WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 951–1,000 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Do Lasso Plugin lasso Cross-Site Scripting No login needed ≤ 358 CVE-2026-28158 Patchstack
7.5 High Do Lasso Plugin lasso Path Traversal ≤ 358 CVE-2026-28157 Patchstack
8.5 High Do Lasso Plugin lasso SQL Injection ≤ 358 CVE-2026-28156 Patchstack
7.1 High Business Directory Plugin business-directory-plugin Cross-Site Scripting No login needed ≤ 6.4.25 Fixed in 6.4.26 CVE-2026-28004 Patchstack
7.1 High Maspik – Spam blacklist Plugin contact-forms-anti-spam Cross-Site Scripting Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-28003 Patchstack
8.1 High MStore API Plugin mstore-api Privilege Escalation No login needed ≤ 4.20.0 Fixed in 4.21.0 CVE-2026-27543 Patchstack
7.1 High Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting No login needed ≤ 2.11.31 Fixed in 2.11.32 CVE-2026-27539 Patchstack
7.5 High WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-27538 Patchstack
7.1 High MailChimp Subscribe Forms Plugin mailchimp-subscribe-sm Cross-Site Scripting No login needed ≤ 4.3.3 Fixed in 4.3.4 CVE-2026-27536 Patchstack
7.1 High Solace Extra Plugin solace-extra Broken Access Control ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-27535 Patchstack
7.2 High Car Rental Manager Plugin car-rental-manager PHP Object Injection ≤ 1.3.9 Fixed in 1.4.0 CVE-2026-27380 Patchstack
7.5 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.5 CVE-2026-27345 Patchstack
7.2 High Fluent Forms Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values No login needed ≤ 6.2.11 CVE-2026-18146 Wordfence
8.2 High WP Helper Premium Plugin wp-helper-lite Information Disclosure Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation No login needed < 4.7.6 Fixed in 4.7.6 CVE-2026-18945 WPScan
7.5 High KiviCare Plugin kivicare-clinic-management-system Privilege Escalation Unauthenticated Privilege Escalation via Registration No login needed < 4.5.2 Fixed in 4.5.2 CVE-2026-13610 WPScan
7.5 High Ezoic Plugin ezoic-integration Broken Access Control Unauthenticated Database Export via Content Export REST Routes No login needed 2.6.35 – < 2.23.1 Fixed in 2.23.1 CVE-2026-18789 WPScan
8.6 High WP Directory Kit Plugin wpdirectorykit SQL Injection Unauthenticated SQL Injection via search_location and search_category No login needed < 1.5.6 Fixed in 1.5.6 CVE-2026-18474 WPScan
8.1 High WP Directory Kit Plugin wpdirectorykit SQL Injection Subscriber+ SQL Injection via section Parameter < 1.5.6 Fixed in 1.5.6 CVE-2026-18230 WPScan
8.1 High Events Manager Plugin events-manager SQL Injection Subscriber+ Booking Consent Record Tampering via SQL Injection < 7.4.1 Fixed in 7.4.1 CVE-2026-18057 WPScan
7.5 High WP Photo Album Plus Plugin wp-photo-album-plus Information Disclosure Unauthenticated Option Disclosure via gettogo No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-18049 WPScan
7.5 High WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Deletion Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-18048 WPScan
8.1 High Form Maker by 10Web Plugin form-maker SQL Injection Subscriber+ SQL Injection via display_name < 1.15.45 Fixed in 1.15.45 CVE-2026-16977 WPScan
7.1 High Blubrry PowerPress Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL < 11.17.1 Fixed in 11.17.1 CVE-2026-16294 WPScan
7.5 High Total Upkeep Plugin boldgrid-backup Information Disclosure Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret No login needed < 1.17.3 Fixed in 1.17.3 CVE-2026-16253 WPScan
7.5 High Import WP Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Export File Download No login needed < 2.14.23 Fixed in 2.14.23 CVE-2026-14925 WPScan
8.8 High KiviCare Plugin kivicare-clinic-management-system SQL Injection Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint < 4.5.2 Fixed in 4.5.2 CVE-2026-13613 WPScan
8.2 High Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Account Creation via Waiting List Endpoint No login needed < 4.1.20 Fixed in 4.1.20 CVE-2026-13171 WPScan
8.1 High Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect Plugin ventraconnect-social-login Authentication Bypass Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback No login needed ≤ 1.4.3 CVE-2026-18961 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token ≤ 3.29.9 CVE-2026-15606 Wordfence
8.1 High GeoDirectory Plugin geodirectory Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision ≤ 2.8.169 CVE-2026-19091 Wordfence
7.5 High InstaWP Connect Plugin instawp-connect Information Disclosure Unauthenticated Cryptographic Key Disclosure No login needed ≤ 0.1.3.6 CVE-2026-13457 Wordfence
8.8 High AcyMailing Plugin acymailing Broken Access Control Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update ≤ 10.11.1 CVE-2026-15426 Wordfence
8.8 High CheckView Plugin checkview Authentication Bypass Administrator Account Creation via REST API Authentication Bypass No login needed 2.0.29 – < 2.3.2 Fixed in 2.3.2 CVE-2026-18786 WPScan
8.8 High Autopay / Blue Media for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-14293 WPScan
7.2 High Vitepos Plugin vitepos-lite Privilege Escalation Outlet Manager+ Privilege Escalation 3.4.0 – < 3.6.0, < 3.5.0 Fixed in 3.6.0 CVE-2026-14237 WPScan
8.6 High ProSolution WP Client Plugin prosolution-wp-client SQL Injection Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie No login needed < 2.0.9 Fixed in 2.0.9 CVE-2026-19049 WPScan
7.5 High Salon Booking System – Free Version Plugin Information Disclosure Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard No login needed < 10.30.34 Fixed in 10.30.34 CVE-2026-17022 WPScan
7.5 High Contact Form to Any API Plugin contact-form-to-any-api Information Disclosure Unauthenticated Sensitive File Disclosure via Predictable Filename No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-18946 WPScan
8.8 High Squeeze Plugin squeeze Arbitrary File Upload Author+ Arbitrary File Upload < 1.7.12 Fixed in 1.7.12 CVE-2026-16985 WPScan
7.5 High HT Contact Form Plugin ht-contactform Information Disclosure Unauthenticated Saved Form Draft Data Disclosure No login needed < 2.9.3 Fixed in 2.9.3 CVE-2026-14206 WPScan
8.1 High AutoNetTV Relay Plugin autonettv-relay Privilege Escalation Unauthenticated Privilege Escalation via Scheduled Sync Cron No login needed < 3.0.14 Fixed in 3.0.14 CVE-2026-13600 WPScan
7.2 High Eventin Plugin wp-event-solution Local File Inclusion Editor+ Local File Inclusion via speaker_template Setting < 4.1.20 Fixed in 4.1.20 CVE-2026-13170 WPScan
7.5 High Login & Register Forms Plugin Information Disclosure Unauthenticated Registered User Email Address Disclosure via Lost Password Response No login needed 3.0.0 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18470 WPScan
8.1 High Login & Register Forms Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Code Brute Force No login needed 3.2.5 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18469 WPScan
8.1 High Login & Register Forms Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header No login needed 3.2.5 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18468 WPScan
8.1 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed < 3.1.8.8 Fixed in 3.1.8.8 CVE-2026-18030 WPScan
8.2 High Arvow AI SEO Writer Plugin journalist-ai Authentication Bypass Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling No login needed < 1.5.4 Fixed in 1.5.4 CVE-2026-16257 WPScan
7.5 High Bit File Manager Plugin Information Disclosure Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector No login needed < 6.9.1 Fixed in 6.9.1 CVE-2026-17542 WPScan
7.5 High Bit File Manager Plugin Information Disclosure Unauthenticated File Activity Log Disclosure No login needed < 6.9.1 Fixed in 6.9.1 CVE-2026-17541 WPScan
8.8 High Bit File Manager Plugin Path Traversal Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch < 6.9.1 Fixed in 6.9.1 CVE-2026-17540 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only