WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 51–100 of 328 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 2.7 Low | Eventin | Broken Access Control Contributor+ User Creation via Speaker Creation |
< 4.1.24 Fixed in 4.1.24 |
CVE-2026-84905 |
WPScan | |
| 2.7 Low | Schema & Structured Data for WP & AMP | Information Disclosure Contributor+ Non-Public Post Content Disclosure via AI Schema Generation |
1.63 – < 1.66 Fixed in 1.66 |
CVE-2026-82126 |
WPScan | |
| 2.7 Low | WP Directory Kit | Information Disclosure Contributor+ Non-Public Listing Field Disclosure via Shortcodes |
≤ 1.5.7 |
CVE-2026-16592 |
WPScan | |
| 3.7 Low | User Registration & Membership | Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed |
5.0 – < 5.2.8 Fixed in 5.2.8 |
CVE-2026-86407 |
WPScan | |
| 2.2 Low | BEAR - Bulk Editor and Products Manager Professional for WooCommerce | Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR |
< 1.2.2 Fixed in 1.2.2 |
CVE-2026-84025 |
WPScan | |
| 2.7 Low | Masteriyo LMS | Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR |
1.14.0 – < 3.4.1 Fixed in 3.4.1 |
CVE-2026-82851 |
WPScan | |
| 2.7 Low | Visualizer | Broken Access Control Contributor+ Arbitrary Chart Deletion via deleteChart |
< 4.0.6 Fixed in 4.0.6 |
CVE-2026-86779 |
WPScan | |
| 3.5 Low | GTranslate | Cross-Site Scripting Admin+ Stored XSS |
< 3.0.10 Fixed in 3.0.10 |
CVE-2025-15695 |
WPScan | |
| 3.7 Low | WP Travel | Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed |
< 12.0.2 Fixed in 12.0.2 |
CVE-2026-13146 |
WPScan | |
| 3.7 Low | WP Travel | Broken Access Control Unauthenticated Arbitrary Booking Payment Reset No login needed |
< 12.0.2 Fixed in 12.0.2 |
CVE-2026-13144 |
WPScan | |
| 2.7 Low | EmbedPress | Broken Access Control Contributor+ Google Reviews Modification |
4.6.0 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-84927 |
WPScan | |
| 2.7 Low | EmbedPress | Information Disclosure Contributor+ Administrator Email Disclosure via Google Reviews REST Route |
4.6.0 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-84926 |
WPScan | |
| 2.7 Low | The Events Calendar | Information Disclosure Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API |
< 6.17.3.1 Fixed in 6.17.3.1 |
CVE-2026-84745 |
WPScan | |
| 2.2 Low | Kirki | Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR |
6.0.0 – < 6.3.0 Fixed in 6.3.0 |
CVE-2026-84225 |
WPScan | |
| 3.7 Low | My Private Site | Information Disclosure Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap No login needed |
< 4.2.3 Fixed in 4.2.3 |
CVE-2026-81348 |
WPScan | |
| 2.7 Low | Post Carousel | Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR |
4.0.0 – < 4.0.8 Fixed in 4.0.8 |
CVE-2026-78150 |
WPScan | |
| 3.5 Low | Joli Table Of Contents | Cross-Site Scripting Admin+ Stored XSS |
2.0.0 – < 2.8.1 Fixed in 2.8.1 |
CVE-2025-15694 |
WPScan | |
| 2.7 Low | JCH Optimize | Path Traversal Admin+ Path Traversal |
4.2.1 – < 5.0.1 Fixed in 5.0.1 |
CVE-2025-15693 |
WPScan | |
| 3.1 Low | Directorist | Broken Access Control Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload |
< 8.9 Fixed in 8.9 |
CVE-2026-84066 |
WPScan | |
| 3.3 Low | Weaver Show Posts | PHP Object Injection Admin+ PHP Object Injection |
< 1.8.1 Fixed in 1.8.1 |
CVE-2023-3360 |
WPScan | |
| 3.5 Low | GutenKit | Content Injection Contributor+ Stored CSS Injection |
< 2.5.1 Fixed in 2.5.1 |
CVE-2026-19698 |
WPScan | |
| 3.8 Low | Timetics | Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR |
≤ 1.0.61 |
CVE-2026-14326 |
WPScan | |
| 3.5 Low | Icegram Express | Cross-Site Scripting Admin+ Stored XSS |
< 5.8.6 Fixed in 5.8.6 |
CVE-2025-15692 |
WPScan | |
| 3.8 Low | MasterStudy LMS | Broken Access Control Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR |
< 3.7.46 Fixed in 3.7.46 |
CVE-2026-81198 |
WPScan | |
| 2.7 Low | MasterStudy LMS | Information Disclosure Instructor+ Quiz Answer Disclosure via IDOR |
< 3.7.46 Fixed in 3.7.46 |
CVE-2026-81196 |
WPScan | |
| 2.7 Low | Rank Math SEO | Broken Access Control Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk |
1.0.255 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77787 |
WPScan | |
| 2.7 Low | Rank Math SEO | Information Disclosure Author+ Non-Public Post Content Disclosure via Abilities API |
1.0.272 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77785 |
WPScan | |
| 2.7 Low | Rank Math SEO | Broken Access Control Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as |
< 1.0.277 Fixed in 1.0.277 |
CVE-2026-77784 |
WPScan | |
| 3.7 Low | Rank Math SEO | Information Disclosure Unauthenticated Non-Public Post Schema and Content Disclosure No login needed |
1.0.48 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77783 |
WPScan | |
| 3.5 Low | MW WP Form | Cross-Site Scripting Editor+ Stored XSS via Inquiry Data List |
< 5.1.6 Fixed in 5.1.6 |
CVE-2026-78364 |
WPScan | |
| 2.7 Low | MasterStudy LMS | Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR |
< 3.7.42 Fixed in 3.7.42 |
CVE-2026-81200 |
WPScan | |
| 2.7 Low | Amelia | Broken Access Control Amelia Customer+ Appointment Status Update and Self-Approval |
1.2.32 – < 2.4.9 Fixed in 2.4.9 |
CVE-2026-77704 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-79615 |
WPScan | |
| 3.5 Low | CMP - Coming Soon & Maintenance | Cross-Site Scripting Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia |
< 4.1.18 Fixed in 4.1.18 |
CVE-2026-13416 |
WPScan | |
| 3.7 Low | Forminator Forms | Privilege Escalation Unauthenticated Multisite Site Creation and Privilege Escalation No login needed |
< 1.57.1 Fixed in 1.57.1 |
CVE-2026-19220 |
WPScan | |
| 2.7 Low | Content Mask | Privilege Escalation Contributor Publish Capability Bypass via create_new_content_mask |
1.8.0 – < 1.8.5.5 Fixed in 1.8.5.5 |
CVE-2026-77003 |
WPScan | |
| 2.7 Low | Tutor LMS | Information Disclosure Instructor+ Cross-Instructor Private Course Disclosure via IDOR |
< 4.0.6 Fixed in 4.0.6 |
CVE-2026-14187 |
WPScan | |
| 3.7 Low | Limit Login Attempts Reloaded | Other Username Denylist Bypass via Case Variant and Account Email No login needed |
< 3.3.5 Fixed in 3.3.5 |
CVE-2026-18356 |
WPScan | |
| 2.7 Low | Eventin | Server-Side Request Forgery Contributor+ Server-Side Request Forgery |
< 4.1.21 Fixed in 4.1.21 |
CVE-2026-13176 |
WPScan | |
| 2.7 Low | Copy & Delete Posts | Information Disclosure Authenticated Arbitrary Post Content and Password Disclosure |
< 1.5.6 Fixed in 1.5.6 |
CVE-2026-19435 |
WPScan | |
| 2.7 Low | Copy & Delete Posts | Information Disclosure Author+ Password-Protected Post Content Disclosure |
< 1.5.6 Fixed in 1.5.6 |
CVE-2026-19085 |
WPScan | |
| 2.7 Low | Dokan | Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount |
< 5.0.14 Fixed in 5.0.14 |
CVE-2026-16577 |
WPScan | |
| 3.5 Low | Drag and Drop Multiple File Upload for Contact Form 7 | Arbitrary File Upload Admin+ Stored XSS via drag_n_drop_heading_tag Setting |
< 1.3.9.9 Fixed in 1.3.9.9 |
CVE-2026-14325 |
WPScan | |
| 2.7 Low | GutenKit | Information Disclosure Contributor+ Mailchimp Audience Data Disclosure |
2.4.12 – < 2.5.0 Fixed in 2.5.0 |
CVE-2026-19699 |
WPScan | |
| 2.7 Low | Easy Appointments | Information Disclosure Contributor+ Sensitive Information Disclosure via REST Appointments Listing |
3.12.28 – < 4.0.1 Fixed in 4.0.1 |
CVE-2026-19406 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-14826 |
WPScan | |
| 2.7 Low | Quiz And Survey Master | Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR |
< 11.2.4 Fixed in 11.2.4 |
CVE-2026-14825 |
WPScan | |
| 2.7 Low | Eventin | Broken Access Control Contributor+ User Role and Meta Modification via Speaker Creation |
< 4.1.21 Fixed in 4.1.21 |
CVE-2026-13173 |
WPScan | |
| 3.7 Low | Amelia | Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed |
< 2.4.6 Fixed in 2.4.6 |
CVE-2026-14213 |
WPScan | |
| 3.7 Low | Estatik Real Estate | Other Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch No login needed |
< 4.3.4 Fixed in 4.3.4 |
CVE-2026-18044 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.