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute ≤ 5.1.1 CVE-2026-15098 Wordfence
6.1 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Reflected Cross-Site Scripting via 'data' Dynamic Content Tag No login needed ≤ 4.14.0 CVE-2026-87917 Wordfence
6.5 Medium Custom Field Template Plugin custom-field-template SQL Injection Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter ≤ 2.7.8 CVE-2026-9855 Wordfence
5.3 Medium Ibtana – Ecommerce Product Addons Plugin ibtana-ecommerce-product-addons Broken Access Control Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action No login needed ≤ 0.4.7.7 CVE-2026-1984 Wordfence
8.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) ≤ 4.17.2 CVE-2026-85658 Wordfence
4.7 Medium WP Ghost (Hide My WP Ghost) Plugin hide-my-wp Open Redirect Unauthenticated Open Redirect via 'redirect_to' Parameter No login needed ≤ 7.0.02 CVE-2026-7527 Wordfence
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Cross-Site Scripting via User Input ≤ 4.5.13 CVE-2026-5400 Wordfence
4.9 Medium GoPay for WooCommerce Plugin gopay-gateway SQL Injection Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter ≤ 1.0.36 CVE-2026-75959 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order' Parameter ≤ 2.5.3 CVE-2026-13200 Wordfence
4.4 Medium OTP Login & Register Woocommerce Plugin mobile-login-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'fb-config' Setting ≤ 2.7.3 CVE-2026-12402 Wordfence
8.8 High The Welcomizer Plugin the-welcomizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter ≤ 2.8.1 CVE-2026-4327 Wordfence
6.4 Medium WP Composer Plugin page-builder-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode ≤ 1.0.5 CVE-2026-2422 Wordfence
6.5 Medium Wow Elements Addons for Elementor Plugin wow-elements-addons-for-elementor Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting No login needed ≤ 1.11.2 CVE-2026-1641 Wordfence
6.1 Medium SSL Zen Plugin ssl-zen Cross-Site Scripting Reflected Cross-Site Scripting via 'uri' and 'host' Parameters No login needed ≤ 4.7.42 CVE-2026-15463 Wordfence
6.5 Medium Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action ≤ 3.12.27 CVE-2026-9232 Wordfence
4.3 Medium Search Atlas SEO Plugin metasync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function ≤ 2.6.23 CVE-2026-15946 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order_by' Parameter ≤ 2.5.3 CVE-2026-13191 Wordfence
4.9 Medium WP Optimizer Plugin wp-optimizer SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 2.5.0 CVE-2026-6295 Wordfence
6.4 Medium AppMySite Plugin appmysite Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler ≤ 3.15.3 CVE-2026-13770 Wordfence
5.3 Medium Payment Gateway of Stripe for WooCommerce Plugin payment-gateway-stripe-and-woocommerce-integration Other Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint No login needed ≤ 5.0.8 CVE-2026-9832 Wordfence
4.3 Medium BlockSpare - Gutenberg Site Builder Blocks & Starter Sites Plugin blockspare Broken Access Control Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation ≤ 4.2.6 CVE-2026-1242 Wordfence
4.3 Medium Search Atlas SEO Plugin metasync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter ≤ 2.6.23 CVE-2026-15947 Wordfence
5.3 Medium Bread Plugin bread Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.9.12 CVE-2026-4792 Wordfence
4.3 Medium VW Writer Blog Theme vw-writer-blog Broken Access Control Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset ≤ 1.3.8 CVE-2026-2278 Wordfence
7.2 High Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value No login needed ≤ 5.7.1 CVE-2026-15664 Wordfence
4.3 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler ≤ 2.0.11 CVE-2026-11899 Wordfence
6.1 Medium WP Customer Reviews Plugin wp-customer-reviews Cross-Site Scripting Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter No login needed ≤ 3.7.8 CVE-2026-11608 Wordfence
4.3 Medium Flex Import Plugin flex-import Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions ≤ 3.0 CVE-2026-9615 Wordfence
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Broken Access Control Unauthenticated Broken Access Control in REST API No login needed < 6.1.1 Fixed in 6.1.1 CVE-2026-92435 WPScan
5.3 Medium Rede Itaú for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Manipulation via PIX Webhook No login needed 3.6.1 – < 5.4.7 Fixed in 5.4.7 CVE-2026-92430 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only