WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 951–1,000 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2026-40778 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed ≤ 1.7.1056 Fixed in 1.7.1057 CVE-2026-40763 Patchstack
5.3 Medium Nelio AB Testing Plugin nelio-ab-testing Information Disclosure Sensitive Data Exposure No login needed ≤ 8.2.8 Fixed in 8.3.0 CVE-2026-40742 Patchstack
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
5.3 Medium COMPE Plugin compe-woo-compare-products Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-40737 Patchstack
6.5 Medium Categories Images Plugin categories-images Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2026-40734 Patchstack
5.3 Medium ThemeGrill Demo Importer Plugin themegrill-demo-importer Broken Access Control No login needed ≤ 2.0.0.6 Fixed in 2.0.0.7 CVE-2026-40730 Patchstack
4.3 Medium 3D viewer – Embed 3D Models Plugin 3d-viewer Broken Access Control Embed 3D Models plugin <= 1.8.5 - Broken Access Control ≤ 1.8.5 Fixed in 1.8.6 CVE-2026-40729 Patchstack
4.3 Medium Magazine Blocks Plugin magazine-blocks Broken Access Control ≤ 1.8.3 Fixed in 1.8.4 CVE-2026-40728 Patchstack
5.4 Medium Avada (Fusion) Builder Plugin Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution ≤ 3.15.1 CVE-2026-1509 Wordfence
6.1 Medium Royal WordPress Backup & Restore Plugin royal-backup-reset Cross-Site Scripting Reflected Cross-Site Scripting via 'wpr_pending_template' Parameter No login needed ≤ 1.0.16 CVE-2026-4305 Wordfence
6.1 Medium adivaha Travel Plugin adiaha-hotel Cross-Site Scripting WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile No login needed 2.3 CVE-2023-54358 VulnCheck
5.3 Medium Flipmart Theme flipmart Broken Access Control No login needed ≤ 2.8 CVE-2026-39716 Patchstack
5.3 Medium AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.5.5 CVE-2026-39715 Patchstack
5.3 Medium G5Plus April Theme g5plus-april Broken Access Control No login needed ≤ 6.8 CVE-2026-39714 Patchstack
5.3 Medium Mailercloud – Integrate webforms and synchronize website contacts Plugin mailercloud-integrate-webforms-synchronize-contacts Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 CVE-2026-39713 Patchstack
5.3 Medium tagDiv Composer Plugin td-composer Arbitrary Shortcode Execution No login needed ≤ 5.4.3 CVE-2026-39712 Patchstack
5.3 Medium RT-Theme 18 | Extensions Plugin rt18-extensions Information Disclosure Sensitive Data Exposure No login needed ≤ 2.5 CVE-2026-39711 Patchstack
5.4 Medium RT-Theme 18 | Extensions Plugin rt18-extensions Cross-Site Request Forgery No login needed ≤ 2.5 CVE-2026-39710 Patchstack
5.3 Medium The Tribal Plugin the-tech-tribe Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.4 CVE-2026-39709 Patchstack
6.5 Medium UiCore Elements Plugin uicore-elements Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2026-39708 Patchstack
5.3 Medium Accept PayPal Payments using Contact Form 7 Plugin contact-form-7-paypal-extension Broken Access Control No login needed ≤ 4.0.4 CVE-2026-39707 Patchstack
5.3 Medium Make My Trivia Plugin trivialy Broken Access Control No login needed ≤ 1.1.0 CVE-2026-39706 Patchstack
5.3 Medium MIPL WC Multisite Sync Plugin mipl-wc-multisite-sync Broken Access Control No login needed ≤ 1.4.4 CVE-2026-39705 Patchstack
5.3 Medium Precious Metals Automated Product Pricing – Pro Plugin precious-metals-automated-product-pricing-pro Broken Access Control Pro plugin <= 4.0.5 - Broken Access Control No login needed ≤ 4.0.5 CVE-2026-39704 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.8.1 CVE-2026-39703 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Cross-Site Scripting ≤ 2.6.1 CVE-2026-39702 Patchstack
5.3 Medium ShopWP Plugin wpshopify Broken Access Control No login needed ≤ 5.2.4 CVE-2026-39701 Patchstack
5.3 Medium WowOptin Plugin optin Broken Access Control No login needed ≤ 1.4.32 CVE-2026-39700 Patchstack
5.3 Medium AI Workflow Automation Plugin ai-workflow-automation-lite Broken Access Control No login needed ≤ 1.4.2 CVE-2026-39699 Patchstack
5.3 Medium The Publisher Desk ads.txt Plugin the-publisher-desk-ads-txt Broken Access Control No login needed ≤ 1.5.0 CVE-2026-39698 Patchstack
5.3 Medium MAIO – The new AI GEO / SEO tool Plugin maio-the-new-ai-geo-seo-tool Broken Access Control The new AI GEO / SEO tool plugin <= 6.2.8 - Broken Access Control No login needed ≤ 6.2.8 CVE-2026-39697 Patchstack
6.5 Medium Elfsight WhatsApp Chat CC Plugin elfsight-whatsapp-chat Cross-Site Scripting ≤ 1.2.0 CVE-2026-39696 Patchstack
5.4 Medium Podigee Plugin podigee Server-Side Request Forgery No login needed ≤ 1.4.0 CVE-2026-39695 Patchstack
5.3 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.10.2 CVE-2026-39694 Patchstack
5.9 Medium FSM Custom Featured Image Caption Plugin fsm-custom-featured-image-caption Cross-Site Scripting ≤ 1.25.1 CVE-2026-39693 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.3 CVE-2026-39692 Patchstack
5.3 Medium Cryptocurrency Donation Box – Bitcoin & Crypto Donations Plugin cryptocurrency-donation-box Broken Access Control Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control No login needed ≤ 2.2.13 CVE-2026-39691 Patchstack
5.3 Medium Author Avatars List/Block Plugin author-avatars Broken Access Control No login needed ≤ 2.1.25 CVE-2026-39690 Patchstack
5.3 Medium eShipper Commerce Plugin eshipper-commerce Broken Access Control No login needed ≤ 2.16.12 CVE-2026-39689 Patchstack
5.3 Medium WP Frontend Profile Plugin wp-front-end-profile Broken Access Control No login needed ≤ 1.3.9 CVE-2026-39688 Patchstack
5.3 Medium Rapid Car Check Vehicle Data Plugin free-vehicle-data-uk Broken Access Control No login needed ≤ 2.0 CVE-2026-39687 Patchstack
5.3 Medium BSK PDF Manager Plugin bsk-pdf-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 CVE-2026-39686 Patchstack
5.3 Medium The Moneytizer Plugin the-moneytizer Broken Access Control No login needed ≤ 10.0.10 CVE-2026-39685 Patchstack
5.9 Medium Garden Gnome Package Plugin garden-gnome-package Cross-Site Scripting ≤ 2.4.1 CVE-2026-39683 Patchstack
5.3 Medium linkPizza-Manager Plugin linkpizza-manager Broken Access Control No login needed ≤ 5.5.5 CVE-2026-39682 Patchstack
5.3 Medium Diet Calorie Calculator Plugin diet-calorie-calculator Broken Access Control No login needed ≤ 1.1.1 CVE-2026-39680 Patchstack
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
5.3 Medium Download Manager Plugin download-manager Broken Access Control No login needed ≤ 3.3.52 Fixed in 3.3.53 CVE-2026-39676 Patchstack
5.3 Medium Court Reservation Plugin court-reservation Broken Access Control No login needed ≤ 1.10.11 CVE-2026-39675 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only