WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 801–850 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting No login needed ≤ 11.1.2 CVE-2026-73184 Patchstack
7.1 High BBQ Pro Plugin bbq-pro Cross-Site Scripting No login needed ≤ 3.9 Fixed in 3.9.1 CVE-2026-73182 Patchstack
8.5 High Community by PeepSo Plugin peepso-core SQL Injection ≤ 9.0.5.2 Fixed in 9.0.5.3 CVE-2026-66668 Patchstack
7.1 High Newsletter Plugin newsletter Cross-Site Scripting No login needed ≤ 9.3.3 Fixed in 9.3.4 CVE-2026-66596 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.5 Fixed in 30.0.6 CVE-2026-61986 Patchstack
8.5 High YITH WooCommerce Membership Premium Plugin yith-woocommerce-membership-premium SQL Injection ≤ 2.33.0 Fixed in 2.33.1 CVE-2026-32552 Patchstack
7.5 High Stitch Express Plugin stitch-express Broken Access Control No login needed ≤ 1.9.0 CVE-2026-73394 Patchstack
7.2 High TranslatePress – Translate Multilingual sites with AI Translation Plugin translatepress-multilingual Cross-Site Scripting Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.2.5 CVE-2026-75981 Wordfence
7.2 High WP Statistics Plugin wp-statistics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter No login needed ≤ 14.16.8 CVE-2026-15780 Wordfence
8.8 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite No login needed 4.8.85 – < 5.4.7 Fixed in 5.4.7 CVE-2026-19842 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via 'page' Parameter No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19056 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via Multiple Parameters No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19055 WPScan
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
8.6 High Product Shortlist Plugin SQL Injection Unauthenticated SQL Injection via get_shortlisted_products No login needed ≤ 1.0.4 CVE-2026-16950 WPScan
8.8 High Simple File List Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Description No login needed ≤ 6.3.11 CVE-2026-16617 WPScan
8.6 High Simple File List Plugin Path Traversal Unauthenticated Arbitrary File Read and Move via Path Traversal No login needed ≤ 6.3.11 CVE-2026-16616 WPScan
7.1 High NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Cross-Site Scripting Reflected XSS via Facebook OAuth Callback No login needed < 4.4.8 Fixed in 4.4.8 CVE-2026-16570 WPScan
7.5 High User Verification Plugin Broken Access Control Unauthenticated Arbitrary Account Lockout via IDOR No login needed ≤ 2.0.47 CVE-2026-14861 WPScan
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
7.2 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Speaker Account Deletion via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13174 WPScan
8.1 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13169 WPScan
8.6 High Dinatur Plugin SQL Injection Unauthenticated SQL Injection via Column Name Injection No login needed ≤ 1.18 CVE-2026-12983 WPScan
8.5 High Advanced File Manager Plugin file-manager-advanced Path Traversal Authenticated Arbitrary File Read and Write via fma_load_fma_ui < 5.4.13 Fixed in 5.4.13 CVE-2026-11565 WPScan
8.1 High Atarim Plugin atarim-visual-collaboration Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta ≤ 5.1.1 CVE-2026-19942 Wordfence
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
7.5 High Starter Templates by Kadence WP Plugin kadence-starter-templates Denial of Service Denial of Service Attack No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-73997 Patchstack
7.5 High Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.11.3 Fixed in 1.8.12 CVE-2026-73994 Patchstack
8.1 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion No login needed ≤ 2.4.11 CVE-2026-73400 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
7.1 High Subscribe2 Plugin subscribe2 Cross-Site Scripting No login needed ≤ 10.46 CVE-2026-73393 Patchstack
7.1 High Site Reviews Plugin site-reviews Cross-Site Scripting No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2026-73382 Patchstack
7.1 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73378 Patchstack
7.5 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73377 Patchstack
7.1 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Cross-Site Scripting No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73375 Patchstack
7.2 High Easy Google Maps Plugin google-maps-easy Local File Inclusion Remote File Inclusion No login needed < 1.14.2 Fixed in 1.14.2 CVE-2026-73367 Patchstack
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-73362 Patchstack
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.1 High Chaty Pro Plugin chaty-pro Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-73360 Patchstack
7.1 High Affiliates Manager Plugin affiliates-manager Cross-Site Scripting No login needed ≤ 2.9.53 Fixed in 2.9.54 CVE-2026-73358 Patchstack
8.2 High Breeze Plugin breeze Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.5.12 Fixed in 2.5.13 CVE-2026-73356 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-73351 Patchstack
8.2 High SupportCandy Plugin supportcandy Authentication Bypass Broken Authentication No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-73350 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.18 Fixed in 3.0.19 CVE-2026-73345 Patchstack
7.1 High WP Multilang Plugin wp-multilang Cross-Site Scripting No login needed ≤ 2.4.31 Fixed in 2.4.32 CVE-2026-73342 Patchstack
7.1 High Autopay Plugin platnosci-online-blue-media Cross-Site Scripting No login needed ≤ 5.0.0 Fixed in 5.0.1 CVE-2026-73338 Patchstack
7.1 High WPDM – Premium Packages Plugin wpdm-premium-packages Cross-Site Scripting Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2026-73190 Patchstack
7.5 High Extra Product Options & Add-Ons for WooCommerce Plugin woocommerce-tm-extra-product-options Path Traversal Arbitrary File Download No login needed < 7.6 Fixed in 7.6 CVE-2026-73181 Patchstack
7.1 High Convert Pro Plugin convertpro Cross-Site Scripting No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2026-68567 Patchstack
7.1 High Templately Plugin templately Cross-Site Scripting No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2026-66667 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only