WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 951–1,000 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium RestroPress Plugin restropress Broken Access Control Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery No login needed ≤ 3.4.6 CVE-2026-85009 WPScan
3.8 Low King Addons for Elementor Plugin king-addons Broken Access Control Author+ Missing Authorization via Image Optimizer 51.1.56 – < 51.1.81 Fixed in 51.1.81 CVE-2026-84904 WPScan
2.7 Low King Addons for Elementor Plugin king-addons Information Disclosure Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode < 51.1.81 Fixed in 51.1.81 CVE-2026-84903 WPScan
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Template Catalog Import < 51.1.81 Fixed in 51.1.81 CVE-2026-84902 WPScan
9.1 Critical AF Companion Plugin af-companion Arbitrary File Upload Shop Manager+ Arbitrary File Upload to RCE < 2.2.0 Fixed in 2.2.0 CVE-2026-84738 WPScan
7.2 High All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Privilege Escalation Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure < 7.111 Fixed in 7.111 CVE-2026-81810 WPScan
3.8 Low MasterStudy LMS Plugin Broken Access Control Instructor+ Order Status Manipulation via IDOR < 3.7.50 Fixed in 3.7.50 CVE-2026-81340 WPScan
7.1 High WordPress Core Cross-Site Scripting Unauth. Cross Site Scripting (XSS) No login needed 7.1 – < 7.1.1, 7.0 – 7.0.4, 6.9 – 6.9.7, … Fixed in 7.1.1 CVE-2026-93485 Patchstack
8.8 High ShortPixel Image Optimizer Plugin shortpixel-image-optimiser PHP Object Injection Authenticated (Author+) PHP Object Injection via Nested JSON Post Content ≤ 6.5.5 CVE-2026-17086 Wordfence
5.4 Medium Biggopti Library (Various Versions) Plugin bdthemes-element-pack-lite Cross-Site Scripting Cross-Site Scripting via display_id from Sigmative API No login needed ≤ 1.5.6, ≤ 2.1.14, ≤ 2.2.0, … CVE-2026-92991 Wordfence
6.4 Medium RT Mega Menu Plugin rt-mega-menu Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action ≤ 1.5.1 CVE-2026-14855 Wordfence
6.4 Medium RT Mega Menu Plugin rt-mega-menu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute ≤ 1.5.2 CVE-2026-15650 Wordfence
4.3 Medium LatePoint - Appointment Booking & Scheduling Plugin latepoint Broken Access Control Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter ≤ 5.6.9 CVE-2026-18441 Wordfence
6.4 Medium Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter ≤ 2.8.14 CVE-2026-2585 Wordfence
5.3 Medium Booking for Appointments and Events Calendar - Amelia Plugin Broken Access Control Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass No login needed ≤ 2.4.5 CVE-2026-16582 Wordfence
5.4 Medium Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Broken Access Control Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover ≤ 2.4.4 CVE-2026-14311 Wordfence
5.3 Medium Motors – Car Dealership & Classified Listings Plugin Broken Access Control Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure No login needed ≤ 1.4.120 CVE-2026-16750 Wordfence
8.8 High faustjs Plugin Authentication Bypass FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope < 1.8.11 CVE-2026-54239 GitHub_M
7.1 High WP Inventory Manager Plugin wp-inventory-manager Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2026-90887 Patchstack
5.3 Medium BerqWP Plugin searchpro Broken Access Control No login needed ≤ 4.1.15 Fixed in 4.1.16 CVE-2026-78528 Patchstack
8.8 High Xagio SEO Plugin xagio-seo Cross-Site Request Forgery No login needed ≤ 7.1.0.43 Fixed in 7.1.0.44 CVE-2026-78295 Patchstack
6.5 Medium Geo Mashup Plugin geo-mashup Cross-Site Scripting ≤ 1.13.21 Fixed in 1.13.22 CVE-2026-78294 Patchstack
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.7 Fixed in 5.2.8 CVE-2026-74017 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-74005 Patchstack
5.3 Medium Booking Calendar Plugin booking Broken Access Control No login needed ≤ 11.7 Fixed in 11.8 CVE-2026-74002 Patchstack
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2026-74000 Patchstack
5.4 Medium Cooked Plugin cooked Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.16.0 Fixed in 1.16.1 CVE-2026-73999 Patchstack
5.3 Medium Easy Invoice Plugin easy-invoice Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.4.0 CVE-2026-66676 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.9.21 Fixed in 2.0.0 CVE-2026-66631 Patchstack
7.6 High PublishPress Series Plugin organize-series SQL Injection ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66630 Patchstack
7.6 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay SQL Injection ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-66628 Patchstack
7.6 High SKT Addons for Elementor Plugin skt-addons-for-elementor SQL Injection ≤ 4.0 Fixed in 4.1 CVE-2026-66626 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.7.2.1 Fixed in 2.7.2.2 CVE-2026-66625 Patchstack
7.6 High WPMasterToolKit Plugin wpmastertoolkit SQL Injection ≤ 2.22.0 Fixed in 2.23.1 CVE-2026-66624 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.18 Fixed in 4.18.1 CVE-2026-66619 Patchstack
7.6 High WP Maps Plugin wp-google-map-plugin SQL Injection ≤ 4.9.9 Fixed in 5.0.0 CVE-2026-66618 Patchstack
6.5 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66617 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
8.5 High Product Feed Manager Plugin best-woocommerce-feed SQL Injection ≤ 7.12.0 Fixed in 7.12.1 CVE-2026-66580 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.2.6 Fixed in 2.3.0 CVE-2026-66578 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.3.1 CVE-2026-66577 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.3.3.1 Fixed in 2.3.3.2 CVE-2026-66573 Patchstack
6.5 Medium JetBlog Plugin jet-blog Cross-Site Scripting ≤ 2.4.10 Fixed in 2.4.10.1 CVE-2026-66572 Patchstack
7.1 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Request Forgery No login needed ≤ 1.4.0.5 Fixed in 1.4.0.6 CVE-2026-66571 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-62108 Patchstack
10.0 Critical Migratico Lite Plugin migratico-lite Remote Code Execution No login needed ≤ 2.6.8 Fixed in 2.7.1 CVE-2026-62104 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only