WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,001–1,050 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High CubeWP Framework Plugin cubewp-framework SQL Injection Subscriber+ SQL Injection via cubewp_remove_relation < 1.1.31 Fixed in 1.1.31 CVE-2026-17017 WPScan
7.5 High WP Maps Pro Plugin Denial of Service Unauthenticated Denial of Service No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-18464 WPScan
7.5 High WPC Order Tip for WooCommerce Plugin wpc-order-tip Information Disclosure Unauthenticated Order Data Disclosure No login needed < 3.3.1 Fixed in 3.3.1 CVE-2026-18357 WPScan
7.5 High WP Data Access Plugin wp-data-access Information Disclosure Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass No login needed < 5.5.79 Fixed in 5.5.79 CVE-2026-18032 WPScan
8.6 High WordPress File Upload Plugin Arbitrary File Upload Unauthenticated SQL Injection via uniqueuploadid No login needed < 5.1.8 Fixed in 5.1.8 CVE-2026-17044 WPScan
7.5 High GeoDirectory Plugin geodirectory Information Disclosure Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint No login needed < 2.8.169 Fixed in 2.8.169 CVE-2026-16988 WPScan
8.1 High Solace Extra Plugin solace-extra Broken Access Control Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure < 1.6.1 Fixed in 1.6.1 CVE-2026-16948 WPScan
7.5 High WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ Plugin Settings and API Key Disclosure No login needed < 1.5.5 Fixed in 1.5.5 CVE-2026-16594 WPScan
7.7 High WP Directory Kit Plugin wpdirectorykit SQL Injection Subscriber+ SQL Injection via data_fields_list Parameter < 1.5.5 Fixed in 1.5.5 CVE-2026-16589 WPScan
7.5 High Admin Safety Guard Plugin Information Disclosure Unauthenticated User Data Disclosure via 2fa/app/users REST Route No login needed 1.2.7 – < 1.4.0 Fixed in 1.4.0 CVE-2026-16578 WPScan
8.1 High Newsletters Plugin newsletters-lite PHP Object Injection Unauthenticated PHP Object Injection via Date Form Field No login needed < 4.16 Fixed in 4.16 CVE-2026-16267 WPScan
8.9 High WordPress Core Cross-Site Scripting WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible… No login needed Not stated CVE-2026-64638 hackerone
8.8 High WP Maps Plugin wp-google-map-plugin Local File Inclusion Subscriber+ Local File Inclusion < 4.9.7 Fixed in 4.9.7 CVE-2026-16263 WPScan
7.5 High Estatik Plugin Cross-Site Request Forgery Login CSRF No login needed < 4.3.3 Fixed in 4.3.3 CVE-2026-16262 WPScan
7.5 High MStore API Plugin mstore-api Broken Access Control Unauthenticated Product Review Creation No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16041 WPScan
8.1 High MStore API Plugin mstore-api Privilege Escalation Unauthenticated Account Takeover via Firebase Phone Authentication No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16030 WPScan
8.1 High Content Views Plugin content-views-query-and-display-post-page SQL Injection Subscriber+ SQL Injection via preview_request < 4.5 Fixed in 4.5 CVE-2026-15361 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Remote Code Execution Shop Manager+ Arbitrary Plugin Installation < 2.0.1 Fixed in 2.0.1 CVE-2026-15215 WPScan
7.5 High Password Protected Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed 2.6.8 – < 2.8.4 Fixed in 2.8.4 CVE-2026-14943 WPScan
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
7.5 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts < 6.2.8 Fixed in 6.2.8 CVE-2026-16619 WPScan
7.5 High CoCart Plugin cart-rest-api-for-woocommerce Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed < 4.9.0 Fixed in 4.9.0 CVE-2026-10524 WPScan
7.5 High Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed < 2.0.20 Fixed in 2.0.20 CVE-2026-13399 WPScan
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed < 7.0.2 Fixed in 7.0.2 CVE-2026-12584 WPScan
7.5 High Integrate PhonePe with WooCommerce Plugin Price Manipulation Unauthenticated Payment Bypass via Transaction ID Reuse No login needed ≤ 1.2.1 CVE-2026-10599 WPScan
8.6 High Creative Mail Plugin SQL Injection Unauthenticated SQLi No login needed 1.6.5 – 1.6.9 CVE-2026-3430 WPScan
7.1 High WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Cross-Site Scripting No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2026-66711 Patchstack
8.1 High e2pdf Plugin e2pdf Local File Inclusion No login needed ≤ 1.32.40 Fixed in 1.32.43 CVE-2026-66710 Patchstack
8.2 High Total Upkeep Plugin boldgrid-backup Broken Access Control No login needed ≤ 1.17.2 Fixed in 1.17.3 CVE-2026-66708 Patchstack
7.1 High Facebook for WooCommerce Plugin facebook-for-woocommerce Cross-Site Scripting No login needed ≤ 3.7.5 Fixed in 3.7.6 CVE-2026-66707 Patchstack
7.1 High Facebook Plugin official-facebook-pixel Cross-Site Scripting No login needed ≤ 5.2.1 Fixed in 5.2.2 CVE-2026-66705 Patchstack
7.1 High Rank Math SEO Plugin seo-by-rank-math Cross-Site Scripting No login needed ≤ 1.0.274.1 Fixed in 1.0.275 CVE-2026-66702 Patchstack
7.1 High Thrive Architect Plugin thrive-visual-editor Cross-Site Scripting No login needed ≤ 10.9.3.1 Fixed in 10.9.3.2 CVE-2026-66694 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.5 Fixed in 4.16.5.1 CVE-2026-66690 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-66664 Patchstack
7.1 High WP Data Access Plugin wp-data-access Cross-Site Scripting No login needed ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-66663 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control ≤ 3.29.10 CVE-2026-66470 Patchstack
7.1 High Events Manager Plugin events-manager Cross-Site Scripting No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2026-66457 Patchstack
7.1 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Scripting File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2026-66440 Patchstack
7.1 High Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting No login needed ≤ 3.2.0.3 Fixed in 3.2.1 CVE-2026-66439 Patchstack
8.1 High Login with phone number Plugin login-with-phone-number Authentication Bypass Bypass vulnerability No login needed ≤ 1.8.70 Fixed in 1.8.71 CVE-2026-65570 Patchstack
8.5 High WP Job Portal Plugin wp-job-portal SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-65569 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.3.3 Fixed in 5.2.3.4 CVE-2026-65565 Patchstack
7.1 High Houzez Property Feed Plugin houzez-property-feed Cross-Site Scripting No login needed ≤ 2.5.48 Fixed in 2.5.49 CVE-2026-65560 Patchstack
7.2 High Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Privilege Escalation ≤ 4.6.0 Fixed in 4.6.1 CVE-2026-65559 Patchstack
7.1 High AnsPress – Question and answer Plugin anspress-question-answer Broken Access Control Question and answer plugin 4.4.4 - Broken Access Control 4.4.4 CVE-2026-65554 Patchstack
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit PHP Object Injection ≤ 3.2.10 Fixed in 3.2.11 CVE-2026-65549 Patchstack
8.5 High Creative Mail Plugin creative-mail-by-constant-contact SQL Injection ≤ 1.6.9 CVE-2026-65547 Patchstack
7.1 High AI Engine Plugin ai-engine Cross-Site Scripting No login needed ≤ 3.6.8 Fixed in 3.6.9 CVE-2026-65545 Patchstack
7.1 High Super Socializer Plugin super-socializer Cross-Site Scripting No login needed ≤ 7.14.5 CVE-2026-65544 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only