WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 51–100 of 8,901 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High CMB2 Plugin cmb2 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type No login needed ≤ 2.13.0 CVE-2026-97336 Wordfence
7.2 High DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.6.0 CVE-2026-95817 Wordfence
7.2 High GSpeech TTS Plugin gspeech Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.22.0 CVE-2026-96578 Wordfence
7.2 High MW WP Form Plugin mw-wp-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta) No login needed ≤ 5.1.7 CVE-2026-96567 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 5.122.0 CVE-2026-97663 Wordfence
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter No login needed ≤ 1.8.28 CVE-2026-102565 Wordfence
7.5 High OMGF Plugin host-webfonts-local Denial of Service Unauthenticated DoS via do_optimize No login needed < 6.3.11 Fixed in 6.3.11 CVE-2026-91828 WPScan
7.5 High SiteOrigin Widgets Bundle Plugin so-widgets-bundle Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter ≤ 1.73.2 CVE-2026-92174 Wordfence
7.2 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission No login needed ≤ 3.15.4 CVE-2026-90438 Wordfence
8.8 High Super Forms – Drag & Drop Form Builder Plugin Privilege Escalation Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login ≤ 6.3.316 CVE-2026-15897 Wordfence
8.1 High Ninja Forms - File Uploads Plugin Arbitrary File Upload File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.34 CVE-2026-92820 Wordfence
7.2 High CTX Feed Pro Plugin Remote Code Execution Authenticated (Administrator+) Remote Code Execution ≤ 7.6.12 CVE-2026-10026 Wordfence
7.2 High Visitors Traffic Real Time Statistics Pro Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) No login needed ≤ 11.22 CVE-2026-93367 Wordfence
7.2 High Prime Mover Plugin prime-mover Path Traversal Prime Mover < 2.2.1 Zip Slip Path Traversal File Write < 2.2.1 Fixed in 2.2.1 CVE-2026-101888 VulnCheck
8.8 High ByteCoreStack – MCP Connector for AI Tools Plugin bcs-mcp-manager Privilege Escalation MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation ≤ 1.2.2 Fixed in 1.2.4 CVE-2026-103068 Patchstack
7.1 High Parallax Section block Plugin parallax-section Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.1.0 CVE-2026-102378 Patchstack
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
8.8 High Icegram Plugin icegram PHP Object Injection ≤ 3.1.31 Fixed in 3.1.44 CVE-2026-97284 Patchstack
7.6 High Social Boost Plugin social-boost Broken Access Control ≤ 3.6.2 Fixed in 3.7.0 CVE-2026-97277 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.1 High MaxGalleria Plugin maxgalleria Cross-Site Scripting No login needed ≤ 6.5.3 Fixed in 6.5.4 CVE-2026-97260 Patchstack
8.6 High AcyMailing SMTP Newsletter Plugin acymailing Arbitrary File Deletion No login needed ≤ 11.0.5 Fixed in 11.1.0 CVE-2026-95588 Patchstack
7.2 High Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce PHP Object Injection ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-94390 Patchstack
7.5 High WP Full Stripe Free Plugin wp-full-stripe-free Broken Access Control No login needed ≤ 8.5.6 Fixed in 8.5.7 CVE-2026-62073 Patchstack
7.6 High Ultimate Member Plugin ultimate-member SQL Injection ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-62059 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-62060 Patchstack
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
8.0 High Memberful - Membership Plugin memberful-wp Cross-Site Request Forgery Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) ≤ 1.81.0 Fixed in 1.81.1 CVE-2026-103067 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter No login needed ≤ 1.57.2 CVE-2026-92144 Wordfence
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields No login needed ≤ 1.15.47 CVE-2026-96813 Wordfence
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint ≤ 2.0.0 CVE-2026-95687 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field No login needed ≤ 1.57.2 CVE-2026-85235 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields No login needed ≤ 5.16.1 CVE-2026-92244 Wordfence
8.1 High Super Forms Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter ≤ 6.3.316 CVE-2026-15983 Wordfence
7.2 High Autoptimize Plugin autoptimize Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path No login needed ≤ 3.1.15.1 CVE-2026-14995 Wordfence
8.8 High ByteCoreStack Plugin bcs-mcp-manager Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool ≤ 1.2.3 CVE-2026-19807 Wordfence
7.5 High LearnPress Plugin learnpress Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter No login needed ≤ 4.4.8 CVE-2026-93882 Wordfence
7.5 High Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Payment Gateway Credentials Disclosure via Debug Log No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96255 WPScan
7.1 High Five Star Restaurant Reviews Plugin good-reviews-wp Cross-Site Scripting Reflected XSS No login needed < 2.3.14 Fixed in 2.3.14 CVE-2026-92412 WPScan
8.6 High Pro Like Button Plugin SQL Injection Unauthenticated SQLi via 'postid' Parameter No login needed < 2.0 Fixed in 2.0 CVE-2026-89296 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments SQL Injection Unauthenticated SQLi via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81809 WPScan
8.8 High Featured Image from URL (FIFU) Free & Premium Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed 6.0.0 – < 6.0.8, 6.8.0 – < 8.2.8 Fixed in 6.0.8 CVE-2026-101147 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments Cross-Site Scripting Unauthenticated Stored XSS via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81739 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only