WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1,001–1,050 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | CubeWP Framework | SQL Injection Subscriber+ SQL Injection via cubewp_remove_relation |
< 1.1.31 Fixed in 1.1.31 |
CVE-2026-17017 |
WPScan | |
| 7.5 High | WP Maps Pro | Denial of Service Unauthenticated Denial of Service No login needed |
< 6.1.3 Fixed in 6.1.3 |
CVE-2026-18464 |
WPScan | |
| 7.5 High | WPC Order Tip for WooCommerce | Information Disclosure Unauthenticated Order Data Disclosure No login needed |
< 3.3.1 Fixed in 3.3.1 |
CVE-2026-18357 |
WPScan | |
| 7.5 High | WP Data Access | Information Disclosure Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass No login needed |
< 5.5.79 Fixed in 5.5.79 |
CVE-2026-18032 |
WPScan | |
| 8.6 High | WordPress File Upload | Arbitrary File Upload Unauthenticated SQL Injection via uniqueuploadid No login needed |
< 5.1.8 Fixed in 5.1.8 |
CVE-2026-17044 |
WPScan | |
| 7.5 High | GeoDirectory | Information Disclosure Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint No login needed |
< 2.8.169 Fixed in 2.8.169 |
CVE-2026-16988 |
WPScan | |
| 8.1 High | Solace Extra | Broken Access Control Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure |
< 1.6.1 Fixed in 1.6.1 |
CVE-2026-16948 |
WPScan | |
| 7.5 High | WP Directory Kit | Information Disclosure Subscriber+ Plugin Settings and API Key Disclosure No login needed |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16594 |
WPScan | |
| 7.7 High | WP Directory Kit | SQL Injection Subscriber+ SQL Injection via data_fields_list Parameter |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16589 |
WPScan | |
| 7.5 High | Admin Safety Guard | Information Disclosure Unauthenticated User Data Disclosure via 2fa/app/users REST Route No login needed |
1.2.7 – < 1.4.0 Fixed in 1.4.0 |
CVE-2026-16578 |
WPScan | |
| 8.1 High | Newsletters | PHP Object Injection Unauthenticated PHP Object Injection via Date Form Field No login needed |
< 4.16 Fixed in 4.16 |
CVE-2026-16267 |
WPScan | |
| 8.9 High | WordPress | Cross-Site Scripting WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible… No login needed | Not stated | CVE-2026-64638 |
hackerone | |
| 8.8 High | WP Maps | Local File Inclusion Subscriber+ Local File Inclusion |
< 4.9.7 Fixed in 4.9.7 |
CVE-2026-16263 |
WPScan | |
| 7.5 High | Estatik | Cross-Site Request Forgery Login CSRF No login needed |
< 4.3.3 Fixed in 4.3.3 |
CVE-2026-16262 |
WPScan | |
| 7.5 High | MStore API | Broken Access Control Unauthenticated Product Review Creation No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16041 |
WPScan | |
| 8.1 High | MStore API | Privilege Escalation Unauthenticated Account Takeover via Firebase Phone Authentication No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16030 |
WPScan | |
| 8.1 High | Content Views | SQL Injection Subscriber+ SQL Injection via preview_request |
< 4.5 Fixed in 4.5 |
CVE-2026-15361 |
WPScan | |
| 8.8 High | Subscriptions for WooCommerce | Remote Code Execution Shop Manager+ Arbitrary Plugin Installation |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15215 |
WPScan | |
| 7.5 High | Password Protected | Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed |
2.6.8 – < 2.8.4 Fixed in 2.8.4 |
CVE-2026-14943 |
WPScan | |
| 7.5 High | WPC Name Your Price for WooCommerce | Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-16620 |
WPScan | |
| 7.5 High | miniOrange 2FA | Authentication Bypass miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts |
< 6.2.8 Fixed in 6.2.8 |
CVE-2026-16619 |
WPScan | |
| 7.5 High | CoCart | Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed |
< 4.9.0 Fixed in 4.9.0 |
CVE-2026-10524 |
WPScan | |
| 7.5 High | Payment Plugins for PayPal WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed |
< 2.0.20 Fixed in 2.0.20 |
CVE-2026-13399 |
WPScan | |
| 7.5 High | Payment Gateway for Redsys & WooCommerce Lite | Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed |
< 7.0.2 Fixed in 7.0.2 |
CVE-2026-12584 |
WPScan | |
| 7.5 High | Integrate PhonePe with WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Transaction ID Reuse No login needed |
≤ 1.2.1 |
CVE-2026-10599 |
WPScan | |
| 8.6 High | Creative Mail | SQL Injection Unauthenticated SQLi No login needed |
1.6.5 – 1.6.9 |
CVE-2026-3430 |
WPScan | |
| 7.1 High | WooCommerce Multilingual & Multicurrency | Cross-Site Scripting No login needed |
≤ 5.5.6 Fixed in 5.5.7 |
CVE-2026-66711 |
Patchstack | |
| 8.1 High | e2pdf | Local File Inclusion No login needed |
≤ 1.32.40 Fixed in 1.32.43 |
CVE-2026-66710 |
Patchstack | |
| 8.2 High | Total Upkeep | Broken Access Control No login needed |
≤ 1.17.2 Fixed in 1.17.3 |
CVE-2026-66708 |
Patchstack | |
| 7.1 High | Facebook for WooCommerce | Cross-Site Scripting No login needed |
≤ 3.7.5 Fixed in 3.7.6 |
CVE-2026-66707 |
Patchstack | |
| 7.1 High | Cross-Site Scripting No login needed |
≤ 5.2.1 Fixed in 5.2.2 |
CVE-2026-66705 |
Patchstack | ||
| 7.1 High | Rank Math SEO | Cross-Site Scripting No login needed |
≤ 1.0.274.1 Fixed in 1.0.275 |
CVE-2026-66702 |
Patchstack | |
| 7.1 High | Thrive Architect | Cross-Site Scripting No login needed |
≤ 10.9.3.1 Fixed in 10.9.3.2 |
CVE-2026-66694 |
Patchstack | |
| 7.1 High | GiveWP | Cross-Site Scripting No login needed |
≤ 4.16.5 Fixed in 4.16.5.1 |
CVE-2026-66690 |
Patchstack | |
| 7.1 High | SEO Plugin by Squirrly SEO | Cross-Site Scripting No login needed |
≤ 14.2.0 Fixed in 14.2.1 |
CVE-2026-66664 |
Patchstack | |
| 7.1 High | WP Data Access | Cross-Site Scripting No login needed |
≤ 5.5.79 Fixed in 5.5.80 |
CVE-2026-66663 |
Patchstack | |
| 7.1 High | Frontend Admin by DynamiApps | Broken Access Control |
≤ 3.29.10 |
CVE-2026-66470 |
Patchstack | |
| 7.1 High | Events Manager | Cross-Site Scripting No login needed |
≤ 7.4.2 Fixed in 7.4.3 |
CVE-2026-66457 |
Patchstack | |
| 7.1 High | WPIDE – File Manager & Code Editor | Cross-Site Scripting File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) No login needed |
≤ 3.5.7 Fixed in 3.5.8 |
CVE-2026-66440 |
Patchstack | |
| 7.1 High | Advanced AJAX Product Filters | Cross-Site Scripting No login needed |
≤ 3.2.0.3 Fixed in 3.2.1 |
CVE-2026-66439 |
Patchstack | |
| 8.1 High | Login with phone number | Authentication Bypass Bypass vulnerability No login needed |
≤ 1.8.70 Fixed in 1.8.71 |
CVE-2026-65570 |
Patchstack | |
| 8.5 High | WP Job Portal | SQL Injection |
≤ 2.5.6 Fixed in 2.5.7 |
CVE-2026-65569 |
Patchstack | |
| 7.1 High | Survey Maker | Cross-Site Scripting No login needed |
≤ 5.2.3.3 Fixed in 5.2.3.4 |
CVE-2026-65565 |
Patchstack | |
| 7.1 High | Houzez Property Feed | Cross-Site Scripting No login needed |
≤ 2.5.48 Fixed in 2.5.49 |
CVE-2026-65560 |
Patchstack | |
| 7.2 High | Order Delivery Date for WooCommerce | Privilege Escalation |
≤ 4.6.0 Fixed in 4.6.1 |
CVE-2026-65559 |
Patchstack | |
| 7.1 High | AnsPress – Question and answer | Broken Access Control Question and answer plugin 4.4.4 - Broken Access Control |
4.4.4 |
CVE-2026-65554 |
Patchstack | |
| 7.2 High | Jeg Kit for Elementor | PHP Object Injection |
≤ 3.2.10 Fixed in 3.2.11 |
CVE-2026-65549 |
Patchstack | |
| 8.5 High | Creative Mail | SQL Injection |
≤ 1.6.9 |
CVE-2026-65547 |
Patchstack | |
| 7.1 High | AI Engine | Cross-Site Scripting No login needed |
≤ 3.6.8 Fixed in 3.6.9 |
CVE-2026-65545 |
Patchstack | |
| 7.1 High | Super Socializer | Cross-Site Scripting No login needed |
≤ 7.14.5 |
CVE-2026-65544 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.