WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 355 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Event Tickets Plugin Broken Access Control Unauthenticated PayPal Order Status Manipulation No login needed < 5.29.0.1 Fixed in 5.29.0.1 CVE-2026-14822 WPScan
6.5 Medium Pixel Tag Manager for WooCommerce Plugin pixel-manager-for-woocommerce Broken Access Control Unauthenticated Forged Conversion Event Submission No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14315 WPScan
5.3 Medium Pixelavo Plugin pixelavo Server-Side Request Forgery Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX No login needed < 1.5.4 Fixed in 1.5.4 CVE-2026-13604 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Broken Access Control Unauthenticated Person Data Modification via IDOR No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14843 WPScan
4.3 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Broken Access Control Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action ≤ 5.3.7 CVE-2026-17166 Wordfence
5.3 Medium Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.29.0.1 Fixed in 5.29.1 CVE-2026-65567 Patchstack
6.5 Medium Events Made Easy Plugin events-made-easy Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-59557 Patchstack
6.8 Medium Calendar Plugin Cross-Site Scripting Contributor+ Stored XSS via event_link Parameter < 1.3.18 Fixed in 1.3.18 CVE-2026-14827 WPScan
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Unauthenticated Event Aggregator Import Status Manipulation No login needed < 6.16.5.1 Fixed in 6.16.5.1 CVE-2026-13390 WPScan
5.3 Medium Event post Plugin event-post Broken Access Control No login needed ≤ 6.0.1 CVE-2026-65486 Patchstack
6.5 Medium Tickera Plugin tickera-event-ticketing-system SQL Injection Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter ≤ 3.6.0.1 CVE-2026-15448 Wordfence
6.5 Medium Registrations for the Events Calendar Plugin registrations-for-the-events-calendar SQL Injection Authenticated (Contributor+) SQL Injection via 'standard' Parameter ≤ 3.2 CVE-2026-13119 Wordfence
6.5 Medium Tickera Plugin tickera-event-ticketing-system SQL Injection Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter ≤ 3.6.0.1 CVE-2026-15761 Wordfence
4.9 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import ≤ 2.4.3 CVE-2026-14782 Wordfence
6.4 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute ≤ 3.6.0.0 CVE-2026-13755 Wordfence
6.5 Medium Tickera Plugin tickera-event-ticketing-system SQL Injection Authenticated (Staff+) SQL Injection via 's' Parameter ≤ 3.6.0.0 CVE-2026-13754 Wordfence
6.5 Medium Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-57400 Patchstack
5.3 Medium Eventin Plugin wp-event-solution Broken Access Control Missing Authorization to Unauthenticated Payment Bypass via REST API No login needed 4.0.26 – 4.1.15 CVE-2026-13039 Wordfence
6.5 Medium JoomSport Plugin joomsport-sports-league-results-management SQL Injection Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute ≤ 5.7.9 CVE-2026-13010 Wordfence
6.4 Medium Eventin Plugin wp-event-solution Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter ≤ 4.1.15 CVE-2026-12924 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup ≤ 6.6.2 CVE-2026-6459 Wordfence
6.4 Medium Event Organiser Plugin event-organiser Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode ≤ 3.12.9 CVE-2026-2387 Wordfence
4.3 Medium Book a Room Event Calendar Plugin book-a-room-event-calendar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.9 CVE-2026-9721 Wordfence
5.3 Medium Event Koi Lite Plugin eventkoi-lite Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints No login needed ≤ 1.3.13.1 CVE-2026-10029 Wordfence
6.5 Medium Event Tickets Plugin event-tickets Authentication Bypass Bypass Vulnerability No login needed ≤ 5.27.5 Fixed in 5.27.6.1 CVE-2026-42662 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
5.3 Medium Event Monster Plugin event-monster Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action No login needed ≤ 2.1.0 CVE-2026-8608 Wordfence
4.3 Medium Timetable and Event Schedule by MotoPress Plugin mp-timetable Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function ≤ 2.4.16 CVE-2026-9228 Wordfence
6.4 Medium Events In City Plugin events-in-city Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.0 CVE-2026-8898 Wordfence
5.3 Medium RSVP and Event Management Plugin rsvp Broken Access Control No login needed ≤ 2.7.16 Fixed in 2.7.17 CVE-2026-27398 Patchstack
4.3 Medium My Calendar Plugin my-calendar Broken Access Control Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter ≤ 3.7.9 CVE-2026-7525 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint No login needed ≤ 2.1.2 CVE-2026-6449 Wordfence
4.4 Medium List View Google Calendar Plugin list-view-google-calendar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Event Description ≤ 7.4.3 CVE-2026-2396 Wordfence
4.3 Medium Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) Plugin Broken Access Control Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 4.1.8 CVE-2026-4109 Wordfence
5.3 Medium RSVP and Event Management Plugin rsvp Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.16 Fixed in 2.7.17 CVE-2026-39536 Patchstack
5.3 Medium Display Eventbrite Events Plugin widget-for-eventbrite-api Broken Access Control No login needed ≤ 6.5.6 Fixed in 6.5.7 CVE-2026-39535 Patchstack
6.5 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Cross-Site Scripting ≤ 1.4.36 CVE-2026-25465 Patchstack
5.3 Medium Modern Events Calendar Plugin modern-events-calendar Broken Access Control No login needed ≤ 7.29.0 CVE-2026-32583 Patchstack
6.5 Medium Themify Event Post Plugin themify-event-post Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-32449 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.1.9 Fixed in 5.1.9 CVE-2026-32354 Patchstack
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
4.3 Medium Court Reservation Plugin court-reservation Cross-Site Request Forgery Event Deletion via CSRF No login needed < 1.10.9 Fixed in 1.10.9 CVE-2026-1508 WPScan
4.9 Medium Community Events Plugin community-events SQL Injection Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field ≤ 1.5.8 CVE-2026-2429 Wordfence
5.3 Medium MDJM Event Management Plugin mobile-dj-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion No login needed ≤ 1.7.8.1 CVE-2026-1650 Wordfence
6.4 Medium My Calendar – Accessible Event Manager Plugin my-calendar Cross-Site Scripting Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.7.3 CVE-2026-2355 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API ≤ 6.15.16 CVE-2026-2694 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.8.3 Fixed in 4.2.8.4 CVE-2026-25389 Patchstack
4.3 Medium Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Email MFA Update ≤ 21.0.9 CVE-2025-14427 Wordfence
6.4 Medium XO Event Calendar Plugin xo-event-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_event_field' shortcode ≤ 3.2.10 CVE-2026-0556 Wordfence
4.4 Medium Community Events Plugin community-events Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter ≤ 1.5.7 CVE-2026-1649 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only