WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 8,501–8,550 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Mailchimp List Subscribe Form | Cross-Site Request Forgery Cross-Site Request Forgery to Mailchimp List Change No login needed |
≤ 2.0.0 |
CVE-2025-12172 |
Wordfence | |
| 6.1 Medium | Aruba HiSpeed Cache | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.0.2 |
CVE-2025-11706 |
Wordfence | |
| 6.4 Medium | Smartsupp – live chat, AI shopping assistant and chatbots | Cross-Site Scripting live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.9.1 |
CVE-2025-12448 |
Wordfence | |
| 6.5 Medium | Aruba HiSpeed Cache | Broken Access Control Missing Authorization to Unauthenticated Plugin's Settings Modification No login needed |
≤ 3.0.2 |
CVE-2025-11725 |
Wordfence | |
| 4.3 Medium | Mesmerize Companion | Broken Access Control Missing Authorization Authenticated (Subscriber+) Settings Update |
≤ 1.6.158 |
CVE-2025-12027 |
Wordfence | |
| 4.3 Medium | Booking Calendar | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification |
≤ 10.14.14 |
CVE-2026-2230 |
Wordfence | |
| 6.1 Medium | Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting via Filter Parameters No login needed |
≤ 2.11.1 |
CVE-2026-1404 |
Wordfence | |
| 8.8 High | Advanced AJAX Product Filters | PHP Object Injection Authenticated (Author+) PHP Object Injection via Live Composer Compatibility |
≤ 3.1.9.6 |
CVE-2026-1426 |
Wordfence | |
| 3.7 Low | WP All Export | Information Disclosure Unauthenticated Sensitive Information Exposure via PHP Type Juggling No login needed |
≤ 1.4.14 |
CVE-2026-1582 |
Wordfence | |
| 6.5 Medium | WP Import – Ultimate CSV XML Importer | SQL Injection Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name |
≤ 7.37 |
CVE-2026-1317 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' |
≤ 6.4.7 |
CVE-2026-2386 |
Wordfence | |
| 4.9 Medium | Bookster – WordPress Appointment Booking | SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' |
≤ 2.1.1 |
CVE-2025-8781 |
Wordfence | |
| 6.5 Medium | Brevo - Email, SMS, Web Push, Chat, and more. | Broken Access Control Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling No login needed |
≤ 3.3.0 |
CVE-2025-14799 |
Wordfence | |
| 6.5 Medium | WP-DownloadManager | Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter |
≤ 1.69 |
CVE-2026-2426 |
Wordfence | |
| 6.5 Medium | Blog2Social: Social Media Auto Post & Scheduler | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification |
≤ 8.7.4 |
CVE-2026-1942 |
Wordfence | |
| 5.3 Medium | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Price Manipulation Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment No login needed |
≤ 6.0.6.9 |
CVE-2025-14444 |
Wordfence | |
| 6.4 Medium | Complianz | GDPR/CCPA Cookie Consent | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 7.4.3 |
CVE-2025-11185 |
Wordfence | |
| 5.3 Medium | User Submitted Posts | Broken Access Control Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter No login needed |
≤ 20260113 |
CVE-2026-2126 |
Wordfence | |
| 4.4 Medium | Video Share VOD | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values |
≤ 2.7.11 |
CVE-2025-13727 |
Wordfence | |
| 5.3 Medium | Business Directory | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Listing Modification No login needed |
≤ 6.4.20 |
CVE-2026-1656 |
Wordfence | |
| 5.4 Medium | SiteOrigin Widgets Bundle | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.70.4 |
CVE-2026-2127 |
Wordfence | |
| 4.4 Medium | Community Events | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter |
≤ 1.5.7 |
CVE-2026-1649 |
Wordfence | |
| 7.5 High | WPNakama | SQL Injection Unauthenticated SQL Injection via 'order' REST API Parameter No login needed |
≤ 0.6.5 |
CVE-2026-2495 |
Wordfence | |
| 6.4 Medium | WP Event Aggregator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.8.7 |
CVE-2026-1941 |
Wordfence | |
| 4.3 Medium | Dam Spam | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Pending Comment Deletion No login needed |
≤ 1.0.8 |
CVE-2026-2112 |
Wordfence | |
| 4.3 Medium | Kali Forms | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure |
≤ 2.4.8 |
CVE-2026-1860 |
Wordfence | |
| 2.7 Low | YayMail | Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation |
≤ 4.3.2 |
CVE-2026-1831 |
Wordfence | |
| 4.4 Medium | YayMail | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements |
≤ 4.3.2 |
CVE-2026-1943 |
Wordfence | |
| 5.3 Medium | YayMail | Broken Access Control Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint No login needed |
≤ 4.3.2 |
CVE-2026-1938 |
Wordfence | |
| 4.3 Medium | EventPrime | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter |
≤ 4.2.8.4 |
CVE-2026-1655 |
Wordfence | |
| 2.7 Low | WP-DownloadManager | Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter |
≤ 1.69 |
CVE-2026-2419 |
Wordfence | |
| 7.2 High | Product Addons for Woocommerce – Product Options with Custom Fields | Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter |
≤ 3.1.0 |
CVE-2026-2296 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Broken Access Control Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload |
≤ 3.6.1 |
CVE-2026-2633 |
Wordfence | |
| 4.4 Medium | Private Comment | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting |
≤ 0.0.4 |
CVE-2026-2281 |
Wordfence | |
| 4.3 Medium | Taskbuilder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation |
≤ 5.0.2 |
CVE-2026-1640 |
Wordfence | |
| 7.2 High | YayMail | Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action |
≤ 4.3.2 |
CVE-2026-1937 |
Wordfence | |
| 6.4 Medium | InteractiveCalculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.0.3 |
CVE-2026-1807 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter |
≤ 3.6.1 |
CVE-2026-1857 |
Wordfence | |
| 6.1 Medium | Download Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect_to' Parameter No login needed |
≤ 3.3.46 |
CVE-2026-1666 |
Wordfence | |
| 7.2 High | Cart All In One For WooCommerce | Remote Code Execution Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting |
≤ 1.1.21 |
CVE-2026-2019 |
Wordfence | |
| 7.5 High | Video Conferencing with Zoom API | Authentication Bypass Unauthenticated SDK Signature Generation No login needed |
< 4.6.6 Fixed in 4.6.6 |
CVE-2026-1368 |
WPScan | |
| 4.4 Medium | Membership Plugin – Restrict Content | Cross-Site Scripting Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings |
≤ 3.2.18 |
CVE-2026-1304 |
Wordfence | |
| 4.3 Medium | Tickera – WordPress Event Ticketing | Broken Access Control WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update |
≤ 3.5.6.4 |
CVE-2025-12356 |
Wordfence | |
| 6.4 Medium | Popup Box – Easily Create WordPress Popups | Cross-Site Scripting Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.2.12 |
CVE-2025-12122 |
Wordfence | |
| 4.3 Medium | PDF Invoices & Packing Slips for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification |
≤ 5.6.0 |
CVE-2026-1906 |
Wordfence | |
| 4.3 Medium | Keybase.io Verification | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.4.5 |
CVE-2026-1072 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters |
≤ 5.0.2 |
CVE-2026-1639 |
Wordfence | |
| 6.4 Medium | VK All in One Expansion Unit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title |
≤ 9.112.3 |
CVE-2025-11737 |
Wordfence | |
| 4.3 Medium | WP Plugin Info Card | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation No login needed |
≤ 6.2.0 |
CVE-2026-2023 |
Wordfence | |
| 7.5 High | Business Directory | SQL Injection Unauthenticated SQL Injection via payment Parameter No login needed |
≤ 6.4.21 |
CVE-2026-2576 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.