WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium SEOPress Plugin wp-seopress Server-Side Request Forgery ≤ 10.1 Fixed in 10.2 CVE-2026-85305 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.11 Fixed in 14.16.12 CVE-2026-84774 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
5.3 Medium BookIt Plugin bookit Other Bypass Vulnerability No login needed ≤ 2.6.0.3 Fixed in 2.6.0.4 CVE-2026-84767 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Other Bypass Vulnerability No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2026-84762 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84758 Patchstack
6.5 Medium Mail Mint Plugin mail-mint Broken Access Control No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84755 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control No login needed ≤ 3.12.13 Fixed in 3.13.0 CVE-2026-84754 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2026-84215 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Graphene Theme graphene Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.6 CVE-2026-81281 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.8 Medium Enfold Theme enfold Cross-Site Scripting No login needed ≤ 8.0 Fixed in 8.1 CVE-2026-84815 Patchstack
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter ≤ 4.27.6 CVE-2026-3852 Wordfence
6.4 Medium GutenKit Plugin gutenkit-blocks-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss' ≤ 2.4.4 CVE-2026-2573 Wordfence
6.4 Medium SEOWriting Plugin seowriting Cross-Site Scripting SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload ≤ 1.12.5 CVE-2026-75134 VulnCheck
5.4 Medium Ajaxify Comments Plugin wp-ajaxify-comments Other Unauthenticated HTTP Header Injection No login needed < 3.2 Fixed in 3.2 CVE-2026-2811 WPScan
5.3 Medium Passster Plugin content-protector Broken Access Control Global Protection Bypass No login needed < 4.2.26 Fixed in 4.2.26 CVE-2025-15490 WPScan
5.3 Medium Wp Edit Password Protected Plugin Broken Access Control Protection Bypass via REST API No login needed < 1.3.5 Fixed in 1.3.5 CVE-2025-8945 WPScan
5.3 Medium Passster Plugin content-protector Broken Access Control Password Protection Bypass No login needed < 4.2.24 Fixed in 4.2.24 CVE-2025-15489 WPScan
5.3 Medium Notification Bar Plugin Information Disclosure Unauthenticated Subscriber Data Disclosure No login needed ≤ 1.1.8 CVE-2025-15481 WPScan
5.9 Medium LiveJournal Shortcode Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1.1 CVE-2024-3773 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Multiple Widgets 1.6.0 – < 1.7.4 Fixed in 1.7.4 CVE-2026-83547 WPScan
5.3 Medium WP Express Checkout Plugin Price Manipulation Unauthenticated Payment Bypass via wpec_process_payment No login needed < 2.4.9 Fixed in 2.4.9 CVE-2026-83533 WPScan
6.8 Medium All in One SEO Plugin all-in-one-seo-pack Cross-Site Scripting Contributor+ Stored XSS via ai-assistant Block < 5.0.0.1 Fixed in 5.0.0.1 CVE-2026-82884 WPScan
4.8 Medium Brave Popup Builder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via UTM Parameter No login needed < 0.8.8 Fixed in 0.8.8 CVE-2026-81571 WPScan
5.4 Medium Simple Membership MailChimp Integration Plugin simple-membership-mailchimp-integration Cross-Site Request Forgery API Key Update via CSRF No login needed < 1.9.8 Fixed in 1.9.8 CVE-2026-8151 WPScan
5.3 Medium Restrict User Access Plugin restrict-user-access Broken Access Control Unauthenticated Content Protection Bypass via REST API Route Normalization No login needed 2.6 – < 2.8.1 Fixed in 2.8.1 CVE-2026-78153 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Zero Quantity No login needed 6.0.0.0 – < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77794 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Omitted Price Field No login needed < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77793 WPScan
6.5 Medium CM HIPAA Forms Plugin Broken Access Control Unauthenticated Authorization Bypass No login needed < 3.2.0 Fixed in 3.2.0 CVE-2026-2688 WPScan
5.3 Medium WP User Frontend Plugin Broken Access Control Unauthenticated Post Creation via Subscription-Gated Form No login needed < 4.3.11 Fixed in 4.3.11 CVE-2026-17563 WPScan
6.6 Medium Yoast SEO Premium Plugin Remote Code Execution Author+ Arbitrary .htaccess Directive Injection to RCE < 27.6.1 Fixed in 27.6.1 CVE-2026-10821 WPScan
5.4 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 6.1.3 Fixed in 6.1.5 CVE-2026-84217 Patchstack
5.3 Medium Rentsyst Plugin rentsyst Broken Access Control No login needed ≤ 2.1.5 CVE-2026-84835 Patchstack
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.3 Medium WP Go Maps Plugin wp-google-maps Denial of Service Denial of Service Attack No login needed ≤ 10.1.08 Fixed in 10.1.09 CVE-2026-84780 Patchstack
5.3 Medium Really Simple SSL Plugin really-simple-ssl Denial of Service Denial of Service Attack No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84775 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.22 Fixed in 4.1.23 CVE-2026-82223 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
6.4 Medium Easy Waveform Player Plugin easy-waveform-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function ≤ 1.2.2 CVE-2025-7963 Wordfence
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter ≤ 4.27.5 CVE-2026-3850 Wordfence
4.1 Medium WPvivid Backup & Migration Plugin SQL Injection Admin+ SQLi via Upload Cleaner Isolation < 0.9.133 Fixed in 0.9.133 CVE-2026-82182 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only