WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 951–1,000 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
5.3 Medium bbPress Plugin bbpress Broken Access Control No login needed ≤ 2.6.14 CVE-2026-74010 Patchstack
5.3 Medium Icollect Plugin Broken Access Control Unauthenticated User and Term Creation via Unrestricted Method Dispatch No login needed ≤ 1.0.0 CVE-2026-77013 WPScan
6.6 Medium Really Simple Security Plugin really-simple-ssl Remote Code Execution Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin < 9.8.0 Fixed in 9.8.0 CVE-2026-81766 WPScan
6.6 Medium WPvivid Backup & Migration Plugin Path Traversal Admin+ Arbitrary File Write via Zip Slip in Backup Restore < 0.9.133 Fixed in 0.9.133 CVE-2026-19722 WPScan
6.8 Medium SOGO Add Script to Individual Pages Header Footer Plugin Cross-Site Scripting Contributor+ Stored XSS via Post Metabox ≤ 3.9 CVE-2026-14835 WPScan
4.3 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Subscriber+ Arbitrary Membership Plan Deletion < 3.29.11 Fixed in 3.29.11 CVE-2026-81346 WPScan
4.7 Medium MasterStudy LMS Plugin Open Redirect Unauthenticated Open Redirect No login needed < 3.7.43 Fixed in 3.7.43 CVE-2026-81342 WPScan
4.8 Medium MasterStudy LMS Plugin Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed < 3.7.40 Fixed in 3.7.40 CVE-2026-81026 WPScan
4.1 Medium WP Ultimate CSV Importer Plugin wp-ultimate-csv-importer SQL Injection Admin+ SQLi via AIOSEO Import Fields < 9.0 Fixed in 9.0 CVE-2026-80488 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Cancellation via IDOR < 8.5.5 Fixed in 8.5.5 CVE-2026-80311 WPScan
4.9 Medium Rank Math SEO Plugin seo-by-rank-math Broken Access Control Editor+ Core Settings Modification via fix-site-seo Ability 1.0.271 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77786 WPScan
6.5 Medium HEL Online Classroom: AI-powered Online Classrooms Plugin Information Disclosure Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass No login needed ≤ 1.0.3 CVE-2026-77010 WPScan
6.5 Medium HEL Online Classroom: AI-powered Online Classrooms Plugin Broken Access Control Unauthenticated Plugin Settings Update No login needed ≤ 1.0.3 CVE-2026-77008 WPScan
6.6 Medium Profile Builder Plugin PHP Object Injection Admin+ PHP Object Injection via Import/Export 3.3.4 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76547 WPScan
6.8 Medium Profile Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via Format Date Shortcode 3.3.4 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76546 WPScan
5.3 Medium CatFolders Document Gallery Pro Plugin Broken Access Control Unauthenticated Missing Authorization via download-all No login needed 2.0.6 – < 2.0.7 Fixed in 2.0.7 CVE-2026-19430 WPScan
6.5 Medium MStore API Plugin mstore-api Price Manipulation Subscriber+ Arbitrary Order Payment Bypass via Wallet < 4.21.1 Fixed in 4.21.1 CVE-2026-18234 WPScan
6.5 Medium MStore API Plugin mstore-api Broken Access Control Subscriber+ Arbitrary Order Completion < 4.21.1 Fixed in 4.21.1 CVE-2026-18233 WPScan
5.4 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery Arbitrary Plugin Option Update via CSRF No login needed < 4.17 Fixed in 4.17 CVE-2026-17522 WPScan
4.8 Medium Newsletters Plugin newsletters-lite Other Unauthenticated API Access via Predictable API Key No login needed < 4.17 Fixed in 4.17 CVE-2026-17520 WPScan
5.3 Medium Forminator Plugin forminator Other Other vulnerability Type No login needed ≤ 1.57.1 Fixed in 1.57.2 CVE-2026-82220 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81761 Patchstack
5.4 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81759 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
4.3 Medium ACF Extended Plugin acf-extended Broken Access Control ≤ 0.9.2.6 Fixed in 0.9.2.7 CVE-2026-81284 Patchstack
5.3 Medium Everest Forms Plugin everest-forms Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' No login needed ≤ 3.4.4 CVE-2026-5096 Wordfence
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description ≤ 1.12.4 CVE-2026-3423 Wordfence
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Authentication Bypass Bypass vulnerability No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-81777 Patchstack
6.4 Medium GiveWP Plugin give Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.14.4 CVE-2026-5510 Wordfence
6.4 Medium All-in-One WP Migration Unlimited Extension Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter ≤ 2.84 CVE-2026-6128 Wordfence
4.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Pending Email Change Cancellation via IDOR < 5.2.5 Fixed in 5.2.5 CVE-2026-79995 WPScan
5.3 Medium Breeze Cache Plugin breeze Path Traversal Unauthenticated File Creation via Cache Path Traversal No login needed < 2.5.13 Fixed in 2.5.13 CVE-2026-79706 WPScan
5.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Unauthenticated Refund Request Creation on Guest Orders No login needed 3.7.1 – < 3.8.2 Fixed in 3.8.2 CVE-2026-77701 WPScan
5.3 Medium WP User Frontend Plugin Information Disclosure Unauthenticated User Email and Phone Disclosure via User Directory No login needed 4.3.0 – < 4.3.10 Fixed in 4.3.10 CVE-2026-14567 WPScan
5.3 Medium Shared Files Plugin shared-files Arbitrary File Upload Unauthenticated Limited File Upload No login needed < 1.7.67, < 1.7.70 Fixed in 1.7.67 CVE-2026-12514 WPScan
6.8 Medium Shared Files Plugin shared-files Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed < 1.7.67, < 1.7.68 Fixed in 1.7.67 CVE-2026-12513 WPScan
6.1 Medium ElementsKit Pro Plugin elementskit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 's' Parameter No login needed ≤ 4.10.1 CVE-2026-4246 Wordfence
6.4 Medium Avada (Fusion) Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute ≤ 3.15.6 CVE-2026-16654 Wordfence
6.5 Medium Tutor LMS Plugin tutor Remote Code Execution Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters No login needed ≤ 4.0.5 CVE-2026-16759 Wordfence
6.4 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes ≤ 7.7 CVE-2026-3129 Wordfence
6.4 Medium Smart Slider 3 Plugin smart-slider-3 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute ≤ 3.5.1.38 CVE-2026-15798 Wordfence
5.4 Medium Spiffy Plugin Cross-Site Scripting WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contribut… Not stated CVE-2026-39071 mitre
4.8 Medium Bit Assist Plugin Cross-Site Scripting WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exp… Not stated CVE-2026-39070 mitre
5.3 Medium Kali Forms Plugin kali-forms Broken Access Control No login needed ≤ 2.4.23 Fixed in 2.4.24 CVE-2026-81276 Patchstack
5.3 Medium Ditty Plugin ditty-news-ticker Broken Access Control No login needed ≤ 3.1.67 Fixed in 3.1.69 CVE-2026-81274 Patchstack
4.9 Medium FluentPlayer Pro Plugin fluent-player-pro Broken Access Control ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-81272 Patchstack
6.8 Medium Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Deletion ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78275 Patchstack
6.5 Medium Fluent Boards Pro Plugin fluent-boards-pro Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78273 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only