WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 51–100 of 17,624 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Advanced Ads Plugin advanced-ads Information Disclosure Sensitive Data Exposure ≤ 2.0.26 CVE-2026-94180 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.71 CVE-2026-94405 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key No login needed ≤ 14.16.14 CVE-2026-97652 Wordfence
6.1 Medium All in One SEO Plugin all-in-one-seo-pack Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL Pathname No login needed ≤ 5.0.1.1 CVE-2026-85492 Wordfence
5.3 Medium Appointment Booking Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter No login needed ≤ 5.7.1 CVE-2026-94432 Wordfence
6.5 Medium Event Tickets and Registration Plugin event-tickets SQL Injection Authenticated (Contributor+) SQL Injection via 'orderby' Parameter ≤ 5.29.5 CVE-2026-97634 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name ≤ 3.3.70 CVE-2026-97338 Wordfence
6.4 Medium Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter ≤ 6.1.1 CVE-2026-96647 Wordfence
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor SQL Injection Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter ≤ 5.0.18 CVE-2026-12951 Wordfence
6.1 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder No login needed ≤ 13.2.0 CVE-2026-93880 Wordfence
4.3 Medium MStore API Plugin mstore-api Price Manipulation Subscriber+ Payment Bypass via 'status' Parameter 4.21.1 – < 4.22.1 Fixed in 4.22.1 CVE-2026-97219 WPScan
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
5.3 Medium WebToffee Gift Cards for WooCommerce Plugin wt-gift-cards-woocommerce Price Manipulation Unauthenticated Gift Card Amount Manipulation via wt_credit_amount No login needed < 1.3.1 Fixed in 1.3.1 CVE-2026-91020 WPScan
5.3 Medium Easy PayPal & Stripe Buy Now Button Plugin wp-ecommerce-paypal Price Manipulation Unauthenticated Payment Amount Manipulation via Client-Supplied Price No login needed 1.8 – < 2.0.6 Fixed in 2.0.6 CVE-2026-90987 WPScan
5.3 Medium WP Edit Password Protected Plugin Broken Access Control Unauthenticated Site-Wide Access Mode Bypass via REST API No login needed 2.0.0 – < 2.0.7 Fixed in 2.0.7 CVE-2026-90952 WPScan
5.4 Medium Popup Maker WP Plugin Broken Access Control Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization 1.2.2.1 – 1.4.5 CVE-2026-85005 WPScan
6.5 Medium The Events Calendar Plugin the-events-calendar Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter No login needed 6.12.0 – < 6.17.5.1 Fixed in 6.17.5.1 CVE-2026-84740 WPScan
4.3 Medium WP User Frontend Plugin Broken Access Control Subscriber+ Post Creation via Subscription-Gated Form < 4.3.12 Fixed in 4.3.12 CVE-2026-79618 WPScan
5.3 Medium CMP - Coming Soon & Maintenance Plugin Broken Access Control Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match No login needed < 4.1.20 Fixed in 4.1.20 CVE-2026-13413 WPScan
4.3 Medium WP Mail Logging Plugin wp-mail-logging Content Injection Unauthenticated HTML Injection No login needed < 1.17.0 Fixed in 1.17.0 CVE-2026-1661 WPScan
6.1 Medium Giveaways and Contests by RafflePress Plugin rafflepress Open Redirect Unauthenticated Stored Open Redirect via 'parent_url' Parameter No login needed < 1.12.27 Fixed in 1.12.27 CVE-2026-97318 WPScan
5.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Information Disclosure Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page No login needed < 1.12.27 Fixed in 1.12.27 CVE-2026-97317 WPScan
6.2 Medium BuildKit Plugin woo-product-builder SQL Injection Contributor+ Stored SQLi via list_content Parameter < 1.0.29 Fixed in 1.0.29 CVE-2026-94298 WPScan
6.8 Medium Motors Plugin motors-car-dealership-classified-listings Cross-Site Scripting Listing Manager+ Stored XSS via Badge Color < 1.4.124 Fixed in 1.4.124 CVE-2026-91022 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Icon Library Parameter < 2.0.21 Fixed in 2.0.21 CVE-2026-85016 WPScan
5.3 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Information Disclosure Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum No login needed ≤ 2.5.6 CVE-2026-90988 WPScan
4.3 Medium Popup Maker WP Plugin Broken Access Control Subscriber+ Missing Authorization via sgpm_connect ≤ 1.4.5 CVE-2026-85004 WPScan
5.3 Medium Paytm Payment Gateway Plugin paytm-payments Authentication Bypass Unauthenticated Order Status Manipulation via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81740 WPScan
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
5.4 Medium Autoptimize Plugin autoptimize Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 3.1.15.1 CVE-2026-78471 Wordfence
6.1 Medium Avada | Website Builder For WordPress & WooCommerce Theme Cross-Site Scripting Reflected Cross-Site Scripting via 'lang' Parameter No login needed ≤ 7.16.1 CVE-2026-84925 Wordfence
5.4 Medium Prime Mover Plugin prime-mover Cross-Site Scripting Prime Mover < 2.2.1 Stored XSS via Package Metadata < 2.2.1 Fixed in 2.2.1 CVE-2026-101890 VulnCheck
6.5 Medium Prime Mover Plugin prime-mover Path Traversal Prime Mover < 2.2.1 Path Traversal via wprime-config.json < 2.2.1 Fixed in 2.2.1 CVE-2026-101889 VulnCheck
6.5 Medium Review Schema Plugin review-schema Broken Access Control No login needed 3.1.0 CVE-2026-97280 Patchstack
5.3 Medium hCaptcha for WP Plugin hcaptcha-for-forms-and-more Authentication Bypass Bypass Vulnerability No login needed ≤ 5.3.0 Fixed in 5.4.0 CVE-2026-103347 Patchstack
6.3 Medium WP Project Manager Plugin wedevs-project-manager Broken Access Control ≤ 4.0.7 Fixed in 4.1.0 CVE-2026-97281 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-97269 Patchstack
6.5 Medium Aruba Migration Tool Plugin aruba-wp-migration-tool Broken Access Control ≤ 1.0.4 Fixed in 1.0.5 CVE-2026-97258 Patchstack
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
5.3 Medium CF7 Apps Plugin contact-form-7-honeypot Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 Fixed in 3.8.0 CVE-2026-62058 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
5.4 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-62063 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.8.4 Fixed in 6.8.5 CVE-2026-102394 Patchstack
6.5 Medium Metform Plugin metform Cross-Site Scripting ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-103339 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103063 Patchstack
5.3 Medium Pie Register Plugin pie-register Information Disclosure Sensitive Data Exposure No login needed ≤ 3.8.4.13 Fixed in 3.8.4.14 CVE-2026-103345 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103064 Patchstack
5.3 Medium AFFI – Affiliate Marketing for WooCommerce Plugin affi-affiliate-marketing-for-woo Broken Access Control Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2026-102390 Patchstack
4.3 Medium Majestic Support Plugin majestic-support Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102382 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102381 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only