WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,001–1,050 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Push Notification for Post and BuddyPress | Broken Access Control |
≤ 3.20 Fixed in 3.21 |
CVE-2026-81279 |
Patchstack | |
| 4.3 Medium | Notifima | Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR |
< 3.1.4 Fixed in 3.1.4 |
CVE-2026-78139 |
WPScan | |
| 4.3 Medium | Finale Lite | Information Disclosure Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html |
< 2.21.0 Fixed in 2.21.0 |
CVE-2026-78138 |
WPScan | |
| 5.3 Medium | LearnPress – Sepay Payment | Information Disclosure Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure No login needed |
< 4.0.3 Fixed in 4.0.3 |
CVE-2026-78125 |
WPScan | |
| 5.9 Medium | UpdraftPlus | Cross-Site Request Forgery Backup Restoration via CSRF No login needed |
< 1.26.7 Fixed in 1.26.7 |
CVE-2026-76549 |
WPScan | |
| 4.4 Medium | JetBackup | Broken Access Control Admin+ Multisite Network Backup Download |
3.1.18.8 – < 3.1.23.5 Fixed in 3.1.23.5 |
CVE-2026-19454 |
WPScan | |
| 6.6 Medium | Defender Security | Remote Code Execution Admin+ Network-Wide RCE via Hub Connector on Multisite |
5.0.0 – < 6.2.0 Fixed in 6.2.0 |
CVE-2026-19225 |
WPScan | |
| 4.3 Medium | ShopApper | Broken Access Control Subscriber+ Arbitrary Product Stock Update |
≤ 0.4.62 |
CVE-2026-16569 |
WPScan | |
| 4.3 Medium | ShopApper | Information Disclosure Subscriber+ Customer Data Disclosure via IDOR |
≤ 0.4.62 |
CVE-2026-16568 |
WPScan | |
| 5.3 Medium | Document Embedder | Broken Access Control Unauthenticated Private Document Download via Token Oracle No login needed |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-16567 |
WPScan | |
| 4.8 Medium | CMP - Coming Soon & Maintenance | Broken Access Control Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax No login needed |
< 4.1.18 Fixed in 4.1.18 |
CVE-2026-13414 |
WPScan | |
| 5.3 Medium | WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps | Broken Access Control No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access No login needed |
≤ 5.5.68 |
CVE-2026-3235 |
Wordfence | |
| 6.4 Medium | Greenshift | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI |
≤ 12.8.9 |
CVE-2026-5092 |
Wordfence | |
| 6.4 Medium | Reviews and Rating – Google Reviews | Cross-Site Scripting Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 5.10 |
CVE-2026-2388 |
Wordfence | |
| 6.4 Medium | Betheme | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode |
≤ 28.4 |
CVE-2026-6178 |
Wordfence | |
| 6.4 Medium | Gutenverse | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks |
≤ 4.0.2 |
CVE-2026-3002 |
Wordfence | |
| 6.5 Medium | Noptin | Information Disclosure Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page No login needed |
4.0.0 – < 4.3.3 Fixed in 4.3.3 |
CVE-2026-78146 |
WPScan | |
| 5.5 Medium | RegistrationMagic | SQL Injection Admin+ SQLi via 'rm_sortby' Parameter |
< 6.0.9.4 Fixed in 6.0.9.4 |
CVE-2026-77790 |
WPScan | |
| 4.3 Medium | Stripe Payment Forms by WP Full Pay | Broken Access Control Cross-Customer Subscription Modification via IDOR |
< 8.5.1 Fixed in 8.5.1 |
CVE-2026-77789 |
WPScan | |
| 5.3 Medium | Stripe Payment Forms by WP Full Pay | Information Disclosure Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session No login needed |
< 8.5.1 Fixed in 8.5.1 |
CVE-2026-77758 |
WPScan | |
| 5.4 Medium | Directorist | Path Traversal Subscriber+ Arbitrary Image Move via REST v2 Listing Submission |
8.5 – < 8.9.3 Fixed in 8.9.3 |
CVE-2026-77757 |
WPScan | |
| 5.3 Medium | Kirki | Information Disclosure Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis No login needed |
< 6.0.14 Fixed in 6.0.14 |
CVE-2026-77754 |
WPScan | |
| 6.5 Medium | Woo Refund And Exchange Lite | Information Disclosure Unauthenticated Guest Order Message Disclosure and Manipulation No login needed |
4.4.6 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-77695 |
WPScan | |
| 5.3 Medium | Eventin | Broken Access Control Unauthenticated Order Completion Without Payment via order_token No login needed |
< 4.1.19 Fixed in 4.1.19 |
CVE-2026-77694 |
WPScan | |
| 5.3 Medium | AI Engine | Broken Access Control Unauthenticated Arbitrary AI Query Execution via Editor Assistant No login needed |
3.4.0 – < 3.7.2 Fixed in 3.7.2 |
CVE-2026-75798 |
WPScan | |
| 4.3 Medium | WP Project Manager | Information Disclosure Subscriber+ User Activity Feed Disclosure via IDOR |
2.2.0 – < 4.0.7 Fixed in 4.0.7 |
CVE-2026-74930 |
WPScan | |
| 5.4 Medium | WP Project Manager | Information Disclosure Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR |
< 4.0.7 Fixed in 4.0.7 |
CVE-2026-74929 |
WPScan | |
| 6.8 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Image Accordion Widget Effect Settings |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-19226 |
WPScan | |
| 5.3 Medium | Tutor LMS | SQL Injection Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters No login needed |
4.0.0 – < 4.0.6 Fixed in 4.0.6 |
CVE-2026-19094 |
WPScan | |
| 5.3 Medium | Booking Package | Price Manipulation Unauthenticated Price Manipulation via Service and Option Cost Parameters No login needed |
< 1.7.25 Fixed in 1.7.25 |
CVE-2026-16986 |
WPScan | |
| 6.5 Medium | WP Legal Pages | Information Disclosure Unauthenticated API Secret Disclosure No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-16984 |
WPScan | |
| 5.3 Medium | WPCafe | Broken Access Control Unauthenticated Reservation Approval Bypass via Missing Authorization No login needed |
< 3.0.18 Fixed in 3.0.18 |
CVE-2026-14550 |
WPScan | |
| 6.5 Medium | Amelia | Authentication Bypass Unauthenticated Notification Queue Dispatch No login needed |
< 2.4.7 Fixed in 2.4.7 |
CVE-2026-14216 |
WPScan | |
| 4.7 Medium | Amelia Pro | Broken Access Control Provider+ Arbitrary Provider Password Update via IDOR |
9.0 – < 9.8 Fixed in 9.8 |
CVE-2026-14212 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Information Disclosure Unauthenticated Taxonomy Term Disclosure No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13406 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Broken Access Control Unauthenticated Like Count and IP Meta Modification via wpr_likes_init No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13404 |
WPScan | |
| 5.3 Medium | Eventin | Information Disclosure Unauthenticated Unpublished Content Disclosure No login needed |
< 4.1.22 Fixed in 4.1.22 |
CVE-2026-13172 |
WPScan | |
| 4.9 Medium | Media Sweep | SQL Injection Authenticated (Administrator+) SQL Injection via 'fields' Parameter |
≤ 1.1.3 |
CVE-2026-77824 |
Wordfence | |
| 6.4 Medium | Ultimate Member | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) |
≤ 2.12.1 |
CVE-2026-18547 |
Wordfence | |
| 5.3 Medium | My Agile Privacy® | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions No login needed |
≤ 3.3.6 |
CVE-2026-17587 |
Wordfence | |
| 4.3 Medium | Newsletters | Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter |
≤ 4.17 |
CVE-2026-75908 |
Wordfence | |
| 6.4 Medium | eCommerce Product Catalog | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute |
≤ 3.5.10 |
CVE-2026-76128 |
Wordfence | |
| 6.4 Medium | TranslatePress | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor |
≤ 3.2.6 |
CVE-2026-18512 |
Wordfence | |
| 6.4 Medium | MetForm | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting |
≤ 4.1.8 |
CVE-2026-18100 |
Wordfence | |
| 6.5 Medium | WP Project Manager Pro | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 4.0.1 |
CVE-2026-78470 |
Wordfence | |
| 6.4 Medium | tagDiv Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.4.5 |
CVE-2026-12561 |
Wordfence | |
| 6.4 Medium | Gutenverse | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute |
≤ 4.0.2 |
CVE-2026-19943 |
Wordfence | |
| 6.6 Medium | Events Manager | Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys |
≤ 7.3.7.4 |
CVE-2026-14280 |
Wordfence | |
| 6.4 Medium | FundEngine | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter |
≤ 1.8.1 |
CVE-2026-76063 |
Wordfence | |
| 6.1 Medium | Events Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'header_format' Parameter No login needed |
≤ 7.4.0.1 |
CVE-2026-17089 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.