WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,051–1,100 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Powerkit Plugin powerkit Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-28178 Patchstack
7.1 High Popup Maker Plugin popup-maker Cross-Site Scripting No login needed ≤ 1.23.0 Fixed in 1.24.0 CVE-2026-28177 Patchstack
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
5.3 Medium YITH WooCommerce Zoom Magnifier Plugin yith-woocommerce-zoom-magnifier Information Disclosure Sensitive Data Exposure No login needed ≤ 2.52.0 Fixed in 2.52.1 CVE-2026-28169 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.56.0 Fixed in 1.56.1 CVE-2026-28143 Patchstack
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.6.4.1 Fixed in 3.6.4.2 CVE-2026-28140 Patchstack
9.8 Critical Ajax Search Lite Plugin ajax-search-lite PHP Object Injection No login needed ≤ 4.14.4 Fixed in 4.14.5 CVE-2026-28139 Patchstack
8.8 High Forminator Plugin forminator Privilege Escalation ≤ 1.56.0 Fixed in 1.56.0.1 CVE-2026-28111 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.13.1 Fixed in 3.8.13.2 CVE-2026-28082 Patchstack
9.8 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation No login needed ≤ 1.5.19 Fixed in 1.5.19.1 CVE-2026-28005 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-25403 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-66712 Patchstack
7.5 High Breakdance Plugin breakdance Broken Access Control No login needed < 2.7 Fixed in 2.7 CVE-2026-65551 Patchstack
7.2 High FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More Plugin formgent Cross-Site Scripting Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.9.2 CVE-2025-15028 Wordfence
3.7 Low MonsterInsights Plugin google-analytics-for-wordpress Authentication Bypass Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-11366 WPScan
5.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.15 Fixed in 2.0.16 CVE-2026-28147 Patchstack
9.8 Critical Insert or Embed Articulate Content into Plugin Arbitrary File Upload Editor+ Arbitrary File Upload No login needed ≤ 4.3000000027 CVE-2026-16060 WPScan
5.4 Medium WordPress Download Manager Plugin Cross-Site Scripting Author+ Stored XSS via Package Title < 3.3.66 Fixed in 3.3.66 CVE-2026-14292 WPScan
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Podcast Contributor/Group/Role Creation and Deletion via CSRF No login needed < 4.5.3 Fixed in 4.5.3 CVE-2026-13729 WPScan
3.7 Low Builderall Plugin Broken Access Control Unauthenticated OAuth Access Token Poisoning via Public REST Routes No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-11882 WPScan
4.3 Medium WP Maps Plugin wp-google-map-plugin Information Disclosure Sensitive Data Exposure ≤ 4.9.6 Fixed in 4.9.7 CVE-2026-28144 Patchstack
5.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.7.39 Fixed in 3.7.40 CVE-2026-28145 Patchstack
6.5 Medium Mailgun Plugin mailgun Broken Access Control Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14834 WPScan
6.5 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion ≤ 3.7.23 CVE-2026-5060 Wordfence
7.1 High WOLF - WordPress Posts Bulk Editor and Manager Plugin Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed < 1.1.0 Fixed in 1.1.0 CVE-2026-14234 WPScan
4.1 Medium Media Cleaner: Clean your WordPress! Plugin media-cleaner Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.0.3 CVE-2026-4912 Wordfence
6.5 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Cross-Site Scripting AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) ≤ 1.8.1 Fixed in 2.0.0 CVE-2026-65448 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.6 Fixed in 30.0.7 CVE-2026-65447 Patchstack
7.1 High Kali Forms Plugin kali-forms Cross-Site Scripting No login needed ≤ 2.4.18 Fixed in 2.4.19 CVE-2026-65446 Patchstack
6.5 Medium Ad Invalid Click Protector (AICP) Plugin ad-invalid-click-protector Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-65445 Patchstack
7.1 High BackWPup Plugin backwpup Cross-Site Scripting No login needed ≤ 5.7.4 Fixed in 5.7.5 CVE-2026-65443 Patchstack
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65441 Patchstack
7.1 High GetGenie Plugin getgenie Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.5.0 CVE-2026-65440 Patchstack
7.1 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting No login needed ≤ 3.5.45 Fixed in 3.5.46 CVE-2026-65439 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting No login needed ≤ 1.6.3.9 Fixed in 1.6.4.0 CVE-2026-65438 Patchstack
7.1 High Spam protection, AntiSpam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting No login needed ≤ 6.82 Fixed in 6.83 CVE-2026-65437 Patchstack
7.1 High miniorange otp verification Plugin miniorange-otp-verification Cross-Site Scripting No login needed ≤ 5.5.1 Fixed in 5.5.2 CVE-2026-61957 Patchstack
7.2 High Simple Link Directory Pro Plugin simple-link-directory-pro Server-Side Request Forgery No login needed ≤ 15.0.6 Fixed in 15.0.7 CVE-2026-61953 Patchstack
7.5 High Xendit Payment Plugin woo-xendit-virtual-accounts Broken Access Control No login needed ≤ 7.1.0 CVE-2026-66473 Patchstack
5.3 Medium Gillion Theme gillion Broken Access Control No login needed ≤ 4.13 Fixed in 4.14 CVE-2026-66477 Patchstack
4.9 Medium Easy Digital Downloads Plugin easy-digital-downloads Arbitrary File Deletion ≤ 3.6.9 CVE-2026-66476 Patchstack
5.9 Medium Checkout Field Editor for WooCommerce – Checkout Manager Plugin checkout-field-editor-and-manager-for-woocommerce Cross-Site Scripting Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) ≤ 3.0.5 CVE-2026-66475 Patchstack
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
6.5 Medium Open User Map Plugin open-user-map Cross-Site Scripting ≤ 1.4.46 Fixed in 1.4.47 CVE-2026-66445 Patchstack
5.4 Medium YayPricing Plugin yaypricing Broken Access Control ≤ 3.5.6 Fixed in 3.5.7 CVE-2026-66442 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-66438 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only