WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 51–100 of 2,392 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | Mang Board WP | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie |
≤ 2.3.7 |
CVE-2026-75977 |
Wordfence | |
| 4.3 Medium | Hash Form | Cross-Site Request Forgery No login needed |
≤ 1.4.0 Fixed in 1.4.1 |
CVE-2026-78280 |
Patchstack | |
| 5.4 Medium | Fluent Support Pro | Cross-Site Request Forgery No login needed |
≤ 2.3.1 Fixed in 2.3.2 |
CVE-2026-78279 |
Patchstack | |
| 4.9 Medium | FluentCRM Pro | Server-Side Request Forgery |
≤ 3.1.12 Fixed in 3.1.13 |
CVE-2026-78277 |
Patchstack | |
| 6.4 Medium | Shared Files | Server-Side Request Forgery |
≤ 1.7.69 Fixed in 1.7.70 |
CVE-2026-78269 |
Patchstack | |
| 9.8 Critical | Mailgun | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed |
≤ 2.2.0 |
CVE-2026-78003 |
Wordfence | |
| 5.3 Medium | Conekta Payment Gateway | Broken Access Control Unauthenticated Order Payment Completion via Webhook Forgery No login needed |
< 6.2.2 Fixed in 6.2.2 |
CVE-2026-16738 |
WPScan | |
| 2.7 Low | Eventin | Server-Side Request Forgery Contributor+ Server-Side Request Forgery |
< 4.1.21 Fixed in 4.1.21 |
CVE-2026-13176 |
WPScan | |
| 9.6 Critical | Easy Elementor Addons | Cross-Site Request Forgery No login needed |
≤ 2.3.7 Fixed in 2.3.8 |
CVE-2026-28164 |
Patchstack | |
| 7.2 High | Animation Addons for Elementor | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
< 2.7.2 Fixed in 2.7.2 |
CVE-2026-17565 |
WPScan | |
| 8.8 High | HashBar – WordPress Notification Bar | Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2026-66602 |
Patchstack | |
| 7.4 High | Slider by 10Web | Cross-Site Request Forgery No login needed |
≤ 1.2.63 |
CVE-2026-66635 |
Patchstack | |
| 7.2 High | OttoKit | Server-Side Request Forgery No login needed |
≤ 1.1.35 Fixed in 1.1.36 |
CVE-2026-32553 |
Patchstack | |
| 7.2 High | PDF Smart Viewer for Elementor | Server-Side Request Forgery No login needed |
≤ 1.0.4 |
CVE-2026-32473 |
Patchstack | |
| 6.0 Medium | [Aotuman] Grab WeChat Articles | Server-Side Request Forgery |
≤ 2.0.1 |
CVE-2026-32467 |
Patchstack | |
| 9.8 Critical | Forminator Forms | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration No login needed |
≤ 1.56.1 |
CVE-2026-15748 |
Wordfence | |
| 5.9 Medium | WooMS | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure No login needed |
≤ 9.14 |
CVE-2026-13700 |
WPScan | |
| 6.5 Medium | WP Compress | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Deletion No login needed |
≤ 7.10.09 |
CVE-2026-17608 |
Wordfence | |
| 8.8 High | Royal Addons for Elementor | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting |
≤ 1.7.1064 |
CVE-2026-17123 |
Wordfence | |
| 5.9 Medium | Epeken All Kurir | Authentication Bypass Unauthenticated Order Payment Confirmation Forgery No login needed |
≤ 2.1.4 |
CVE-2026-16739 |
WPScan | |
| 4.3 Medium | Astro Booking Engine | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed |
≤ 1.4.0 |
CVE-2025-10308 |
Wordfence | |
| 7.2 High | Gutenverse Companion | Server-Side Request Forgery No login needed |
≤ 2.5.1 Fixed in 2.5.2 |
CVE-2026-66704 |
Patchstack | |
| 6.0 Medium | Vehica Core | Server-Side Request Forgery |
≤ 1.0.104 |
CVE-2026-66654 |
Patchstack | |
| 5.3 Medium | Welcart e-Commerce | Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed |
< 2.11.33 Fixed in 2.11.33 |
CVE-2026-15213 |
WPScan | |
| 7.1 High | Blubrry PowerPress | Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL |
< 11.17.1 Fixed in 11.17.1 |
CVE-2026-16294 |
WPScan | |
| 5.4 Medium | WP Umbrella | Cross-Site Request Forgery No login needed |
2.24.2 – 2.26.2 Fixed in 2.27.0 |
CVE-2026-66642 |
Patchstack | |
| 5.3 Medium | Podcast Player | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
< 8.3.1 Fixed in 8.3.1 |
CVE-2026-14860 |
WPScan | |
| 2.2 Low | LearnPress | Server-Side Request Forgery Instructor+ Server-Side Request Forgery via openai_apply_image_feature |
< 4.4.4 Fixed in 4.4.4 |
CVE-2026-12971 |
WPScan | |
| 8.1 High | Bricksforge | Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed |
< 3.1.8.8 Fixed in 3.1.8.8 |
CVE-2026-18030 |
WPScan | |
| 4.8 Medium | AI Engine | Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed |
< 3.6.4 Fixed in 3.6.4 |
CVE-2026-16953 |
WPScan | |
| 6.5 Medium | Plugins Garbage Collector (Database Cleanup) | Cross-Site Request Forgery No login needed |
≤ 0.14 |
CVE-2026-66686 |
Patchstack | |
| 4.3 Medium | Theme My Login | Cross-Site Request Forgery No login needed |
≤ 7.1.14 |
CVE-2026-66681 |
Patchstack | |
| 8.2 High | Newsletters | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via SNS Bounce Handler No login needed |
< 4.16 Fixed in 4.16 |
CVE-2026-16268 |
WPScan | |
| 8.1 High | WPMU DEV Dashboard | Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed |
≤ 5.0.0 |
CVE-2026-15459 |
Wordfence | |
| 7.2 High | Forminator Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field No login needed |
≤ 1.56.1 |
CVE-2026-18325 |
Wordfence | |
| 8.1 High | Search Analytics for WP | Cross-Site Request Forgery No login needed |
≤ 1.4.16 |
CVE-2026-7444 |
Wordfence | |
| 6.8 Medium | Visualizer: Tables and Charts Manager | Server-Side Request Forgery Contributor+ Server-Side Request Forgery via JSON Import |
< 4.0.6 Fixed in 4.0.6 |
CVE-2026-14939 |
WPScan | |
| 6.5 Medium | The GDPR Framework | Broken Access Control Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam No login needed |
< 2.4.0 Fixed in 2.4.0 |
CVE-2026-14816 |
WPScan | |
| 9.8 Critical | WooCommerce - Social Login | Authentication Bypass Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT No login needed |
≤ 2.8.7 |
CVE-2026-8457 |
Wordfence | |
| 8.8 High | AI Engine | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match No login needed |
≤ 3.6.5 |
CVE-2026-15988 |
Wordfence | |
| 4.3 Medium | Theme Editor | Cross-Site Request Forgery Cross-Site Request Forgery to CSS Modification No login needed |
≤ 3.1 |
CVE-2025-14469 |
Wordfence | |
| 6.5 Medium | Pixel Tag Manager for WooCommerce | Broken Access Control Unauthenticated Forged Conversion Event Submission No login needed |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14315 |
WPScan | |
| 4.3 Medium | FuseWP | Cross-Site Request Forgery Cross-Site Request Forgery to Sync Rule Status Toggle No login needed |
≤ 1.1.24.2 |
CVE-2026-5582 |
Wordfence | |
| 5.3 Medium | WP Travel | Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed |
< 11.8.1 Fixed in 11.8.1 |
CVE-2026-13143 |
WPScan | |
| 4.9 Medium | WP CTA | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
2.1.2 |
CVE-2026-6089 |
Wordfence | |
| 4.3 Medium | Facturación Electrónica Costa Rica | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.0.2 |
CVE-2026-9720 |
Wordfence | |
| 4.1 Medium | Media Cleaner: Clean your WordPress! | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 7.0.3 |
CVE-2026-4912 |
Wordfence | |
| 4.3 Medium | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent | Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed |
≤ 4.3.7 |
CVE-2026-15136 |
Wordfence | |
| 7.2 High | FormCraft | Server-Side Request Forgery No login needed |
≤ 3.9.15 Fixed in 3.9.16 |
CVE-2026-65442 |
Patchstack | |
| 7.2 High | Simple Link Directory Pro | Server-Side Request Forgery No login needed |
≤ 15.0.6 Fixed in 15.0.7 |
CVE-2026-61953 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.