WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,751–8,800 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 176 of 594
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.41 Fixed in 7.42 CVE-2026-25011 Patchstack
5.3 Medium Share This Image Plugin share-this-image Broken Access Control No login needed ≤ 2.09 Fixed in 2.10 CVE-2026-25010 Patchstack
5.3 Medium Hustle Plugin wordpress-popup Information Disclosure Sensitive Data Exposure No login needed ≤ 7.8.9.2 Fixed in 7.8.9.3 CVE-2026-24998 Patchstack
5.3 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-24997 Patchstack
4.3 Medium WPElemento Importer Plugin wpelemento-importer Broken Access Control ≤ 0.6.4 Fixed in 0.6.5 CVE-2026-24996 Patchstack
4.3 Medium Latest Post Shortcode Plugin latest-post-shortcode Broken Access Control ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-24995 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.7.2 Fixed in 3.5.7.3 CVE-2026-24994 Patchstack
5.3 Medium Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2026-24992 Patchstack
5.3 Medium Extensions For CF7 Plugin extensions-for-cf7 Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-24991 Patchstack
5.4 Medium WP Docs Plugin wp-docs Broken Access Control ≤ 2.2.8 Fixed in 2.2.9 CVE-2026-24990 Patchstack
6.5 Medium The Events Calendar Shortcode & Block Plugin the-events-calendar-shortcode Cross-Site Scripting ≤ 3.1.1 Fixed in 3.1.2 CVE-2026-24988 Patchstack
5.4 Medium Simple Membership WP user Import Plugin simple-membership-wp-user-import Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24986 Patchstack
4.3 Medium WP Forms Signature Contract Add-On Plugin wp-forms-signature-contract-add-on Broken Access Control Broken Access Control to Notice Dismissal ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-24985 Patchstack
6.5 Medium Visual Link Preview Plugin visual-link-preview Broken Access Control ≤ 2.2.9 Fixed in 2.3.0 CVE-2026-24984 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control No login needed ≤ 2.19.17 Fixed in 2.19.18 CVE-2026-24982 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control No login needed ≤ 1.2.38 Fixed in 2.0 CVE-2026-24967 Patchstack
4.3 Medium Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24966 Patchstack
4.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control ≤ 28.1.1 Fixed in 28.1.2 CVE-2026-24965 Patchstack
4.3 Medium Sigmize Plugin sigmize Cross-Site Request Forgery No login needed ≤ 0.0.9 Fixed in 0.0.10 CVE-2026-24962 Patchstack
5.4 Medium Grand Blog Theme grandblog Server-Side Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-24961 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12.2 Fixed in 2.7.12.3 CVE-2026-24958 Patchstack
6.5 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.2.20 Fixed in 3.2.21 CVE-2026-24957 Patchstack
8.8 High WpEvently Plugin mage-eventpress PHP Object Injection Deserialization of untrusted data ≤ 5.0.8 Fixed in 5.0.9 CVE-2026-24954 Patchstack
6.5 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-24952 Patchstack
4.3 Medium myCred Plugin mycred Broken Access Control ≤ 2.9.7.3 Fixed in 2.9.7.4 CVE-2026-24951 Patchstack
4.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control ≤ 1.5.6.3 Fixed in 1.5.6.3 CVE-2026-24947 Patchstack
5.3 Medium Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.5.34 Fixed in 3.5.35 CVE-2026-24945 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-24942 Patchstack
4.3 Medium Travelfic Toolkit Plugin travelfic-toolkit Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-24940 Patchstack
4.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control ≤ 2.13.6 Fixed in 2.13.7 CVE-2026-24939 Patchstack
5.9 Medium Better Search Plugin better-search Cross-Site Scripting ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-24938 Patchstack
8.8 High OS DataHub Maps Plugin os-datahub-maps Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 1.8.3 CVE-2026-1730 Wordfence
8.1 High Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion ≤ 3.9.5 CVE-2026-1375 Wordfence
5.3 Medium Tutor LMS Plugin tutor Information Disclosure Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action No login needed ≤ 3.9.5 CVE-2026-1371 Wordfence
5.4 Medium Mail Mint Plugin mail-mint Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.19.2 CVE-2026-1447 Wordfence
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Hidden Field No login needed ≤ 1.15.35 CVE-2026-1058 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field ≤ 3.20.7 CVE-2026-1210 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG file No login needed ≤ 1.15.35 CVE-2026-1065 Wordfence
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
5.3 Medium Spectra Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Information Disclosure Unauthenticated Information Disclosure in Sensitive Data No login needed ≤ 2.19.17 CVE-2026-0950 Wordfence
5.4 Medium Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget ≤ 2.0.1 CVE-2025-14274 Wordfence
5.3 Medium WP ULike Plugin wp-ulike Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter No login needed ≤ 4.8.3.1 CVE-2026-0909 Wordfence
7.5 High Spirit Framework Plugin spirit-framework Local File Inclusion ≤ 1.2.13 CVE-2024-54263 Patchstack
4.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed < 2.7.9 Fixed in 2.7.9 CVE-2026-0658 WPScan
7.1 High Library Viewer Plugin library-viewer Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 3.2.0 Fixed in 3.2.0 CVE-2025-15396 WPScan
9.8 Critical User Profile Builder Plugin profile-builder Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed 1.1.27 – < 3.15.2 Fixed in 3.15.2 CVE-2025-15030 WPScan
6.4 Medium Stripe Green Downloads Plugin Cross-Site Scripting Stripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings 2.03 CVE-2022-50797 VulnCheck
4.3 Medium Popup Box Plugin ays-popup-box Cross-Site Request Forgery Cross-Site Request Forgery to Popup Status Change No login needed ≤ 6.1.1 CVE-2026-1165 Wordfence
7.2 High Sell BTC - Cryptocurrency Selling Calculator Plugin sell-btc-by-hayyatapps Cross-Site Scripting Cryptocurrency Selling Calculator <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'orderform_data' AJAX Action No login needed ≤ 1.5 CVE-2025-14554 Wordfence
5.4 Medium SupportCandy – Helpdesk & Customer Support Ticket System Plugin supportcandy Broken Access Control Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 3.4.4 CVE-2026-1251 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only