WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.109 Fixed in 4.11.110 CVE-2026-103084 Patchstack
5.3 Medium Name Directory Plugin name-directory Arbitrary Shortcode Execution No login needed ≤ 1.34.2 Fixed in 1.34.3 CVE-2026-104397 Patchstack
6.5 Medium Logo Showcase Plugin logo-showcase Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2026-105060 Patchstack
6.5 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting ≤ 5.14.2 Fixed in 5.15 CVE-2026-104673 Patchstack
6.5 Medium eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting ≤ 3.6.2 Fixed in 3.6.3 CVE-2026-105056 Patchstack
5.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Information Disclosure Sensitive Data Exposure ≤ 4.6.10 Fixed in 4.6.11 CVE-2026-103335 Patchstack
5.3 Medium WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.9.0.0 Fixed in 1.9.1.0 CVE-2026-105055 Patchstack
5.3 Medium CURCY Plugin woo-multi-currency Broken Access Control No login needed ≤ 2.2.17 Fixed in 2.2.18 CVE-2026-97071 Patchstack
4.3 Medium WP Admin Audit Plugin wp-admin-audit Broken Access Control ≤ 1.2.17 Fixed in 1.2.18 CVE-2026-105062 Patchstack
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.0.0 Fixed in 5.0.0 CVE-2026-103078 Patchstack
6.5 Medium WP VR Plugin wpvr Broken Access Control ≤ 9.1.3 Fixed in 9.1.4 CVE-2026-104386 Patchstack
6.5 Medium QR Redirector Plugin qr-redirector Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2026-105069 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting ≤ 4.17.0 Fixed in 4.18.0 CVE-2026-104404 Patchstack
5.3 Medium Events Manager Plugin events-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 7.4.5 Fixed in 7.4.6 CVE-2026-105068 Patchstack
4.3 Medium Memberful - Membership Plugin memberful-wp Information Disclosure Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure ≤ 1.81.2 Fixed in 1.82.0 CVE-2026-104401 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting ≤ 2.1.8 Fixed in 2.1.9 CVE-2026-104400 Patchstack
6.5 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting ≤ 3.6.13 Fixed in 3.6.14 CVE-2026-104409 Patchstack
4.3 Medium Mindio Magic MCP Plugin mindio-magic-mcp Information Disclosure Sensitive Data Exposure ≤ 0.5.6 Fixed in 0.7.1 CVE-2026-104402 Patchstack
4.3 Medium LearnPress Plugin learnpress Broken Access Control ≤ 4.4.9.1 CVE-2026-39717 Patchstack
4.7 Medium Aculect AI Companion Plugin aculect-ai-companion Open Redirect Unvalidated Redirects and Forwards No login needed ≤ 0.8.1 CVE-2026-39600 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
6.5 Medium WebSamurai Plugin websamurai Broken Access Control ≤ 1.0.7 CVE-2026-39439 Patchstack
6.5 Medium Airano MCP Bridge Plugin airano-mcp-bridge Broken Access Control ≤ 2.11.0 CVE-2026-32585 Patchstack
5.3 Medium Smart One Click Setup – Complete Demo Import & Export Plugin smart-one-click-setup Information Disclosure Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure No login needed ≤ 1.4.3 CVE-2026-32584 Patchstack
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
6.5 Medium ThemeREX Addons Plugin trx_addons Cross-Site Scripting ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102798 Patchstack
5.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.4.9 Fixed in 4.4.9.1 CVE-2026-104403 Patchstack
4.3 Medium Advanced Ads Plugin advanced-ads Information Disclosure Sensitive Data Exposure ≤ 2.0.26 CVE-2026-94180 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.71 CVE-2026-94405 Patchstack
6.1 Medium Avada | Website Builder For WordPress & WooCommerce Theme Cross-Site Scripting Reflected Cross-Site Scripting via 'lang' Parameter No login needed ≤ 7.16.1 CVE-2026-84925 Wordfence
6.5 Medium Review Schema Plugin review-schema Broken Access Control No login needed 3.1.0 CVE-2026-97280 Patchstack
5.3 Medium hCaptcha for WP Plugin hcaptcha-for-forms-and-more Authentication Bypass Bypass Vulnerability No login needed ≤ 5.3.0 Fixed in 5.4.0 CVE-2026-103347 Patchstack
6.3 Medium WP Project Manager Plugin wedevs-project-manager Broken Access Control ≤ 4.0.7 Fixed in 4.1.0 CVE-2026-97281 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-97269 Patchstack
6.5 Medium Aruba Migration Tool Plugin aruba-wp-migration-tool Broken Access Control ≤ 1.0.4 Fixed in 1.0.5 CVE-2026-97258 Patchstack
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
5.3 Medium CF7 Apps Plugin contact-form-7-honeypot Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 Fixed in 3.8.0 CVE-2026-62058 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
5.4 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-62063 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.8.4 Fixed in 6.8.5 CVE-2026-102394 Patchstack
6.5 Medium Metform Plugin metform Cross-Site Scripting ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-103339 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103063 Patchstack
5.3 Medium Pie Register Plugin pie-register Information Disclosure Sensitive Data Exposure No login needed ≤ 3.8.4.13 Fixed in 3.8.4.14 CVE-2026-103345 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103064 Patchstack
5.3 Medium AFFI – Affiliate Marketing for WooCommerce Plugin affi-affiliate-marketing-for-woo Broken Access Control Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2026-102390 Patchstack
4.3 Medium Majestic Support Plugin majestic-support Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102382 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102381 Patchstack
6.5 Medium FluentForm Plugin fluentform Cross-Site Scripting ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103343 Patchstack
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103341 Patchstack
5.3 Medium Site Reviews Plugin site-reviews Broken Access Control No login needed ≤ 8.3.2 Fixed in 8.3.3 CVE-2026-103340 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only