WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 292 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
4.3 Medium Starter Templates Plugin astra-sites Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.5 Fixed in 4.7.6 CVE-2026-62134 Patchstack
4.3 Medium Slim SEO Plugin slim-seo Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.10.0 Fixed in 4.10.1 CVE-2026-62113 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
5.3 Medium Nexi XPay Build Plugin Information Disclosure Unauthenticated Saved Payment Token Disclosure via IDOR No login needed 7.6.1 – 7.6.2 CVE-2026-82213 WPScan
5.5 Medium Visualizer Plugin visualizer Broken Access Control Contributor+ Arbitrary Post/Page Modification via IDOR 4.0.0 – < 4.0.6 Fixed in 4.0.6 CVE-2026-86782 WPScan
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Price Manipulation Unauthenticated Price Manipulation via IDOR No login needed < 3.7 Fixed in 3.7 CVE-2026-85037 WPScan
5.9 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control Subscriber+ Stored Payment Method Assignment via IDOR 1.1.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80341 WPScan
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
5.3 Medium Accept Stripe Payments Plugin stripe-payments Broken Access Control Unauthenticated Product Substitution via IDOR No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-81424 WPScan
5.4 Medium WP Rentals Theme wprentals Broken Access Control Insecure Direct Object References (IDOR) < 3.16.0 Fixed in 3.16.0 CVE-2026-27432 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
5.3 Medium WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-32480 Patchstack
5.3 Medium SureForms Plugin sureforms Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.12.5 Fixed in 2.12.6 CVE-2026-85308 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
6.5 Medium WC Vendors Plugin wc-vendors Broken Access Control Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81428 WPScan
4.3 Medium WC Vendors Plugin wc-vendors Broken Access Control Vendor+ Cross-Vendor Order Shipment Status Change < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81427 WPScan
4.3 Medium WC Vendors Plugin wc-vendors Cross-Site Request Forgery Order Shipment Status Change via CSRF No login needed < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81426 WPScan
5.3 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed 5.0.13 – < 5.0.15 Fixed in 5.0.15 CVE-2026-74927 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Cancellation via IDOR < 8.5.5 Fixed in 8.5.5 CVE-2026-80311 WPScan
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
4.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Pending Email Change Cancellation via IDOR < 5.2.5 Fixed in 5.2.5 CVE-2026-79995 WPScan
5.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Unauthenticated Refund Request Creation on Guest Orders No login needed 3.7.1 – < 3.8.2 Fixed in 3.8.2 CVE-2026-77701 WPScan
4.3 Medium Notifima Plugin woocommerce-product-stock-alert Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-78139 WPScan
4.3 Medium ShopApper Plugin Information Disclosure Subscriber+ Customer Data Disclosure via IDOR ≤ 0.4.62 CVE-2026-16568 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Modification via IDOR < 8.5.1 Fixed in 8.5.1 CVE-2026-77789 WPScan
4.3 Medium WP Project Manager Plugin Information Disclosure Subscriber+ User Activity Feed Disclosure via IDOR 2.2.0 – < 4.0.7 Fixed in 4.0.7 CVE-2026-74930 WPScan
5.4 Medium WP Project Manager Plugin Information Disclosure Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR < 4.0.7 Fixed in 4.0.7 CVE-2026-74929 WPScan
4.7 Medium Amelia Pro Plugin Broken Access Control Provider+ Arbitrary Provider Password Update via IDOR 9.0 – < 9.8 Fixed in 9.8 CVE-2026-14212 WPScan
5.3 Medium Fluent Boards Pro Plugin fluent-boards-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78278 Patchstack
6.5 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Arbitrary Media Attachment Read via IDOR < 4.5.4 Fixed in 4.5.4 CVE-2026-19417 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Cross-Patient Appointment Modification via IDOR No login needed < 4.5.4 Fixed in 4.5.4 CVE-2026-19416 WPScan
5.3 Medium YayCurrency Plugin yaycurrency Information Disclosure Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration No login needed < 3.3.5 Fixed in 3.3.5 CVE-2026-16058 WPScan
4.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14196 WPScan
6.5 Medium Eventin Plugin wp-event-solution Broken Access Control Contributor+ Schedule Deletion and Modification via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13175 WPScan
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.7 CVE-2026-74009 Patchstack
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.19 CVE-2026-66651 Patchstack
4.3 Medium Modal Survey Plugin modal-survey Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2.2.3 CVE-2026-66634 Patchstack
5.7 Medium Manual Image Crop Plugin manual-image-crop Broken Access Control Subscriber+ Arbitrary Attachment Image Overwrite via IDOR < 1.15 Fixed in 1.15 CVE-2026-15384 WPScan
4.9 Medium WC Vendors Plugin wc-vendors SQL Injection Authenticated (Shop Manager+) SQL Injection via 'status' Parameter ≤ 2.7.0 CVE-2026-15351 Wordfence
6.5 Medium StoreEngine Plugin storeengine Path Traversal Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL ≤ 2.1.1 CVE-2026-15056 Wordfence
6.5 Medium Groundhogg Plugin groundhogg SQL Injection Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter ≤ 4.5.14 CVE-2026-18387 Wordfence
6.5 Medium Do Lasso Plugin lasso Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 358 CVE-2026-28155 Patchstack
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Information Disclosure Subscriber+ Order Data Disclosure via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14858 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Update Modification via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14857 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only