WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 901–950 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WP-Stats Plugin wp-stats Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.56 CVE-2026-19794 Wordfence
8.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment No login needed 5.8.6 – < 6.7.2 Fixed in 6.7.2 CVE-2026-18039 WPScan
8.6 High Paymob for WooCommerce Plugin paymob-for-woocommerce SQL Injection Unauthenticated SQL Injection via Paymob Callback Pixel Lookup No login needed < 4.1.9 Fixed in 4.1.9 CVE-2026-15205 WPScan
7.2 High W3 Total Cache Plugin w3-total-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 2.10.3 CVE-2026-18109 Wordfence
7.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Cross-Site Scripting WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) No login needed ≤ 2.5, ≤ 1.7 CVE-2026-28154 Patchstack
8.5 High Booktics Plugin booktics SQL Injection ≤ 1.0.22 Fixed in 1.0.23 CVE-2026-28002 Patchstack
7.6 High MailChimp For WooCommerce Plugin mailchimp-for-woocommerce SQL Injection < 6.2 Fixed in 6.2 CVE-2026-73346 Patchstack
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
7.1 High Smart Online Order for Clover Plugin clover-online-orders Cross-Site Scripting No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2026-66700 Patchstack
7.1 High SureDash Plugin suredash Cross-Site Scripting No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2026-66698 Patchstack
7.1 High Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Cross-Site Scripting No login needed ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66697 Patchstack
7.7 High Directories Pro Plugin directories-pro Privilege Escalation No login needed ≤ 2.0.5 CVE-2026-66661 Patchstack
8.5 High Reviewer Plugin reviewer SQL Injection ≤ 3.14.2 CVE-2026-66658 Patchstack
8.1 High Biagiotti Core Plugin biagiotti-core Local File Inclusion No login needed ≤ 2.1.1 CVE-2026-66657 Patchstack
8.1 High Foton Core Plugin foton-core Local File Inclusion No login needed ≤ 1.1.1 CVE-2026-66656 Patchstack
7.1 High MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.30.36 CVE-2026-66655 Patchstack
8.1 High Barista Theme barista Local File Inclusion No login needed ≤ 2.5.1 CVE-2026-66653 Patchstack
7.5 High Arvow AI SEO Writer Plugin journalist-ai Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-66469 Patchstack
7.1 High Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Cross-Site Scripting No login needed ≤ 3.0.0 CVE-2026-66468 Patchstack
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control No login needed ≤ 2.1.1 CVE-2026-66466 Patchstack
7.5 High iCARRY Plugin icarry Information Disclosure Sensitive Data Exposure No login needed ≤ 2.9 CVE-2026-66463 Patchstack
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
8.1 High Geo Mashup Plugin geo-mashup Local File Inclusion No login needed ≤ 1.13.18 Fixed in 1.13.19 CVE-2026-66450 Patchstack
7.1 High Geo Mashup Plugin geo-mashup Cross-Site Scripting No login needed ≤ 1.13.18 Fixed in 1.13.19 CVE-2026-66449 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-66443 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66441 Patchstack
7.5 High WPJAM Basic Plugin wpjam-basic Information Disclosure Sensitive Data Exposure No login needed ≤ 7.0.2.1 Fixed in 7.0.3 CVE-2026-66432 Patchstack
7.5 High Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin clink-gateway-for-woocommerce Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-66431 Patchstack
8.5 High Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro SQL Injection ≤ 11.10 Fixed in 11.11 CVE-2026-66430 Patchstack
7.1 High Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro Cross-Site Scripting No login needed ≤ 11.10 Fixed in 11.11 CVE-2026-66429 Patchstack
7.1 High WP-Stats Plugin wp-stats Cross-Site Scripting No login needed ≤ 2.56 Fixed in 2.56.1 CVE-2026-66426 Patchstack
7.7 High AI Hub Theme aihub Path Traversal Arbitrary File Download ≤ 1.3.10 CVE-2026-65582 Patchstack
7.1 High Agrion Theme agrion Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2026-65580 Patchstack
7.5 High WPMobile.App Plugin wpappninja Broken Access Control No login needed ≤ 11.77 Fixed in 11.78 CVE-2026-61984 Patchstack
7.5 High OMGF Pro Plugin host-google-fonts-pro Path Traversal Arbitrary File Download No login needed ≤ 5.2.7 Fixed in 5.2.8 CVE-2026-61980 Patchstack
8.1 High SAML SP Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation No login needed ≤ 5.4.3 Fixed in 5.4.4 CVE-2026-61979 Patchstack
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2026-61974 Patchstack
7.1 High GeekyBot Plugin geeky-bot Cross-Site Scripting No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-61965 Patchstack
7.1 High WP Full Stripe Free Plugin wp-full-stripe-free Cross-Site Scripting No login needed ≤ 8.5.0 Fixed in 8.5.1 CVE-2026-61960 Patchstack
7.4 High Participants Database Plugin participants-database Arbitrary File Deletion No login needed ≤ 2.7.8.4 Fixed in 2.7.8.5 CVE-2026-28189 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-28188 Patchstack
7.1 High Knowledge Base for Documentation, FAQs with AI Assistance Plugin echo-knowledge-base Cross-Site Scripting No login needed ≤ 17.211.0 Fixed in 17.212.0 CVE-2026-28187 Patchstack
8.1 High Travelfic Toolkit Plugin travelfic-toolkit Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-28186 Patchstack
8.8 High Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.4 Fixed in 1.18.5 CVE-2026-28176 Patchstack
7.1 High Visitors Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting No login needed ≤ 8.11 Fixed in 8.12 CVE-2026-28175 Patchstack
7.1 High WP Event SOlution Plugin wp-event-solution Broken Access Control Arbitrary Content Deletion ≤ 4.1.19 Fixed in 4.1.20 CVE-2026-28173 Patchstack
7.1 High Blog Floating Button Plugin blog-floating-button Cross-Site Scripting No login needed ≤ 1.4.20 Fixed in 1.4.21 CVE-2026-28170 Patchstack
8.5 High CubeWP Plugin cubewp-framework SQL Injection ≤ 1.1.30 Fixed in 1.1.31 CVE-2026-28168 Patchstack
8.8 High Service Finder Booking Plugin sf-booking Privilege Escalation ≤ 6.2 CVE-2026-28161 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only