WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 51–100 of 308 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | Profile Builder | Privilege Escalation Unauthenticated Account Takeover via Auto-Login After Registration No login needed |
< 3.16.4 Fixed in 3.16.4 |
CVE-2026-15368 |
WPScan | |
| 7.2 High | ElementsKit Lite | Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) |
< 3.10.01 Fixed in 3.10.01 |
CVE-2026-13392 |
WPScan | |
| 7.1 High | Easy Form Builder | Cross-Site Scripting No login needed |
≤ 4.0.12 Fixed in 4.0.13 |
CVE-2026-59517 |
Patchstack | |
| 7.1 High | Funnel Kit Funnel Builder PRO | Cross-Site Scripting No login needed |
≤ 3.15.0.7 Fixed in 3.15.0.8 |
CVE-2026-57374 |
Patchstack | |
| 7.2 High | FormCraft | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters No login needed |
≤ 3.9.14 |
CVE-2026-7232 |
Wordfence | |
| 7.1 High | FunnelKit | Cross-Site Scripting Reflected XSS via Divi Optin Form No login needed |
< 3.15.0.6 Fixed in 3.15.0.6 |
CVE-2026-12978 |
WPScan | |
| 7.1 High | Funnel Builder by FunnelKit | Cross-Site Scripting No login needed |
≤ 3.15.0.8 Fixed in 3.15.0.9 |
CVE-2026-57816 |
Patchstack | |
| 7.1 High | tagDiv Opt-In Builder | Cross-Site Scripting No login needed |
≤ 1.7.4 |
CVE-2026-57732 |
Patchstack | |
| 7.1 High | NEX-Forms | Cross-Site Scripting No login needed |
≤ 9.2.2 Fixed in 9.2.3 |
CVE-2026-57668 |
Patchstack | |
| 7.1 High | Bopo – WooCommerce Product Bundle Builder | Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.0 Fixed in 1.2.1 |
CVE-2026-57422 |
Patchstack | |
| 7.1 High | Themify Builder | Cross-Site Scripting No login needed |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2026-57369 |
Patchstack | |
| 8.8 High | WP Grid Builder | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter |
≤ 2.3.3 |
CVE-2026-13756 |
Wordfence | |
| 7.5 High | SureForms – Drag and Drop Form Builder | Price Manipulation Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation No login needed |
≤ 2.2.1 |
CVE-2026-15288 |
Wordfence | |
| 7.2 High | WP Cost Estimation & Payment Forms Builder (E&P Forms) | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter No login needed |
≤ 10.5.97 |
CVE-2026-9253 |
Wordfence | |
| 7.2 High | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Broken Access Control Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation |
≤ 1.22.0 |
CVE-2026-8848 |
Wordfence | |
| 8.8 High | Divi Form Builder | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form |
≤ 5.1.8 |
CVE-2026-5523 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter No login needed |
≤ 9.2.2 |
CVE-2026-13040 |
Wordfence | |
| 7.1 High | Internal Links Manager | Cross-Site Scripting No login needed |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2026-57345 |
Patchstack | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed |
≤ 9.2.2 |
CVE-2026-12142 |
Wordfence | |
| 8.8 High | RegistrationMagic | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter |
≤ 6.0.9.1 |
CVE-2026-12158 |
Wordfence | |
| 7.1 High | Landing Page Builder | Cross-Site Scripting No login needed |
≤ 1.5.3.5 Fixed in 1.5.3.6 |
CVE-2026-57337 |
Patchstack | |
| 8.8 High | Fusion Builder | Privilege Escalation |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-56008 |
Patchstack | |
| 7.6 High | Funnel Builder by FunnelKit | SQL Injection |
≤ 3.15.0.5 Fixed in 3.15.0.6 |
CVE-2026-56052 |
Patchstack | |
| 7.7 High | Fusion Builder | Arbitrary File Deletion |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-54193 |
Patchstack | |
| 7.1 High | JetFormBuilder | Cross-Site Scripting No login needed |
≤ 3.6.0.1 Fixed in 3.6.1 |
CVE-2026-54195 |
Patchstack | |
| 7.1 High | Profile Builder Pro | Cross-Site Scripting No login needed |
≤ 3.15.0 Fixed in 3.15.1 |
CVE-2026-42385 |
Patchstack | |
| 7.1 High | Taskbuilder | Cross-Site Scripting Reflected XSS via Shortcode No login needed |
< 5.0.8 Fixed in 5.0.8 |
CVE-2026-9570 |
WPScan | |
| 8.8 High | Fusion Builder | PHP Object Injection |
≤ 3.15.3 Fixed in 3.15.4 |
CVE-2026-12256 |
Patchstack | |
| 8.5 High | Taskbuilder | SQL Injection |
≤ 5.0.7 Fixed in 5.0.8 |
CVE-2026-52697 |
Patchstack | |
| 7.1 High | Funnel Builder by FunnelKit | Cross-Site Scripting No login needed |
≤ 3.15.0.2 Fixed in 3.15.0.3 |
CVE-2026-48966 |
Patchstack | |
| 8.6 High | Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field | Arbitrary File Upload Save Entries, File Upload & Country Code Field plugin <= 1.0.6 - Arbitrary File Deletion No login needed |
≤ 1.0.6 Fixed in 1.0.7 |
CVE-2026-40769 |
Patchstack | |
| 7.2 High | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed |
≤ 6.1.3 |
CVE-2026-10586 |
Wordfence | |
| 8.8 High | Content Visibility for Divi Builder | Remote Code Execution Authenticated (Contributor+) Remote Code Execution |
≤ 4.02 |
CVE-2026-1829 |
Wordfence | |
| 7.5 High | Funnel Builder for WooCommerce Checkout | Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed |
< 3.15.0.3 Fixed in 3.15.0.3 |
CVE-2026-47100 |
VulnCheck | |
| 7.5 High | Avada Builder | SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed |
≤ 3.15.1 |
CVE-2026-4798 |
Wordfence | |
| 7.1 High | Bricks Builder | Cross-Site Scripting No login needed |
1.9.2 – 2.2 Fixed in 2.3 |
CVE-2026-41554 |
Patchstack | |
| 7.5 High | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed |
≤ 1.15.42 |
CVE-2026-3359 |
Wordfence | |
| 7.5 High | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed |
≤ 1.52.1 |
CVE-2026-5192 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names No login needed |
≤ 9.1.11 |
CVE-2026-5063 |
Wordfence | |
| 7.2 High | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value No login needed |
≤ 2.8.11 |
CVE-2026-5324 |
Wordfence | |
| 8.1 High | Profile Builder Pro | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 3.14.5 |
CVE-2026-7647 |
Wordfence | |
| 8.5 High | Beaver Builder | SQL Injection |
≤ 2.10.1.2 Fixed in 2.10.1.5 |
CVE-2026-40744 |
Patchstack | |
| 8.8 High | Vertex Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' |
≤ 1.6.4 |
CVE-2026-4326 |
Wordfence | |
| 7.1 High | Fusion Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ < 3.15.0 Fixed in 3.15.0 |
CVE-2026-32542 |
Patchstack | |
| 7.1 High | Contact Form & Lead Form Elementor Builder | Cross-Site Scripting No login needed |
≤ <= 2.0.1 Fixed in 2.0.2 |
CVE-2026-32532 |
Patchstack | |
| 7.5 High | RegistrationMagic | Broken Access Control No login needed |
≤ <= 6.0.7.6 Fixed in 6.0.7.7 |
CVE-2026-32498 |
Patchstack | |
| 7.1 High | FAQ Builder AYS | Cross-Site Scripting No login needed |
≤ 1.8.2 Fixed in 1.8.3 |
CVE-2026-25346 |
Patchstack | |
| 8.1 High | RegistrationMagic | Privilege Escalation Account Takeover No login needed |
≤ 6.0.7.1 Fixed in 6.0.7.2 |
CVE-2026-24373 |
Patchstack | |
| 7.5 High | WP Cost Estimation & Payment Forms Builder | Broken Access Control No login needed |
≤ 10.3.0 Fixed in 10.3.0 |
CVE-2026-24363 |
Patchstack | |
| 7.5 High | JetFormBuilder | Path Traversal Unauthenticated Arbitrary File Read via Media Field No login needed |
≤ 3.5.6.2 |
CVE-2026-4373 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.