WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 51–100 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
2.7 Low Eventin Plugin wp-event-solution Broken Access Control Contributor+ User Creation via Speaker Creation < 4.1.24 Fixed in 4.1.24 CVE-2026-84905 WPScan
2.7 Low Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Contributor+ Non-Public Post Content Disclosure via AI Schema Generation 1.63 – < 1.66 Fixed in 1.66 CVE-2026-82126 WPScan
2.7 Low WP Directory Kit Plugin wpdirectorykit Information Disclosure Contributor+ Non-Public Listing Field Disclosure via Shortcodes ≤ 1.5.7 CVE-2026-16592 WPScan
3.7 Low User Registration & Membership Plugin user-registration Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed 5.0 – < 5.2.8 Fixed in 5.2.8 CVE-2026-86407 WPScan
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
2.7 Low Masteriyo LMS Plugin learning-management-system Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR 1.14.0 – < 3.4.1 Fixed in 3.4.1 CVE-2026-82851 WPScan
2.7 Low Visualizer Plugin visualizer Broken Access Control Contributor+ Arbitrary Chart Deletion via deleteChart < 4.0.6 Fixed in 4.0.6 CVE-2026-86779 WPScan
3.5 Low GTranslate Plugin Cross-Site Scripting Admin+ Stored XSS < 3.0.10 Fixed in 3.0.10 CVE-2025-15695 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13146 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Payment Reset No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13144 WPScan
2.7 Low EmbedPress Plugin embedpress Broken Access Control Contributor+ Google Reviews Modification 4.6.0 – < 4.6.4 Fixed in 4.6.4 CVE-2026-84927 WPScan
2.7 Low EmbedPress Plugin embedpress Information Disclosure Contributor+ Administrator Email Disclosure via Google Reviews REST Route 4.6.0 – < 4.6.4 Fixed in 4.6.4 CVE-2026-84926 WPScan
2.7 Low The Events Calendar Plugin the-events-calendar Information Disclosure Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API < 6.17.3.1 Fixed in 6.17.3.1 CVE-2026-84745 WPScan
2.2 Low Kirki Plugin kirki Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84225 WPScan
3.7 Low My Private Site Plugin jonradio-private-site Information Disclosure Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap No login needed < 4.2.3 Fixed in 4.2.3 CVE-2026-81348 WPScan
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
3.5 Low Joli Table Of Contents Plugin joli-table-of-contents Cross-Site Scripting Admin+ Stored XSS 2.0.0 – < 2.8.1 Fixed in 2.8.1 CVE-2025-15694 WPScan
2.7 Low JCH Optimize Plugin jch-optimize Path Traversal Admin+ Path Traversal 4.2.1 – < 5.0.1 Fixed in 5.0.1 CVE-2025-15693 WPScan
3.1 Low Directorist Plugin directorist-wpml-integration Broken Access Control Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload < 8.9 Fixed in 8.9 CVE-2026-84066 WPScan
3.3 Low Weaver Show Posts Plugin show-posts PHP Object Injection Admin+ PHP Object Injection < 1.8.1 Fixed in 1.8.1 CVE-2023-3360 WPScan
3.5 Low GutenKit Plugin gutenkit-blocks-addon Content Injection Contributor+ Stored CSS Injection < 2.5.1 Fixed in 2.5.1 CVE-2026-19698 WPScan
3.8 Low Timetics Plugin timetics Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR ≤ 1.0.61 CVE-2026-14326 WPScan
3.5 Low Icegram Express Plugin Cross-Site Scripting Admin+ Stored XSS < 5.8.6 Fixed in 5.8.6 CVE-2025-15692 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81198 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Quiz Answer Disclosure via IDOR < 3.7.46 Fixed in 3.7.46 CVE-2026-81196 WPScan
2.7 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk 1.0.255 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77787 WPScan
2.7 Low Rank Math SEO Plugin seo-by-rank-math Information Disclosure Author+ Non-Public Post Content Disclosure via Abilities API 1.0.272 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77785 WPScan
2.7 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as < 1.0.277 Fixed in 1.0.277 CVE-2026-77784 WPScan
3.7 Low Rank Math SEO Plugin seo-by-rank-math Information Disclosure Unauthenticated Non-Public Post Schema and Content Disclosure No login needed 1.0.48 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77783 WPScan
3.5 Low MW WP Form Plugin mw-wp-form Cross-Site Scripting Editor+ Stored XSS via Inquiry Data List < 5.1.6 Fixed in 5.1.6 CVE-2026-78364 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR < 3.7.42 Fixed in 3.7.42 CVE-2026-81200 WPScan
2.7 Low Amelia Plugin Broken Access Control Amelia Customer+ Appointment Status Update and Self-Approval 1.2.32 – < 2.4.9 Fixed in 2.4.9 CVE-2026-77704 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-79615 WPScan
3.5 Low CMP - Coming Soon & Maintenance Plugin Cross-Site Scripting Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia < 4.1.18 Fixed in 4.1.18 CVE-2026-13416 WPScan
3.7 Low Forminator Forms Plugin forminator Privilege Escalation Unauthenticated Multisite Site Creation and Privilege Escalation No login needed < 1.57.1 Fixed in 1.57.1 CVE-2026-19220 WPScan
2.7 Low Content Mask Plugin content-mask Privilege Escalation Contributor Publish Capability Bypass via create_new_content_mask 1.8.0 – < 1.8.5.5 Fixed in 1.8.5.5 CVE-2026-77003 WPScan
2.7 Low Tutor LMS Plugin tutor Information Disclosure Instructor+ Cross-Instructor Private Course Disclosure via IDOR < 4.0.6 Fixed in 4.0.6 CVE-2026-14187 WPScan
3.7 Low Limit Login Attempts Reloaded Plugin Other Username Denylist Bypass via Case Variant and Account Email No login needed < 3.3.5 Fixed in 3.3.5 CVE-2026-18356 WPScan
2.7 Low Eventin Plugin wp-event-solution Server-Side Request Forgery Contributor+ Server-Side Request Forgery < 4.1.21 Fixed in 4.1.21 CVE-2026-13176 WPScan
2.7 Low Copy & Delete Posts Plugin Information Disclosure Authenticated Arbitrary Post Content and Password Disclosure < 1.5.6 Fixed in 1.5.6 CVE-2026-19435 WPScan
2.7 Low Copy & Delete Posts Plugin Information Disclosure Author+ Password-Protected Post Content Disclosure < 1.5.6 Fixed in 1.5.6 CVE-2026-19085 WPScan
2.7 Low Dokan Plugin Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount < 5.0.14 Fixed in 5.0.14 CVE-2026-16577 WPScan
3.5 Low Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Admin+ Stored XSS via drag_n_drop_heading_tag Setting < 1.3.9.9 Fixed in 1.3.9.9 CVE-2026-14325 WPScan
2.7 Low GutenKit Plugin gutenkit-blocks-addon Information Disclosure Contributor+ Mailchimp Audience Data Disclosure 2.4.12 – < 2.5.0 Fixed in 2.5.0 CVE-2026-19699 WPScan
2.7 Low Easy Appointments Plugin easy-appointments Information Disclosure Contributor+ Sensitive Information Disclosure via REST Appointments Listing 3.12.28 – < 4.0.1 Fixed in 4.0.1 CVE-2026-19406 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
2.7 Low Eventin Plugin wp-event-solution Broken Access Control Contributor+ User Role and Meta Modification via Speaker Creation < 4.1.21 Fixed in 4.1.21 CVE-2026-13173 WPScan
3.7 Low Amelia Plugin Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed < 2.4.6 Fixed in 2.4.6 CVE-2026-14213 WPScan
3.7 Low Estatik Real Estate Plugin Other Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch No login needed < 4.3.4 Fixed in 4.3.4 CVE-2026-18044 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only