WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.7 Medium Hydra Booking 1.1.0 Plugin Broken Access Control < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 1.1.0 – < 1.2.3 Fixed in 1.2.3 CVE-2026-92421 WPScan
3.8 Low Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-92420 WPScan
4.8 Medium Bookly Plugin Information Disclosure Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR No login needed 28.1 – < 28.2 Fixed in 28.2 CVE-2026-91847 WPScan
7.5 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter No login needed ≤ 3.8.2 CVE-2026-18442 Wordfence
2.7 Low MasterStudy LMS 3.6.2 Plugin Information Disclosure < 3.7.50 - Instructor+ Student PII Disclosure via IDOR 3.6.2 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88844 WPScan
5.3 Medium Easy Appointments Plugin easy-appointments Broken Access Control Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR No login needed 4.0 – < 4.0.2.2 Fixed in 4.0.2.2 CVE-2026-87966 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Order Status Manipulation via IDOR < 3.7.50 Fixed in 3.7.50 CVE-2026-81340 WPScan
5.4 Medium Cooked Plugin cooked Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.16.0 Fixed in 1.16.1 CVE-2026-73999 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.7.2.1 Fixed in 2.7.2.2 CVE-2026-66625 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
5.3 Medium KBoard Plugin Broken Access Control Unauthenticated Board Media Deletion via IDOR No login needed < 6.7 Fixed in 6.7 CVE-2026-88910 WPScan
4.3 Medium FluentBoards Plugin fluent-boards Information Disclosure Subscriber+ Private Board Membership Disclosure via IDOR < 2.0.15 Fixed in 2.0.15 CVE-2026-85349 WPScan
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Non-Public Comment Content Disclosure via IDOR No login needed 1.46 – < 1.66 Fixed in 1.66 CVE-2026-82125 WPScan
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
2.7 Low Masteriyo LMS Plugin learning-management-system Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR 1.14.0 – < 3.4.1 Fixed in 3.4.1 CVE-2026-82851 WPScan
4.3 Medium Starter Templates Plugin astra-sites Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.5 Fixed in 4.7.6 CVE-2026-62134 Patchstack
4.3 Medium Slim SEO Plugin slim-seo Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.10.0 Fixed in 4.10.1 CVE-2026-62113 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
5.3 Medium Nexi XPay Build Plugin Information Disclosure Unauthenticated Saved Payment Token Disclosure via IDOR No login needed 7.6.1 – 7.6.2 CVE-2026-82213 WPScan
5.5 Medium Visualizer Plugin visualizer Broken Access Control Contributor+ Arbitrary Post/Page Modification via IDOR 4.0.0 – < 4.0.6 Fixed in 4.0.6 CVE-2026-86782 WPScan
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Privilege Escalation Store Owner+ Privilege Escalation to Administrator 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74925 WPScan
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Price Manipulation Unauthenticated Price Manipulation via IDOR No login needed < 3.7 Fixed in 3.7 CVE-2026-85037 WPScan
5.9 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control Subscriber+ Stored Payment Method Assignment via IDOR 1.1.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80341 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13146 WPScan
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
2.2 Low Kirki Plugin kirki Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84225 WPScan
5.3 Medium Accept Stripe Payments Plugin stripe-payments Broken Access Control Unauthenticated Product Substitution via IDOR No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-81424 WPScan
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
5.4 Medium WP Rentals Theme wprentals Broken Access Control Insecure Direct Object References (IDOR) < 3.16.0 Fixed in 3.16.0 CVE-2026-27432 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
5.3 Medium WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-32480 Patchstack
7.1 High Classified Listing Plugin classified-listing Broken Access Control Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR 5.3.0 – < 6.1.1 Fixed in 6.1.1 CVE-2026-16281 WPScan
5.3 Medium SureForms Plugin sureforms Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.12.5 Fixed in 2.12.6 CVE-2026-85308 Patchstack
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
7.1 High WCFM Membership Plugin wc-multivendor-membership Privilege Escalation ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-84756 Patchstack
3.8 Low Timetics Plugin timetics Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR ≤ 1.0.61 CVE-2026-14326 WPScan
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
9.3 Critical WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2026-81286 Patchstack
6.5 Medium WC Vendors Plugin wc-vendors Broken Access Control Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81428 WPScan
4.3 Medium WC Vendors Plugin wc-vendors Broken Access Control Vendor+ Cross-Vendor Order Shipment Status Change < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81427 WPScan
4.3 Medium WC Vendors Plugin wc-vendors Cross-Site Request Forgery Order Shipment Status Change via CSRF No login needed < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81426 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81198 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Quiz Answer Disclosure via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81196 WPScan
5.3 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed 5.0.13 – < 5.0.15 Fixed in 5.0.15 CVE-2026-74927 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only