WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Mang Board WP Plugin mangboard Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie ≤ 2.3.7 CVE-2026-75977 Wordfence
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack
6.4 Medium Shared Files Plugin shared-files Server-Side Request Forgery ≤ 1.7.69 Fixed in 1.7.70 CVE-2026-78269 Patchstack
9.8 Critical Mailgun Plugin mailgun Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed ≤ 2.2.0 CVE-2026-78003 Wordfence
5.3 Medium Conekta Payment Gateway Plugin conekta-payment-gateway Broken Access Control Unauthenticated Order Payment Completion via Webhook Forgery No login needed < 6.2.2 Fixed in 6.2.2 CVE-2026-16738 WPScan
2.7 Low Eventin Plugin wp-event-solution Server-Side Request Forgery Contributor+ Server-Side Request Forgery < 4.1.21 Fixed in 4.1.21 CVE-2026-13176 WPScan
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
7.4 High Slider by 10Web Plugin slider-wd Cross-Site Request Forgery No login needed ≤ 1.2.63 CVE-2026-66635 Patchstack
7.2 High OttoKit Plugin suretriggers Server-Side Request Forgery No login needed ≤ 1.1.35 Fixed in 1.1.36 CVE-2026-32553 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-32473 Patchstack
6.0 Medium [Aotuman] Grab WeChat Articles Plugin apoyl-grabweixin Server-Side Request Forgery ≤ 2.0.1 CVE-2026-32467 Patchstack
9.8 Critical Forminator Forms Plugin forminator Arbitrary File Upload Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration No login needed ≤ 1.56.1 CVE-2026-15748 Wordfence
5.9 Medium WooMS Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure No login needed ≤ 9.14 CVE-2026-13700 WPScan
6.5 Medium WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Deletion No login needed ≤ 7.10.09 CVE-2026-17608 Wordfence
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting ≤ 1.7.1064 CVE-2026-17123 Wordfence
5.9 Medium Epeken All Kurir Plugin epeken-all-kurir Authentication Bypass Unauthenticated Order Payment Confirmation Forgery No login needed ≤ 2.1.4 CVE-2026-16739 WPScan
4.3 Medium Astro Booking Engine Plugin astro-booking-engine Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 1.4.0 CVE-2025-10308 Wordfence
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
5.3 Medium Welcart e-Commerce Plugin usc-e-shop Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed < 2.11.33 Fixed in 2.11.33 CVE-2026-15213 WPScan
7.1 High Blubrry PowerPress Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL < 11.17.1 Fixed in 11.17.1 CVE-2026-16294 WPScan
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
5.3 Medium Podcast Player Plugin podcast-player Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 8.3.1 Fixed in 8.3.1 CVE-2026-14860 WPScan
2.2 Low LearnPress Plugin learnpress Server-Side Request Forgery Instructor+ Server-Side Request Forgery via openai_apply_image_feature < 4.4.4 Fixed in 4.4.4 CVE-2026-12971 WPScan
8.1 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed < 3.1.8.8 Fixed in 3.1.8.8 CVE-2026-18030 WPScan
4.8 Medium AI Engine Plugin ai-engine Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed < 3.6.4 Fixed in 3.6.4 CVE-2026-16953 WPScan
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
8.2 High Newsletters Plugin newsletters-lite Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via SNS Bounce Handler No login needed < 4.16 Fixed in 4.16 CVE-2026-16268 WPScan
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field No login needed ≤ 1.56.1 CVE-2026-18325 Wordfence
8.1 High Search Analytics for WP Plugin search-analytics Cross-Site Request Forgery No login needed ≤ 1.4.16 CVE-2026-7444 Wordfence
6.8 Medium Visualizer: Tables and Charts Manager Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via JSON Import < 4.0.6 Fixed in 4.0.6 CVE-2026-14939 WPScan
6.5 Medium The GDPR Framework Plugin gdpr-framework Broken Access Control Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-14816 WPScan
9.8 Critical WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT No login needed ≤ 2.8.7 CVE-2026-8457 Wordfence
8.8 High AI Engine Plugin ai-engine Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match No login needed ≤ 3.6.5 CVE-2026-15988 Wordfence
4.3 Medium Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross-Site Request Forgery to CSS Modification No login needed ≤ 3.1 CVE-2025-14469 Wordfence
6.5 Medium Pixel Tag Manager for WooCommerce Plugin pixel-manager-for-woocommerce Broken Access Control Unauthenticated Forged Conversion Event Submission No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14315 WPScan
4.3 Medium FuseWP Plugin fusewp Cross-Site Request Forgery Cross-Site Request Forgery to Sync Rule Status Toggle No login needed ≤ 1.1.24.2 CVE-2026-5582 Wordfence
5.3 Medium WP Travel Plugin wp-travel Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed < 11.8.1 Fixed in 11.8.1 CVE-2026-13143 WPScan
4.9 Medium WP CTA Plugin easy-sticky-sidebar Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery 2.1.2 CVE-2026-6089 Wordfence
4.3 Medium Facturación Electrónica Costa Rica Plugin factura-electronica-cr Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.0.2 CVE-2026-9720 Wordfence
4.1 Medium Media Cleaner: Clean your WordPress! Plugin media-cleaner Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.0.3 CVE-2026-4912 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.2 High Simple Link Directory Pro Plugin simple-link-directory-pro Server-Side Request Forgery No login needed ≤ 15.0.6 Fixed in 15.0.7 CVE-2026-61953 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only