WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WordPress Core Remote Code Execution WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript i… < 7.0.4 Fixed in 7.0.4 CVE-2026-65640 hackerone
4.3 Medium Password Protect WordPress Lite Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update ≤ 1.9.20 CVE-2025-10005 Wordfence
8.8 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress PHP Object Injection Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter ≤ 4.5.3 CVE-2026-16099 Wordfence
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
7.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Cross-Site Scripting WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) No login needed ≤ 2.5, ≤ 1.7 CVE-2026-28154 Patchstack
8.5 High Booktics Plugin booktics SQL Injection ≤ 1.0.22 Fixed in 1.0.23 CVE-2026-28002 Patchstack
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.6 Fixed in 5.2.7 CVE-2026-73403 Patchstack
5.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.3.7 Fixed in 0.1.3.8 CVE-2026-73401 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting < 4.16.6 Fixed in 4.16.6 CVE-2026-73357 Patchstack
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control No login needed < 4.22.10 Fixed in 4.22.10 CVE-2026-73353 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed < 4.16.6 Fixed in 4.16.6 CVE-2026-73349 Patchstack
7.6 High MailChimp For WooCommerce Plugin mailchimp-for-woocommerce SQL Injection < 6.2 Fixed in 6.2 CVE-2026-73346 Patchstack
5.9 Medium WP Data Access Plugin wp-data-access Cross-Site Scripting ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-73344 Patchstack
6.5 Medium Featured Image from URL Plugin featured-image-from-url Cross-Site Scripting ≤ 5.3.3 Fixed in 6.0.0 CVE-2026-73340 Patchstack
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
7.1 High Smart Online Order for Clover Plugin clover-online-orders Cross-Site Scripting No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2026-66700 Patchstack
7.1 High SureDash Plugin suredash Cross-Site Scripting No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2026-66698 Patchstack
7.1 High Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Cross-Site Scripting No login needed ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66697 Patchstack
6.5 Medium Motors Plugin motors-car-dealership-classified-listings Broken Access Control ≤ 1.4.113 Fixed in 1.4.114 CVE-2026-66693 Patchstack
9.8 Critical Nokri Theme nokri Broken Access Control No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-66691 Patchstack
6.3 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Broken Access Control AcyChecker plugin <= 2.0.0 - Broken Access Control ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66689 Patchstack
6.5 Medium WpBookingly Plugin service-booking-manager Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-66687 Patchstack
7.7 High Directories Pro Plugin directories-pro Privilege Escalation No login needed ≤ 2.0.5 CVE-2026-66661 Patchstack
6.5 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Broken Access Control PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control No login needed ≤ 2.5.1 CVE-2026-66660 Patchstack
8.5 High Reviewer Plugin reviewer SQL Injection ≤ 3.14.2 CVE-2026-66658 Patchstack
8.1 High Biagiotti Core Plugin biagiotti-core Local File Inclusion No login needed ≤ 2.1.1 CVE-2026-66657 Patchstack
8.1 High Foton Core Plugin foton-core Local File Inclusion No login needed ≤ 1.1.1 CVE-2026-66656 Patchstack
7.1 High MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.30.36 CVE-2026-66655 Patchstack
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
8.1 High Barista Theme barista Local File Inclusion No login needed ≤ 2.5.1 CVE-2026-66653 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-66478 Patchstack
9.3 Critical Everest Backup Plugin everest-backup SQL Injection No login needed ≤ 2.3.12 CVE-2026-66472 Patchstack
6.5 Medium Accordion Plugin accordions-wp Cross-Site Scripting ≤ 3.0.6 CVE-2026-66471 Patchstack
7.5 High Arvow AI SEO Writer Plugin journalist-ai Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-66469 Patchstack
7.1 High Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Cross-Site Scripting No login needed ≤ 3.0.0 CVE-2026-66468 Patchstack
6.5 Medium FluentCommunity Plugin fluent-community Cross-Site Scripting ≤ 2.7.5 Fixed in 2.7.7 CVE-2026-66467 Patchstack
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control No login needed ≤ 2.1.1 CVE-2026-66466 Patchstack
9.8 Critical Cartify Theme cartify-multipurpose-woocommerce-wordpress-theme Privilege Escalation Account Takeover No login needed ≤ 1.3.0.1 CVE-2026-66465 Patchstack
6.5 Medium Internal Link Optimiser Plugin internal-link-finder Broken Access Control No login needed ≤ 5.2.7 CVE-2026-66464 Patchstack
7.5 High iCARRY Plugin icarry Information Disclosure Sensitive Data Exposure No login needed ≤ 2.9 CVE-2026-66463 Patchstack
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
6.5 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Cross-Site Scripting ≤ 1.18.1 CVE-2026-66460 Patchstack
6.5 Medium AI for SEO Plugin ai-for-seo Broken Access Control No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-66459 Patchstack
9.3 Critical RealPress Plugin realpress SQL Injection No login needed ≤ 1.1.2 CVE-2026-66458 Patchstack
6.5 Medium Profile Extra Fields by BestWebSoft Plugin profile-extra-fields Cross-Site Scripting ≤ 1.3.4 CVE-2026-66456 Patchstack
6.0 Medium ReactPress Plugin reactpress Broken Access Control ≤ 3.4.0 CVE-2026-66455 Patchstack
6.5 Medium WP Social Avatar Plugin wp-social-avatar Broken Access Control No login needed ≤ 1.5 CVE-2026-66454 Patchstack
9.8 Critical Salon booking system Plugin salon-booking-system Authentication Bypass Broken Authentication No login needed ≤ 10.30.26 Fixed in 10.30.27 CVE-2026-66453 Patchstack
8.1 High Geo Mashup Plugin geo-mashup Local File Inclusion No login needed ≤ 1.13.18 Fixed in 1.13.19 CVE-2026-66450 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only