WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical The Pressengine Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.0 CVE-2026-86709 WPScan
9.8 Critical Private Feed Key Plugin Authentication Bypass Unauthenticated Authentication Bypass via 'feedkey' Parameter No login needed ≤ 0.1 CVE-2026-86707 WPScan
9.8 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Arbitrary File Upload Unauthenticated Arbitrary File Upload via Chunked File Upload No login needed ≤ 1.1.9 CVE-2026-87796 Wordfence
9.8 Critical JetFormBuilder Plugin jetformbuilder Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed ≤ 3.6.2 CVE-2026-12793 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action No login needed ≤ 1.2.3 CVE-2026-14349 Wordfence
10.0 Critical CryptoPayment Gateway Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router No login needed 1.2.1 – 1.2.2 CVE-2026-81648 WPScan
9.8 Critical The Events Calendar Plugin the-events-calendar Remote Code Execution Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation No login needed ≤ 6.17.3 CVE-2026-78159 Wordfence
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 6.17.4 CVE-2026-78006 Wordfence
9.8 Critical WP Component Plugin Privilege Escalation Unauthenticated Privilege Escalation via Arbitrary Blog Option Update No login needed ≤ 2.2.4 CVE-2026-85681 WPScan
9.8 Critical WP Images Upload on Piclect Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0 CVE-2026-84171 WPScan
9.9 Critical Masteriyo LMS Plugin learning-management-system PHP Object Injection Subscriber+ PHP Object Injection < 3.4.1 Fixed in 3.4.1 CVE-2026-82845 WPScan
9.8 Critical DS Ad Rotator Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 0.8 CVE-2026-81402 WPScan
9.6 Critical WebTotem Backups Plugin wt-backups Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Path Traversal < 1.1.0 Fixed in 1.1.0 CVE-2026-77006 WPScan
9.6 Critical Code Monkeys Proposals Plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Path Traversal ≤ 1.0.1 CVE-2026-77005 WPScan
9.8 Critical Frontegg SAML SSO Plugin Privilege Escalation Unauthenticated Account Takeover via Unverified SAMLResponse No login needed ≤ 1.0.1 CVE-2026-75800 WPScan
9.8 Critical ThemeREX Addons Plugin trx_addons PHP Object Injection No login needed < 2.45.0 Fixed in 2.45.0 CVE-2026-62105 Patchstack
9.8 Critical Everest Forms Plugin everest-forms PHP Object Injection No login needed ≤ 3.6.0 Fixed in 3.6.1 CVE-2026-62103 Patchstack
9.8 Critical Advanced Customized Prompts Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.1 CVE-2026-14563 WPScan
10.0 Critical Teddy Bear Customize Addon Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2026-14560 WPScan
9.8 Critical Teddy Bear Customize Addon Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.5 CVE-2026-14559 WPScan
9.8 Critical MIPL Grouped Checkout Fields for WooCommerce Plugin mipl-wc-checkout-fields Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2026-8778 Wordfence
9.3 Critical Verified Reviews (Avis Vérifiés) Plugin netreviews SQL Injection No login needed ≤ 2.4.6 CVE-2026-81800 Patchstack
9.1 Critical zipMoney(Zip Co) Payments Plugin for WooCommerce Plugin zipmoney-payments-woocommerce Broken Access Control Unauthenticated Arbitrary Option Deletion No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-78361 WPScan
10.0 Critical miniOrange 2FA (Free & Pro) Plugin Broken Access Control Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator No login needed 5.3.24 – < 6.3.1, 18.0 – < 19.3 Fixed in 6.3.1 CVE-2026-77770 WPScan
9.8 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'type' Parameter No login needed ≤ 1.6.0 CVE-2026-18351 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Account Takeover via '_acf_objects' Object Identifier No login needed ≤ 3.29.12 CVE-2026-75816 Wordfence
9.8 Critical MemberDash Plugin Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter No login needed ≤ 1.8.5 CVE-2026-16310 Wordfence
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection Unauthenticated PHP Object Injection in Arbitrary Form Fields No login needed ≤ 1.31.0 CVE-2026-10196 Wordfence
9.8 Critical Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Remote Code Execution ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection No login needed 2.2.85 – 2.3.32 CVE-2024-11080 Wordfence
9.8 Critical SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Privilege Escalation Unauthenticated Privilege Escalation via API Key Authentication No login needed 3.0.0 – < 3.0.3 Fixed in 3.0.3 CVE-2026-78362 WPScan
9.8 Critical Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN Plugin hummingbird-performance Remote Code Execution Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log No login needed ≤ 3.21.0 CVE-2026-83627 Wordfence
9.8 Critical MStore API Plugin mstore-api Authentication Bypass Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery No login needed ≤ 4.20.0 CVE-2026-13447 Wordfence
9.8 Critical AI Website Builder (GitHub build) Plugin Remote Code Execution Unauthenticated RCE via Unprotected REST Routes No login needed 1.0.0 – 1.0.0 CVE-2026-82923 WPScan
9.8 Critical ACPT (Premium) Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter No login needed ≤ 2.0.66 CVE-2026-15354 Wordfence
9.8 Critical Divi Ajax Filter Plugin Local File Inclusion Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter No login needed ≤ 5.1.2 CVE-2026-11613 Wordfence
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.2.0 CVE-2026-84834 Patchstack
9.8 Critical Bricksforge Plugin bricksforge Privilege Escalation No login needed ≤ 3.1.8.8 Fixed in 3.1.8.9 CVE-2026-84814 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.174 Fixed in 2.8.175 CVE-2026-84813 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84753 Patchstack
9.8 Critical YITH Request a Quote for WooCommerce Premium Plugin yith-woocommerce-request-a-quote-premium Broken Access Control No login needed < 4.46.0 Fixed in 4.46.0 CVE-2026-84238 Patchstack
9.8 Critical Developer Tools Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.1.3 CVE-2025-9314 WPScan
9.9 Critical WatchMan-Site7 Plugin Remote Code Execution Subscriber+ RCE via Debug Console 3.1.1 – 4.2.0 CVE-2026-77009 WPScan
10.0 Critical Embed HTML5 Game Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3 CVE-2026-4357 WPScan
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.1 Fixed in 3.15.2 CVE-2026-81294 Patchstack
9.3 Critical WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2026-81286 Patchstack
9.8 Critical SigmaForms Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field No login needed ≤ 1.4.11 CVE-2026-78657 Wordfence
9.8 Critical Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Privilege Escalation Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' No login needed 8.0 – 9.6.2 CVE-2026-9055 Wordfence
9.8 Critical Nokri - Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter No login needed ≤ 1.6.6 CVE-2026-18550 Wordfence
9.8 Critical WPLP Cookie Consent Plugin gdpr-cookie-consent Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint No login needed ≤ 4.4.1 CVE-2026-75865 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only