WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Admin Audit Plugin wp-admin-audit Broken Access Control ≤ 1.2.17 Fixed in 1.2.18 CVE-2026-105062 Patchstack
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103078 Patchstack
7.1 High PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.17.9 Fixed in 11.17.11 CVE-2026-104407 Patchstack
6.5 Medium WP VR Plugin wpvr Broken Access Control ≤ 9.1.3 Fixed in 9.1.4 CVE-2026-104386 Patchstack
6.5 Medium QR Redirector Plugin qr-redirector Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2026-105069 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting ≤ 4.17.0 Fixed in 4.18.0 CVE-2026-104404 Patchstack
5.3 Medium Events Manager Plugin events-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 7.4.5 Fixed in 7.4.6 CVE-2026-105068 Patchstack
4.3 Medium Memberful - Membership Plugin memberful-wp Information Disclosure Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure ≤ 1.81.2 Fixed in 1.82.0 CVE-2026-104401 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting ≤ 2.1.8 Fixed in 2.1.9 CVE-2026-104400 Patchstack
6.5 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting ≤ 3.6.13 Fixed in 3.6.14 CVE-2026-104409 Patchstack
4.3 Medium Mindio Magic MCP Plugin mindio-magic-mcp Information Disclosure Sensitive Data Exposure ≤ 0.5.6 Fixed in 0.7.1 CVE-2026-104402 Patchstack
7.5 High Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 4.0.17 Fixed in 4.0.18 CVE-2026-97307 Patchstack
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2026-103062 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.14 Fixed in 14.16.15 CVE-2026-97276 Patchstack
7.1 High Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting No login needed ≤ 3.7.11.1 Fixed in 3.7.12 CVE-2026-103354 Patchstack
3.5 Low Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Admin+ Stored XSS via PayPal API Credentials < 5.2.6 Fixed in 5.2.6 CVE-2026-104119 WPScan
8.8 High Ultimate Member Plugin ultimate-member Privilege Escalation ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-96451 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
8.2 High Kirki Plugin kirki Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-103065 Patchstack
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
4.3 Medium LearnPress Plugin learnpress Broken Access Control ≤ 4.4.9.1 CVE-2026-39717 Patchstack
3.7 Low Booking Calendar Plugin booking Other Race Condition No login needed ≤ 11.8.4 Fixed in 11.9 CVE-2026-39601 Patchstack
4.7 Medium Aculect AI Companion Plugin aculect-ai-companion Open Redirect Unvalidated Redirects and Forwards No login needed ≤ 0.8.1 CVE-2026-39600 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
6.5 Medium WebSamurai Plugin websamurai Broken Access Control ≤ 1.0.7 CVE-2026-39439 Patchstack
6.5 Medium Airano MCP Bridge Plugin airano-mcp-bridge Broken Access Control ≤ 2.11.0 CVE-2026-32585 Patchstack
5.3 Medium Smart One Click Setup – Complete Demo Import & Export Plugin smart-one-click-setup Information Disclosure Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure No login needed ≤ 1.4.3 CVE-2026-32584 Patchstack
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
6.5 Medium ThemeREX Addons Plugin trx_addons Cross-Site Scripting ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102798 Patchstack
5.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.4.9 Fixed in 4.4.9.1 CVE-2026-104403 Patchstack
4.3 Medium Advanced Ads Plugin advanced-ads Information Disclosure Sensitive Data Exposure ≤ 2.0.26 CVE-2026-94180 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.71 CVE-2026-94405 Patchstack
6.1 Medium Avada | Website Builder For WordPress & WooCommerce Theme Cross-Site Scripting Reflected Cross-Site Scripting via 'lang' Parameter No login needed ≤ 7.16.1 CVE-2026-84925 Wordfence
6.5 Medium Review Schema Plugin review-schema Broken Access Control No login needed 3.1.0 CVE-2026-97280 Patchstack
5.3 Medium hCaptcha for WP Plugin hcaptcha-for-forms-and-more Authentication Bypass Bypass Vulnerability No login needed ≤ 5.3.0 Fixed in 5.4.0 CVE-2026-103347 Patchstack
8.8 High ByteCoreStack – MCP Connector for AI Tools Plugin bcs-mcp-manager Privilege Escalation MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation ≤ 1.2.2 Fixed in 1.2.4 CVE-2026-103068 Patchstack
7.1 High Parallax Section block Plugin parallax-section Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.1.0 CVE-2026-102378 Patchstack
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
8.8 High Icegram Plugin icegram PHP Object Injection ≤ 3.1.31 Fixed in 3.1.44 CVE-2026-97284 Patchstack
6.3 Medium WP Project Manager Plugin wedevs-project-manager Broken Access Control ≤ 4.0.7 Fixed in 4.1.0 CVE-2026-97281 Patchstack
7.6 High Social Boost Plugin social-boost Broken Access Control ≤ 3.6.2 Fixed in 3.7.0 CVE-2026-97277 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-97269 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.1 High MaxGalleria Plugin maxgalleria Cross-Site Scripting No login needed ≤ 6.5.3 Fixed in 6.5.4 CVE-2026-97260 Patchstack
6.5 Medium Aruba Migration Tool Plugin aruba-wp-migration-tool Broken Access Control ≤ 1.0.4 Fixed in 1.0.5 CVE-2026-97258 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only