WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 425 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.1 High SureCart Plugin surecart Privilege Escalation Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook No login needed ≤ 4.2.3 CVE-2026-7655 Wordfence
7.2 High Planyo online reservation system Plugin planyo-online-reservation-system Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter No login needed ≤ 3.0 CVE-2026-3576 Wordfence
8.8 High Salon Booking System Plugin salon-booking-system Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter No login needed ≤ 10.30.32 CVE-2026-15070 Wordfence
8.8 High Divi Torque Lite Plugin addons-for-divi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint No login needed ≤ 4.2.3 CVE-2026-4275 Wordfence
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2026-57751 Patchstack
7.2 High Paid Member Subscriptions Plugin paid-member-subscriptions Server-Side Request Forgery No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-57348 Patchstack
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter ≤ 6.0.9.1 CVE-2026-12158 Wordfence
8.8 High Paid Memberships Pro - Add Member From Admin Plugin pmpro-add-member-admin Cross-Site Request Forgery Add Member From Admin plugin <= 0.7.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 0.7.2 Fixed in 0.7.3 CVE-2026-57659 Patchstack
8.2 High Child Theme Wizard Plugin child-theme-wizard Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-57655 Patchstack
8.8 High Eagle Booking Plugin eagle-booking Cross-Site Request Forgery No login needed ≤ 1.3.4.3 CVE-2025-68052 Patchstack
7.2 High Kargo Takip Plugin kargo-takip Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'api_url' Parameter No login needed ≤ 1.2 CVE-2026-12095 Wordfence
7.2 High URL Preview Plugin link-preview Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.0 CVE-2026-12100 Wordfence
7.2 High CF7 to Webhook Plugin cf7-to-zapier Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host No login needed ≤ 5.0.0 CVE-2026-11395 Wordfence
7.5 High Bricksforge Plugin bricksforge Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.8.4 Fixed in 3.1.8.5 CVE-2026-34888 Patchstack
8.8 High Dating Theme da10 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 11.2.0 CVE-2026-22342 Patchstack
7.2 High Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed ≤ 6.1.3 CVE-2026-10586 Wordfence
8.1 High Media Library Assistant Plugin media-library-assistant Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed ≤ 3.35 CVE-2026-6075 Wordfence
8.1 High WP Contact Form 7 DB Handler Plugin wp-contact-form-7-db-handler Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed ≤ 3.0 CVE-2026-6455 Wordfence
7.1 High CformsII Plugin cforms2 Cross-Site Request Forgery No login needed ≤ 15.1.3 Fixed in 15.1.4 CVE-2026-39436 Patchstack
7.2 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter No login needed ≤ 1.7.1057 CVE-2026-6229 Wordfence
7.2 High PixelYourSite Pro Plugin pixelyoursite-pro Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery via 'urls[]' Parameter No login needed ≤ 12.5.0.1 CVE-2026-7049 Wordfence
8.8 High WP Editor Plugin wp-editor Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor No login needed ≤ 1.2.9.2 CVE-2026-3772 Wordfence
7.5 High Otter Blocks Plugin otter-blocks Broken Access Control Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie No login needed ≤ 3.1.4 CVE-2026-2892 Wordfence
8.8 High Career Section Plugin career-section Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.6 CVE-2025-14868 Wordfence
8.1 High Contact Form by WPForms Plugin wpforms-lite Cross-Site Request Forgery No login needed ≤ 1.10.0.2 Fixed in 1.10.0.3 CVE-2026-40764 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
8.8 High Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed 13.4.6 – 13.5.2.1 CVE-2026-3499 Wordfence
7.5 High Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Request Forgery No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-34904 Patchstack
7.5 High Under Construction, Coming Soon & Maintenance Mode Plugin under-construction-maintenance-mode Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-34896 Patchstack
7.2 High Webmention Plugin webmention Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 5.6.2 CVE-2026-0686 Wordfence
7.2 High Oxygen Theme oxygen Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via route_path No login needed ≤ 6.0.8 CVE-2025-12886 Wordfence
7.2 High Content Syndication Toolkit Plugin content-syndication-toolkit Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.3 CVE-2026-3478 Wordfence
7.2 High Performance Monitor Plugin performance-monitor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.0.6 CVE-2026-1648 Wordfence
8.1 High Invelity Products Feeds Plugin invelity-products-feeds Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion ≤ 1.2.6 CVE-2025-14037 Wordfence
8.3 High MimeTypes Link Icons Plugin mimetypes-link-icons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Crafted Links in Post Content No login needed ≤ 3.2.20 CVE-2026-1313 Wordfence
7.2 High WowOptin: Next-Gen Popup Maker Plugin optin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API No login needed ≤ 1.4.29 CVE-2026-4302 Wordfence
7.2 High PostX Plugin ultimate-post Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints No login needed ≤ 5.0.8 CVE-2026-1273 Wordfence
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
7.5 High WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token No login needed ≤ 3.8.3 CVE-2026-1916 Wordfence
7.2 High Oxygen Theme oxygen Server-Side Request Forgery No login needed ≤ 6.0.8 CVE-2025-69299 Patchstack
7.2 High Smart Auto Upload Images Plugin smart-auto-upload-images Server-Side Request Forgery ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-23803 Patchstack
8.8 High NewsBlogger Theme newsblogger Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation No login needed 0.2.5.6 – 0.2.5.9 CVE-2025-12821 Wordfence
7.2 High All In One Image Viewer Block Plugin image-viewer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via image-proxy Endpoint No login needed ≤ 1.0.2 CVE-2026-1294 Wordfence
7.2 High TableMaster for Elementor Plugin tablemaster-for-elementor Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter No login needed ≤ 1.3.6 CVE-2025-14610 Wordfence
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.1.6 CVE-2026-0807 Wordfence
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-68030 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only