WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,051–1,100 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Cross-Site Request Forgery Subscription Cancellation via CSRF No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87860 WPScan
5.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass No login needed < 2.0.3 Fixed in 2.0.3 CVE-2026-87854 WPScan
5.7 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Denial of Service Subscriber+ DoS via seraph_accel_State Update < 2.29.24 Fixed in 2.29.24 CVE-2026-87828 WPScan
5.3 Medium Newsletter Plugin newsletter Open Redirect Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter No login needed < 9.3.7 Fixed in 9.3.7 CVE-2026-86823 WPScan
6.8 Medium Visualizer Plugin visualizer Cross-Site Scripting Contributor+ Stored XSS via JSON Data Source < 4.0.8 Fixed in 4.0.8 CVE-2026-86784 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Unpublished Course Disclosure via REST API No login needed 4.2.7.1 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86449 WPScan
3.7 Low LearnPress Plugin learnpress Information Disclosure Unauthenticated Order Data Disclosure via lp_download_order No login needed 4.3.2.8 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86448 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Student Enrollment Disclosure via load_content_via_ajax No login needed 4.4.6 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86447 WPScan
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Question Bank Disclosure via load_content_via_ajax No login needed 4.2.9 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86445 WPScan
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected XSS via 'skin' Parameter No login needed 4.2.6.4 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86444 WPScan
4.3 Medium Formidable Forms Plugin formidable Content Injection Unauthenticated Stored Content Injection via 'updated_by' Parameter No login needed 6.34 – < 6.35 Fixed in 6.35 CVE-2026-85641 WPScan
4.3 Medium Tutor LMS 4.0.0 Plugin Information Disclosure < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-85572 WPScan
7.2 High Tutor LMS 2.7.1 Plugin Privilege Escalation < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification 2.7.1 – < 4.0.8 Fixed in 4.0.8 CVE-2026-85569 WPScan
8.1 High GiveWP Plugin give Privilege Escalation Unauthenticated Account Takeover via Donor Email Sanitization Mismatch No login needed 4.16.6 – < 4.16.8.1 Fixed in 4.16.8.1 CVE-2026-85530 WPScan
4.3 Medium FluentBoards Plugin fluent-boards Information Disclosure Subscriber+ Private Board Membership Disclosure via IDOR < 2.0.15 Fixed in 2.0.15 CVE-2026-85349 WPScan
6.5 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85131 WPScan
3.7 Low Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint No login needed 4.1.5 – < 4.1.24 Fixed in 4.1.24 CVE-2026-84907 WPScan
2.7 Low Eventin Plugin wp-event-solution Broken Access Control Contributor+ User Creation via Speaker Creation < 4.1.24 Fixed in 4.1.24 CVE-2026-84905 WPScan
8.8 High Optimole Plugin optimole-wp Cross-Site Scripting Unauthenticated Stored XSS via Srcset Descriptor Parameter No login needed 4.2.3 – < 4.2.12 Fixed in 4.2.12 CVE-2026-84829 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget < 1.7.9 Fixed in 1.7.9 CVE-2026-84088 WPScan
2.7 Low Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Contributor+ Non-Public Post Content Disclosure via AI Schema Generation 1.63 – < 1.66 Fixed in 1.66 CVE-2026-82126 WPScan
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Non-Public Comment Content Disclosure via IDOR No login needed 1.46 – < 1.66 Fixed in 1.66 CVE-2026-82125 WPScan
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output No login needed < 1.66 Fixed in 1.66 CVE-2026-82124 WPScan
5.3 Medium Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report Information Disclosure Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78474 WPScan
8.6 High Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report SQL Injection Unauthenticated SQLi via 'sort' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78472 WPScan
5.3 Medium Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Ticket Price Rewrite via order_token No login needed < 4.1.24 Fixed in 4.1.24 CVE-2026-77702 WPScan
4.1 Medium WP Import Export Lite Plugin wp-import-export-lite Server-Side Request Forgery Admin+ SSRF via Import URL Handling < 3.9.33 Fixed in 3.9.33 CVE-2026-76559 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite Cross-Site Scripting Contributor+ Stored DOM XSS via Custom Field Names < 3.9.33 Fixed in 3.9.33 CVE-2026-76558 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite SQL Injection Authenticated SQLi via Import Options < 3.9.33 Fixed in 3.9.33 CVE-2026-76557 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite SQL Injection Authenticated SQLi via Export Filter Rules < 3.9.33 Fixed in 3.9.33 CVE-2026-76556 WPScan
6.8 Medium WP Import Export Lite Plugin wp-import-export-lite Information Disclosure Authenticated Sensitive File Disclosure via Existing File Import Path Traversal < 3.9.33 Fixed in 3.9.33 CVE-2026-76555 WPScan
6.5 Medium WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Deletion Authenticated Arbitrary Directory Deletion via Template Path Traversal < 3.9.33 Fixed in 3.9.33 CVE-2026-76553 WPScan
8.8 High WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Upload Authenticated Arbitrary File Upload via Remote Image Import < 3.9.33 Fixed in 3.9.33 CVE-2026-76552 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Remote Code Execution Authenticated RCE via Export Field PHP Function < 3.9.33 Fixed in 3.9.33 CVE-2026-76551 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Remote Code Execution Authenticated RCE via Export Template Path Traversal < 3.9.34 Fixed in 3.9.34 CVE-2026-76550 WPScan
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
6.1 Medium Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots Plugin bp-better-messages Cross-Site Scripting Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter No login needed ≤ 2.15.22 CVE-2026-18555 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter ≤ 5.9.6 CVE-2026-5920 Wordfence
6.4 Medium Advanced Popups Plugin advanced-popups Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field ≤ 1.2.3 CVE-2026-11996 Wordfence
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
7.2 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via AJAX Cron Handler Request No login needed ≤ 3.8.9 CVE-2026-18595 Wordfence
6.5 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Custom+) SQL Injection via 'order_by' Parameter ≤ 1.5.4 CVE-2026-16588 Wordfence
9.8 Critical JetFormBuilder Plugin jetformbuilder Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed ≤ 3.6.2 CVE-2026-12793 Wordfence
5.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter No login needed ≤ 2.8.16 CVE-2026-11984 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action No login needed ≤ 1.2.3 CVE-2026-14349 Wordfence
6.5 Medium JWT Authentication for WP REST APIs Plugin wp-rest-api-authentication Authentication Bypass miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade No login needed < 4.8.0 Fixed in 4.8.0 CVE-2026-89027 VulnCheck
5.1 Medium design-scuole-wordpress-theme Theme Content Injection HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme 1.0 – 2.17.3 CVE-2026-89307 ENISA
5.1 Medium design-scuole-wordpress-theme Theme Cross-Site Scripting Reflected XSS in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.18.2 CVE-2026-87793 ENISA
8.7 High design-scuole-wordpress-theme Theme Broken Access Control Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.17.3 CVE-2026-87792 ENISA

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only