WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 345 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium International Sms For Contact Form Plugin cf7-international-sms-integration Cross-Site Scripting WordPress International Sms Contact Form 7 Integration 1.2 XSS No login needed 1.2 CVE-2022-50960 VulnCheck
7.5 High Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Denial of Service Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption No login needed < 2.7.3 Fixed in 2.7.3 CVE-2026-25863 VulnCheck
5.3 Medium FundPress Plugin fundpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Donation Status Modification via donate_action_status AJAX Handler No login needed ≤ 2.0.8 CVE-2026-4650 Wordfence
4.4 Medium Ona Theme ona Server-Side Request Forgery Authenticated (Administrator+) Blind Server-Side Request Forgery via 'download_link' Parameter ≤ 1.26 CVE-2026-6812 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
6.5 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification No login needed ≤ 1.1.5 CVE-2026-1672 Wordfence
4.3 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion No login needed ≤ 1.1.5 CVE-2026-1673 Wordfence
5.3 Medium Cryptocurrency Donation Box – Bitcoin & Crypto Donations Plugin cryptocurrency-donation-box Broken Access Control Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control No login needed ≤ 2.2.13 CVE-2026-39691 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
5.4 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery No login needed ≤ 5.11 CVE-2026-39647 Patchstack
5.3 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable Other Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook No login needed ≤ 1.8.9.7 CVE-2026-3177 Wordfence
9.8 Critical Contact Form by Supsystic Plugin contact-form-by-supsystic Remote Code Execution Unauthenticated Server-Side Template Injection via Prefill Functionality No login needed ≤ 1.7.36 CVE-2026-4257 Wordfence
4.3 Medium Conditional Menus Plugin conditional-menus Cross-Site Request Forgery Cross-Site Request Forgery to Menu Options Update No login needed ≤ 1.2.6 CVE-2026-1032 Wordfence
9.3 Critical PublishPress Revisions Plugin revisionary SQL Injection No login needed ≤ <= 3.7.23 Fixed in 3.7.24 CVE-2026-32539 Patchstack
9.9 Critical Ona Plugin ona Arbitrary File Upload ≤ < 1.24 Fixed in 1.24 CVE-2026-32482 Patchstack
8.8 High Apicona Theme apicona PHP Object Injection ≤ 24.1.0 CVE-2026-25400 Patchstack
8.8 High Visionary Core Plugin noo-visionary-core PHP Object Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-24981 Patchstack
7.1 High Visionary Core Plugin noo-visionary-core Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-24980 Patchstack
4.3 Medium Smart Custom Fields Plugin smart-custom-fields Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Relational Post Search ≤ 5.0.6 CVE-2026-4066 Wordfence
4.4 Medium Weaver Show Posts Plugin show-posts Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Additional Classes to Wrap Posts' Widget Setting ≤ 1.8.1 CVE-2026-2121 Wordfence
5.5 Medium Multi Functional Flexi Lightbox Plugin multi-functional-flexi-lightbox Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via 'message' Parameter ≤ 1.2 CVE-2026-3347 Wordfence
6.4 Medium WordPress PayPal Donation Plugin wordpress-paypal-donation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'amount' Shortcode Attribute ≤ 1.01 CVE-2026-4072 Wordfence
9.3 Critical WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem SQL Injection Easy Stripe & Paypal donations plugin <= 1.25 - SQL Injection No login needed ≤ 1.25 CVE-2026-28115 Patchstack
8.1 High Eona Theme eona Local File Inclusion No login needed ≤ 1.3 CVE-2026-22412 Patchstack
4.3 Medium Conditional CAPTCHA Plugin Open Redirect No login needed ≤ 4.0.0 CVE-2026-1369 WPScan
5.3 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure No login needed 4.0 – 5.10 CVE-2026-1219 Wordfence
5.4 Medium PublishPress Revisions Plugin revisionary Cross-Site Request Forgery No login needed ≤ 3.7.22 Fixed in 3.7.23 CVE-2026-25322 Patchstack
8.8 High IDonate Plugin idonate Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function 2.1.5 – 2.1.9 CVE-2025-4521 Wordfence
7.2 High Product Addons for Woocommerce – Product Options with Custom Fields Plugin woo-custom-product-addons Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter ≤ 3.1.0 CVE-2026-2296 Wordfence
6.4 Medium Display During Conditional Shortcode Plugin display-during-conditional-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via message Parameter ≤ 1.2 CVE-2025-6460 Wordfence
5.0 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery 5.3 – 5.10 CVE-2026-1249 Wordfence
6.1 Medium personal-authors-category Plugin personal-authors-category Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.3 CVE-2026-1754 Wordfence
7.2 High Lucky Wheel Giveaway Plugin wp-lucky-wheel Remote Code Execution Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter ≤ 1.0.22 CVE-2025-14541 Wordfence
4.3 Medium Bitcoin Donate Button Plugin bitcoin-donate-button Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1380 Wordfence
4.3 Medium Trusona Plugin trusona Broken Access Control ≤ 2.0.0 CVE-2026-24627 Patchstack
6.5 Medium Houzez Theme - Functionality Plugin houzez-theme-functionality Cross-Site Scripting Functionality plugin <= 4.2.6 - Cross Site Scripting (XSS) ≤ 4.2.6 Fixed in 4.2.7 CVE-2026-24355 Patchstack
7.6 High FireStorm Professional Real Estate Plugin fs-real-estate-plugin SQL Injection ≤ 2.7.11 CVE-2026-22470 Patchstack
8.8 High Anona Plugin anona PHP Object Injection ≤ 8.0 CVE-2025-68903 Patchstack
7.5 High Anona Plugin anona Path Traversal Arbitrary File Download No login needed ≤ 8.0 CVE-2025-68902 Patchstack
8.6 High Anona Plugin anona Arbitrary File Deletion No login needed ≤ 8.0 CVE-2025-68901 Patchstack
7.5 High WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Broken Access Control Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion No login needed ≤ 1.25 CVE-2025-22715 Patchstack
4.4 Medium Multi-column Tag Map Plugin multi-column-tag-map Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'mctm_css_conditional' Parameter ≤ 17.0.39 CVE-2025-14057 Wordfence
9.8 Critical Optional Email Plugin optional-email Privilege Escalation Unauthenticated Privilege Escalation to Account Takeover No login needed ≤ 1.3.11 CVE-2025-15018 Wordfence
5.4 Medium Questionar for Elementor Plugin questionar-elementor Broken Access Control ≤ 1.1.7 CVE-2025-66155 Patchstack
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
4.7 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Open Redirect No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-68602 Patchstack
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' ≤ 1.3.7.3 CVE-2025-13110 Wordfence
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.11 CVE-2025-60045 Patchstack
7.5 High IDonatePro Plugin idonate-pro Broken Access Control No login needed ≤ 2.1.9 CVE-2025-58938 Patchstack
4.3 Medium WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.25 CVE-2025-58999 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only