WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 2,543 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
4.3 Medium JetStyleManager Plugin jet-style-manager Cross-Site Request Forgery Skin Deletion and Modification via CSRF No login needed < 1.3.9 Fixed in 1.3.9 CVE-2026-81432 WPScan
4.3 Medium WC Vendors Plugin wc-vendors Cross-Site Request Forgery Order Shipment Status Change via CSRF No login needed < 2.7.2.1 Fixed in 2.7.2.1 CVE-2026-81426 WPScan
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
9.3 Critical Icollect Plugin Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed ≤ 1.0.0 CVE-2026-77012 WPScan
5.4 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery Arbitrary Plugin Option Update via CSRF No login needed < 4.17 Fixed in 4.17 CVE-2026-17522 WPScan
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
8.1 High FluentBooking Pro Plugin fluent-booking-pro Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-81273 Patchstack
8.8 High GeoDirectory Plugin geodirectory Cross-Site Request Forgery No login needed ≤ 2.8.176 Fixed in 2.8.177 CVE-2026-81271 Patchstack
5.9 Medium UpdraftPlus Plugin Cross-Site Request Forgery Backup Restoration via CSRF No login needed < 1.26.7 Fixed in 1.26.7 CVE-2026-76549 WPScan
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack
6.4 Medium Shared Files Plugin shared-files Server-Side Request Forgery ≤ 1.7.69 Fixed in 1.7.70 CVE-2026-78269 Patchstack
9.8 Critical Mailgun Plugin mailgun Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed ≤ 2.2.0 CVE-2026-78003 Wordfence
4.2 Medium LitExtension: Store to WooCommerce Migration Plugin Cross-Site Request Forgery Connector Token Takeover via CSRF No login needed ≤ 1.2.5 CVE-2026-15046 WPScan
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
7.4 High Slider by 10Web Plugin slider-wd Cross-Site Request Forgery No login needed ≤ 1.2.63 CVE-2026-66635 Patchstack
7.2 High OttoKit Plugin suretriggers Server-Side Request Forgery No login needed ≤ 1.1.35 Fixed in 1.1.36 CVE-2026-32553 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-32473 Patchstack
6.0 Medium [Aotuman] Grab WeChat Articles Plugin apoyl-grabweixin Server-Side Request Forgery ≤ 2.0.1 CVE-2026-32467 Patchstack
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.23.1 Fixed in 2.23.2 CVE-2026-27999 Patchstack
6.4 Medium ProSolution WP Client Plugin prosolution-wp-client Server-Side Request Forgery Subscriber+ SSRF via proSol_url_validate < 2.0.9 Fixed in 2.0.9 CVE-2026-19050 WPScan
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
7.5 High Estatik Plugin Cross-Site Request Forgery Login CSRF No login needed < 4.3.3 Fixed in 4.3.3 CVE-2026-16262 WPScan
10.0 Critical Premium SEO Plugin Remote Code Execution Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) No login needed Not stated CVE-2026-14812 WPScan
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
6.5 Medium Google Authenticator Plugin google-authenticator Cross-Site Request Forgery Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF No login needed < 0.56 Fixed in 0.56 CVE-2026-14204 WPScan
4.3 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Request Forgery Cookie Deletion and Forced Logout via CSRF No login needed < 5.1.0 Fixed in 5.1.0 CVE-2026-16613 WPScan
4.7 Medium Clearfy Plugin Open Redirect Open Redirect via Cyrlitera 404 Handler No login needed < 2.4.3 Fixed in 2.4.3 CVE-2026-16296 WPScan
4.3 Medium Clearfy Plugin Information Disclosure Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher < 2.4.3 Fixed in 2.4.3 CVE-2026-16295 WPScan
5.8 Medium EmbedPress Plugin embedpress Server-Side Request Forgery Unauthenticated Blind SSRF No login needed < 4.6.1 Fixed in 4.6.1 CVE-2026-10526 WPScan
5.3 Medium Simple Google Calendar Outlook Events Widget Plugin simple-google-icalendar-widget Server-Side Request Forgery Unauthenticated SSRF via calendar_id No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-16536 WPScan
4.1 Medium Clearfy Plugin PHP Object Injection Admin+ PHP Object Injection via Settings Import < 2.4.3 Fixed in 2.4.3 CVE-2026-16297 WPScan
5.4 Medium Frontend File Manager Plugin Cross-Site Request Forgery File Metadata Update via CSRF No login needed ≤ 23.6 CVE-2026-16292 WPScan
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Podcast Contributor/Group/Role Creation and Deletion via CSRF No login needed < 4.5.3 Fixed in 4.5.3 CVE-2026-13729 WPScan
7.1 High Tourmaster Plugin Cross-Site Scripting Stored XSS via CSRF No login needed < 5.4.8 Fixed in 5.4.8 CVE-2026-14239 WPScan
7.1 High WOLF - WordPress Posts Bulk Editor and Manager Plugin Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed < 1.1.0 Fixed in 1.1.0 CVE-2026-14234 WPScan
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.2 High Simple Link Directory Pro Plugin simple-link-directory-pro Server-Side Request Forgery No login needed ≤ 15.0.6 Fixed in 15.0.7 CVE-2026-61953 Patchstack
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only