WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,701–8,750 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 175 of 594
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WP Duplicate Plugin local-sync Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action ≤ 1.1.8 CVE-2026-1499 Wordfence
6.4 Medium Employee Directory Plugin employee-staff-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_title' Shortcode Attribute ≤ 1.2.1 CVE-2026-1279 Wordfence
6.4 Medium Tune Library Plugin tune-library Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import ≤ 1.6.3 CVE-2026-1401 Wordfence
6.4 Medium WaveSurfer-WP Plugin wavesurfer-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute ≤ 2.8.3 CVE-2026-1909 Wordfence
5.3 Medium OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Broken Access Control SSO (OAuth Client) <= 6.26.14 - Missing Authorization No login needed ≤ 6.26.14 CVE-2025-10753 Wordfence
6.4 Medium Orange Confort+ accessibility toolbar Plugin orange-confort-plus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.7 CVE-2026-1808 Wordfence
6.4 Medium Docus Plugin docus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.6 CVE-2026-1888 Wordfence
4.3 Medium Timeline Block Plugin timeline-block-block Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode Attribute ≤ 1.3.3 CVE-2026-1228 Wordfence
5.4 Medium GreenShift - Animation and Page Builder Blocks Plugin greenshift-animation-and-page-builder-blocks Broken Access Control Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css ≤ 12.6 CVE-2026-1927 Wordfence
6.1 Medium Peter's Date Countdown Plugin peters-date-countdown Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 2.0.0 CVE-2026-1654 Wordfence
7.2 High All In One Image Viewer Block Plugin image-viewer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via image-proxy Endpoint No login needed ≤ 1.0.2 CVE-2026-1294 Wordfence
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification No login needed ≤ 5.9.7.2 CVE-2026-1271 Wordfence
5.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update No login needed ≤ 3.3.5 CVE-2025-14079 Wordfence
6.4 Medium Robin Image Optimizer Plugin robin-image-optimizer Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text Field ≤ 2.0.2 CVE-2026-1319 Wordfence
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension ≤ 5.9.7.2 CVE-2025-13416 Wordfence
6.4 Medium Dynamic Widget Content Plugin dynamic-widget-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Content Field ≤ 1.3.6 CVE-2026-1268 Wordfence
6.4 Medium Essential Widgets Plugin essential-widgets Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.0 CVE-2026-0867 Wordfence
4.9 Medium ShortPixel Image Optimizer Plugin shortpixel-image-optimiser Path Traversal Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter ≤ 6.4.2 CVE-2026-1246 Wordfence
8.2 High Popup builder with Gamification Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed ≤ 2.2.0 CVE-2025-13192 Wordfence
8.8 High SportsPress Plugin sportspress Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.7.26 CVE-2025-15368 Wordfence
4.9 Medium All push notification for WP Plugin all-push-notification SQL Injection Authenticated (Administrator+) SQL Injection via 'delete_id' Parameter ≤ 1.5.3 CVE-2026-0816 Wordfence
4.9 Medium SIBS - WooCommerce Plugin sibs-woocommerce SQL Injection WooCommerce <= 2.2.0 - Authenticated (Admin+) SQL Injection via 'referencedId' Parameter ≤ 2.2.0 CVE-2026-1370 Wordfence
4.9 Medium Code Explorer Plugin code-explorer Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'file' Parameter ≤ 1.4.6 CVE-2025-15487 Wordfence
4.4 Medium WP Content Permission Plugin wp-content-permission Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'ohmem-message' Parameter ≤ 1.2 CVE-2026-0743 Wordfence
6.4 Medium Smart Appointment & Booking Plugin smart-appointment-booking Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action ≤ 1.0.7 CVE-2026-0742 Wordfence
5.3 Medium Fortis for WooCommerce Plugin fortis-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint No login needed ≤ 1.2.0 CVE-2026-0679 Wordfence
6.5 Medium WebPurify Profanity Filter Plugin webpurifytextreplace Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Change via webpurify_save_options No login needed ≤ 4.0.2 CVE-2026-0572 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.6 CVE-2025-15508 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Broken Access Control Missing Authorization to Unauthenticated Plugin License Status Modification No login needed ≤ 1.0.5 CVE-2025-15507 Wordfence
7.5 High Infility Global Plugin infility-global SQL Injection Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass No login needed ≤ 2.14.46 CVE-2025-15268 Wordfence
4.4 Medium Extended Random Number Generator Plugin extended-random-number-generator Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings ≤ 1.1 CVE-2026-0681 Wordfence
7.5 High SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Broken Access Control Unauthenticated Arbitrary Post/Category Modification No login needed ≤ 2.2.1 CVE-2025-15285 Wordfence
5.3 Medium Xendit Payment Plugin woo-xendit-virtual-accounts Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid No login needed ≤ 6.0.2 CVE-2025-14461 Wordfence
6.5 Medium MyRewards – Loyalty Points and Rewards for WooCommerce Plugin woorewards Broken Access Control Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification ≤ 5.6.1 CVE-2025-15260 Wordfence
5.3 Medium Chapa Payment Gateway Plugin for WooCommerce Plugin chapa-payment-gateway-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.3 CVE-2025-15482 Wordfence
8.8 High WP FOFT Loader Plugin wp-foft-loader Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.1.39 CVE-2026-1756 Wordfence
6.4 Medium Menu Icons by ThemeIsle Plugin menu-icons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 0.13.20 CVE-2026-1755 Wordfence
6.5 Medium Passster Plugin content-protector Broken Access Control ≤ 4.2.25 Fixed in 4.2.26 CVE-2026-25036 Patchstack
5.4 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-25028 Patchstack
7.5 High Unicamp Plugin unicamp Local File Inclusion ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-25027 Patchstack
5.4 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Request Forgery No login needed ≤ 3.11.9 Fixed in 3.11.10 CVE-2026-25024 Patchstack
5.3 Medium Run Contests, Raffles, and Giveaways with ContestsWP Plugin contest-code-checker Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.7 Fixed in 2.1.1 CVE-2026-25023 Patchstack
8.5 High KiviCare Plugin kivicare-clinic-management-system SQL Injection ≤ 3.6.16 Fixed in 4.0.0 CVE-2026-25022 Patchstack
5.4 Medium Mizan Demo Importer Plugin mizan-demo-importer Broken Access Control ≤ 0.1.3 Fixed in 0.1.4 CVE-2026-25021 Patchstack
4.3 Medium WP Sync for Notion Plugin wp-sync-for-notion Broken Access Control ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-25020 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-25019 Patchstack
4.3 Medium Nelio Popups Plugin nelio-popups Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2026-25016 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.53 Fixed in 1.2.54 CVE-2026-25015 Patchstack
4.3 Medium Enter Addons Plugin enteraddons Cross-Site Request Forgery No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-25014 Patchstack
5.3 Medium WP Bannerize Pro Plugin wp-bannerize-pro Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2026-25012 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only