WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.5 Medium Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Account Modification and Deletion via IDOR < 1.2.4 Fixed in 1.2.4 CVE-2026-92425 WPScan
4.7 Medium Hydra Booking 1.1.0 Plugin Broken Access Control < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 1.1.0 – < 1.2.3 Fixed in 1.2.3 CVE-2026-92421 WPScan
3.8 Low Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-92420 WPScan
7.5 High MgoSync Plugin megamo Information Disclosure Unauthenticated WooCommerce API Credential Disclosure No login needed 2.1.5 – < 2.1.7 Fixed in 2.1.7 CVE-2026-92404 WPScan
3.7 Low Secure Custom Fields Plugin secure-custom-fields Broken Access Control Unauthenticated Post Modification via Front-End Form ID Substitution No login needed < 6.9.4 Fixed in 6.9.4 CVE-2026-92403 WPScan
6.5 Medium WPGraphQL Smart Cache Plugin wpgraphql-smart-cache Broken Access Control Unauthenticated Persisted Query Registration and Alias Squatting No login needed < 2.3.2 Fixed in 2.3.2 CVE-2026-92099 WPScan
4.8 Medium Bookly Plugin Information Disclosure Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR No login needed 28.1 – < 28.2 Fixed in 28.2 CVE-2026-91847 WPScan
8.6 High VikRentItems Flexible Rental Management System Plugin vikrentitems SQL Injection Unauthenticated SQLi No login needed < 1.2.4 Fixed in 1.2.4 CVE-2026-88926 WPScan
8.8 High Master Blocks Plugin ultimate-blocks-for-gutenberg Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed 1.4.1 – < 1.5.0 Fixed in 1.5.0 CVE-2026-88824 WPScan
8.1 High UsersWP - Social Login Plugin Privilege Escalation Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email No login needed < 1.5.10 Fixed in 1.5.10 CVE-2026-86814 WPScan
9.8 Critical Botiga Pro Plugin Privilege Escalation Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route No login needed < 1.6.5 Fixed in 1.6.5 CVE-2026-86591 WPScan
8.8 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Unauthenticated Stored XSS via Profile Page Title No login needed < 2.13.1 Fixed in 2.13.1 CVE-2026-85680 WPScan
8.0 High Unbounce Landing Pages Plugin unbounce Broken Access Control Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains 1.1.1 – < 1.1.5 Fixed in 1.1.5 CVE-2026-85574 WPScan
6.5 Medium Ultimate Addons for Contact Form 7 Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Signature Field No login needed 3.2.4 – < 3.5.51 Fixed in 3.5.51 CVE-2026-84750 WPScan
7.1 High Estatik Plugin Cross-Site Scripting Reflected XSS via get_listings hash Parameter No login needed 4.0.1 – < 4.3.5 Fixed in 4.3.5 CVE-2026-76790 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Privilege Escalation Authenticated Privilege Escalation via User Import < 3.9.35 Fixed in 3.9.35 CVE-2026-76554 WPScan
5.5 Medium JetFormBuilder Plugin Arbitrary File Deletion Admin+ Arbitrary File Deletion via Server-Side Validation Callback 3.5.6.2 – < 3.6.5.3 Fixed in 3.6.5.3 CVE-2026-19860 WPScan
3.5 Low Business Name Generator Plugin Cross-Site Scripting Admin+ Stored XSS via Button Color Setting ≤ 1.3 CVE-2025-15698 WPScan
4.3 Medium Nimble Builder Plugin Information Disclosure Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins ≤ 3.3.8 CVE-2026-16557 WPScan
8.8 High Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute ≤ 4.6.1 CVE-2026-92807 Wordfence
6.1 Medium Pochipp Plugin pochipp Cross-Site Scripting Reflected Cross-Site Scripting via 'keyword' Parameter No login needed ≤ 1.20.2 CVE-2026-92967 Wordfence
4.4 Medium WP2Social Auto Publish Plugin facebook-auto-publish Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter ≤ 2.4.12 CVE-2026-12042 Wordfence
9.1 Critical WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content No login needed ≤ 10.8.1 CVE-2026-89274 Wordfence
5.3 Medium Better Messages Plugin bp-better-messages Information Disclosure Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register No login needed ≤ 2.15.33 CVE-2026-89093 Wordfence
6.1 Medium Tutor LMS Plugin tutor Cross-Site Scripting Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters No login needed ≤ 4.0.8 CVE-2026-89081 Wordfence
9.1 Critical Forminator Forms Plugin forminator Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter No login needed ≤ 1.57.2 CVE-2026-92229 Wordfence
6.5 Medium Better Messages Plugin bp-better-messages Broken Access Control Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint ≤ 2.15.33 CVE-2026-89334 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter ≤ 4.0.8 CVE-2026-88944 Wordfence
7.5 High WP Photo Album Plus Plugin wp-photo-album-plus Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection ≤ 9.2.09.002 CVE-2026-87909 Wordfence
9.8 Critical Gravity Forms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Hidden File Upload Field No login needed ≤ 3.1.0.4 CVE-2026-84434 Wordfence
6.5 Medium Divi Essentials Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action ≤ 5.8.1 CVE-2026-15760 Wordfence
4.3 Medium SEO Booster Plugin seo-booster Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() ≤ 7.4.7 CVE-2026-15660 Wordfence
7.2 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 1.4.0.5 CVE-2026-13354 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter ≤ 4.0.8 CVE-2026-89333 Wordfence
6.4 Medium WPComplete Plugin wpcomplete Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute ≤ 2.9.9.0 CVE-2026-77820 Wordfence
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
7.2 High Popup Maker Plugin popup-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter No login needed ≤ 1.24.0 CVE-2026-87915 Wordfence
6.4 Medium Popup Maker Plugin popup-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via post_title ≤ 1.24.0 CVE-2026-15797 Wordfence
5.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint ≤ 10.8.1 CVE-2026-90884 Wordfence
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.16 CVE-2026-18405 Wordfence
8.1 High Master Addons for Elementor Plugin master-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter ≤ 3.2.2 CVE-2026-85410 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
4.4 Medium CSS & JavaScript Toolbox Plugin css-javascript-toolbox Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields ≤ 12.0.6 CVE-2025-13533 Wordfence
6.1 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 1.11 CVE-2026-92249 Wordfence
7.5 High Location Manager Plugin SQL Injection Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters No login needed ≤ 2.3.38 CVE-2026-85705 Wordfence
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute ≤ 1.8.44 CVE-2026-85652 Wordfence
7.5 High WP Multi Store Locator Pro Plugin SQL Injection Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter No login needed ≤ 4.5.1 CVE-2026-15275 Wordfence
4.3 Medium WP Easy Pay Plugin wp-easy-pay Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 4.5.0 CVE-2026-12739 Wordfence
4.9 Medium Store Exporter Plugin woocommerce-exporter Path Traversal Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter ≤ 2.8.0 CVE-2026-16777 Wordfence
5.4 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Cross-Site Scripting WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 6.5.6 CVE-2026-15004 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only