WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 1,491 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Frontend File Manager Plugin Cross-Site Request Forgery File Metadata Update via CSRF No login needed ≤ 23.6 CVE-2026-16292 WPScan
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Podcast Contributor/Group/Role Creation and Deletion via CSRF No login needed < 4.5.3 Fixed in 4.5.3 CVE-2026-13729 WPScan
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
5.4 Medium AffiliateX Plugin affiliatex Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2026-65558 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Request Forgery No login needed ≤ 4.4.5 CVE-2026-65536 Patchstack
5.4 Medium WP Activity Log Plugin wp-security-audit-log Cross-Site Request Forgery No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-65512 Patchstack
4.4 Medium Complianz Plugin complianz-gdpr Server-Side Request Forgery ≤ 7.5.0 CVE-2026-65496 Patchstack
4.9 Medium JetEngine Plugin jet-engine Server-Side Request Forgery ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-65467 Patchstack
4.9 Medium JetBooking Plugin jet-booking Server-Side Request Forgery ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65466 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65464 Patchstack
4.3 Medium Zarinpal Gateway Plugin zarinpal-woocommerce-payment-gateway Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65460 Patchstack
5.4 Medium Simple Link Directory Pro Plugin simple-link-directory-pro Cross-Site Request Forgery No login needed ≤ 15.0.8 Fixed in 15.0.9 CVE-2026-61981 Patchstack
4.4 Medium Photo Block Plugin photo-block Server-Side Request Forgery ≤ 1.7.1 CVE-2026-24639 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Cross-Site Request Forgery No login needed ≤ 0.6.6 CVE-2026-24537 Patchstack
5.4 Medium MailerSend - Official SMTP Integration Plugin Cross-Site Request Forgery Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF No login needed < 1.0.8 Fixed in 1.0.8 CVE-2026-13156 WPScan
5.4 Medium LatePoint Plugin Cross-Site Request Forgery Multiple Privileged Actions via CSRF No login needed < 5.6.3 Fixed in 5.6.3 CVE-2026-11866 WPScan
4.9 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Server-Side Request Forgery ≤ 5.0.4 Fixed in 5.0.5 CVE-2026-61970 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57395 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57392 Patchstack
4.3 Medium SurfLink Plugin surflink Broken Access Control Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action < 2.6.0 Fixed in 2.6.0 CVE-2026-3552 Wordfence
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Site Info Endpoint No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12517 WPScan
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Media Proxy No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12516 WPScan
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
6.5 Medium Booked Plugin booked Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-57747 Patchstack
4.3 Medium Werkstatt Theme werkstatt Cross-Site Request Forgery No login needed ≤ 4.7.2 CVE-2026-57690 Patchstack
6.4 Medium GeoDirectory Plugin geodirectory Server-Side Request Forgery ≤ 2.8.161 Fixed in 2.8.162 CVE-2026-57681 Patchstack
4.3 Medium Gmail SMTP Plugin gmail-smtp Cross-Site Request Forgery No login needed ≤ 1.2.3.19 Fixed in 1.2.3.20 CVE-2026-57657 Patchstack
6.5 Medium Real Estate 7 Theme realestate-7 Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2026-57641 Patchstack
4.3 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-57637 Patchstack
6.5 Medium FunnelKit Payment Gateway for Stripe WooCommerce Plugin funnelkit-stripe-woo-payment-gateway Cross-Site Request Forgery No login needed ≤ 1.14.0.3 Fixed in 1.14.0.4 CVE-2026-57635 Patchstack
4.9 Medium Kirki Plugin kirki Server-Side Request Forgery ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57627 Patchstack
6.4 Medium utm.codes Plugin utm-dot-codes Server-Side Request Forgery ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-56026 Patchstack
6.5 Medium WP EasyPay Plugin wp-easy-pay Cross-Site Request Forgery No login needed ≤ 4.5.0 CVE-2026-56024 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 8.0 Fixed in 9.0 CVE-2024-35648 Patchstack
4.3 Medium Skyline WP Theme skyline-wp Cross-Site Request Forgery No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-34810 Patchstack
4.7 Medium WP Migrate Lite Plugin wp-migrate-db Cross-Site Request Forgery No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2026-49043 Patchstack
4.4 Medium PopAd Plugin popad Server-Side Request Forgery ≤ 1.0.4 CVE-2025-60175 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
5.4 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Broken Access Control Broken Access Control + CSRF ≤ 1.6.3.3 Fixed in 1.6.3.4 CVE-2022-45813 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
6.1 Medium Product Filter Widget for Elementor Plugin product-filter-widget-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter No login needed ≤ 1.0.6 CVE-2026-11603 Wordfence
6.4 Medium ePaperFlip Publisher Plugin epaperflip-publisher Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'publicationid' Shortcode Attribute ≤ 1 CVE-2026-7662 Wordfence
4.0 Medium Contact Form Maker Plugin contact-form-maker Cross-Site Request Forgery Contact Form by WD 1.13.1 CSRF to Local File Inclusion No login needed 1.13.1 CVE-2019-25734 VulnCheck
4.3 Medium DearFlip Plugin 3d-flipbook-dflip-lite Broken Access Control ≤ 2.4.27 CVE-2026-49047 Patchstack
4.3 Medium WPSubscription Plugin subscription Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24554 Patchstack
6.5 Medium Export WP Page to Static HTML/CSS Plugin export-wp-page-to-static-html Cross-Site Request Forgery No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-24574 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only