WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 51–100 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 7
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Profile Builder Plugin Privilege Escalation Unauthenticated Account Takeover via Auto-Login After Registration No login needed < 3.16.4 Fixed in 3.16.4 CVE-2026-15368 WPScan
7.2 High ElementsKit Lite Plugin Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13392 WPScan
7.1 High Easy Form Builder Plugin easy-form-builder Cross-Site Scripting No login needed ≤ 4.0.12 Fixed in 4.0.13 CVE-2026-59517 Patchstack
7.1 High Funnel Kit Funnel Builder PRO Plugin funnel-builder-pro Cross-Site Scripting No login needed ≤ 3.15.0.7 Fixed in 3.15.0.8 CVE-2026-57374 Patchstack
7.2 High FormCraft Plugin formcraft-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters No login needed ≤ 3.9.14 CVE-2026-7232 Wordfence
7.1 High FunnelKit Plugin funnel-builder Cross-Site Scripting Reflected XSS via Divi Optin Form No login needed < 3.15.0.6 Fixed in 3.15.0.6 CVE-2026-12978 WPScan
7.1 High Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting No login needed ≤ 3.15.0.8 Fixed in 3.15.0.9 CVE-2026-57816 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2026-57732 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.2.2 Fixed in 9.2.3 CVE-2026-57668 Patchstack
7.1 High Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-57422 Patchstack
7.1 High Themify Builder Plugin themify-builder Cross-Site Scripting No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2026-57369 Patchstack
8.8 High WP Grid Builder Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter ≤ 2.3.3 CVE-2026-13756 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms Price Manipulation Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation No login needed ≤ 2.2.1 CVE-2026-15288 Wordfence
7.2 High WP Cost Estimation & Payment Forms Builder (E&P Forms) Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter No login needed ≤ 10.5.97 CVE-2026-9253 Wordfence
7.2 High Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder Plugin popup-maker Broken Access Control Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation ≤ 1.22.0 CVE-2026-8848 Wordfence
8.8 High Divi Form Builder Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form ≤ 5.1.8 CVE-2026-5523 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter No login needed ≤ 9.2.2 CVE-2026-13040 Wordfence
7.1 High Internal Links Manager Plugin seo-automated-link-building Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2026-57345 Patchstack
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed ≤ 9.2.2 CVE-2026-12142 Wordfence
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter ≤ 6.0.9.1 CVE-2026-12158 Wordfence
7.1 High Landing Page Builder Plugin page-builder-add Cross-Site Scripting No login needed ≤ 1.5.3.5 Fixed in 1.5.3.6 CVE-2026-57337 Patchstack
8.8 High Fusion Builder Plugin fusion-builder Privilege Escalation ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-56008 Patchstack
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.15.0.5 Fixed in 3.15.0.6 CVE-2026-56052 Patchstack
7.7 High Fusion Builder Plugin fusion-builder Arbitrary File Deletion ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-54193 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.0.1 Fixed in 3.6.1 CVE-2026-54195 Patchstack
7.1 High Profile Builder Pro Plugin profile-builder-pro Cross-Site Scripting No login needed ≤ 3.15.0 Fixed in 3.15.1 CVE-2026-42385 Patchstack
7.1 High Taskbuilder Plugin taskbuilder Cross-Site Scripting Reflected XSS via Shortcode No login needed < 5.0.8 Fixed in 5.0.8 CVE-2026-9570 WPScan
8.8 High Fusion Builder Plugin fusion-builder PHP Object Injection ≤ 3.15.3 Fixed in 3.15.4 CVE-2026-12256 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 5.0.7 Fixed in 5.0.8 CVE-2026-52697 Patchstack
7.1 High Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting No login needed ≤ 3.15.0.2 Fixed in 3.15.0.3 CVE-2026-48966 Patchstack
8.6 High Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field Plugin contact-form-extender-for-divi-builder Arbitrary File Upload Save Entries, File Upload & Country Code Field plugin <= 1.0.6 - Arbitrary File Deletion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-40769 Patchstack
7.2 High Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed ≤ 6.1.3 CVE-2026-10586 Wordfence
8.8 High Content Visibility for Divi Builder Plugin content-visibility-for-divi-builder Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 4.02 CVE-2026-1829 Wordfence
7.5 High Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed < 3.15.0.3 Fixed in 3.15.0.3 CVE-2026-47100 VulnCheck
7.5 High Avada Builder Plugin SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed ≤ 3.15.1 CVE-2026-4798 Wordfence
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
7.5 High Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed ≤ 1.15.42 CVE-2026-3359 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed ≤ 1.52.1 CVE-2026-5192 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names No login needed ≤ 9.1.11 CVE-2026-5063 Wordfence
7.2 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value No login needed ≤ 2.8.11 CVE-2026-5324 Wordfence
8.1 High Profile Builder Pro Plugin profile-builder-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.5 CVE-2026-7647 Wordfence
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
8.8 High Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' ≤ 1.6.4 CVE-2026-4326 Wordfence
7.1 High Fusion Builder Plugin fusion-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ < 3.15.0 Fixed in 3.15.0 CVE-2026-32542 Patchstack
7.1 High Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Cross-Site Scripting No login needed ≤ <= 2.0.1 Fixed in 2.0.2 CVE-2026-32532 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ <= 6.0.7.6 Fixed in 6.0.7.7 CVE-2026-32498 Patchstack
7.1 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-25346 Patchstack
8.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Account Takeover No login needed ≤ 6.0.7.1 Fixed in 6.0.7.2 CVE-2026-24373 Patchstack
7.5 High WP Cost Estimation & Payment Forms Builder Plugin wp_estimation_form Broken Access Control No login needed ≤ 10.3.0 Fixed in 10.3.0 CVE-2026-24363 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Path Traversal Unauthenticated Arbitrary File Read via Media Field No login needed ≤ 3.5.6.2 CVE-2026-4373 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only