WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,051–1,100 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Vimeo Plugin vimeo Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.2 CVE-2026-65543 Patchstack
8.8 High Super Socializer Plugin super-socializer Authentication Bypass Broken Authentication No login needed ≤ 7.14.5 CVE-2026-65542 Patchstack
7.3 High Staff Training Plugin staff-training Broken Access Control No login needed ≤ 1.0.7 CVE-2026-65541 Patchstack
7.5 High Formidable Forms Signature Online Contract Automation Plugin forms-signature-formidable-online-contract-automation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-65523 Patchstack
7.1 High Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2026-65517 Patchstack
7.1 High AffiliateWP Plugin affiliate-wp Cross-Site Scripting No login needed ≤ 2.35.0 Fixed in 2.35.1 CVE-2026-65515 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65513 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-65509 Patchstack
7.5 High BOX NOW Delivery Croatia Plugin box-now-delivery-croatia Broken Access Control No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2026-65504 Patchstack
7.1 High SiteGuard WP Plugin siteguard Cross-Site Scripting No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-61982 Patchstack
7.1 High Ninja Tables Plugin ninja-tables Cross-Site Scripting No login needed ≤ 5.2.9 Fixed in 5.2.10 CVE-2026-61964 Patchstack
7.1 High Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting No login needed ≤ 3.38 Fixed in 3.39 CVE-2026-61963 Patchstack
7.1 High EmbedPress Plugin embedpress Cross-Site Scripting No login needed ≤ 4.5.6 Fixed in 4.6.0 CVE-2026-61961 Patchstack
7.2 High PublishPress Capabilities Plugin capability-manager-enhanced Privilege Escalation ≤ 2.45.0 Fixed in 2.50.0 CVE-2026-28183 Patchstack
7.1 High Popup Maker Plugin popup-maker Cross-Site Scripting No login needed ≤ 1.23.0 Fixed in 1.24.0 CVE-2026-28177 Patchstack
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.56.0 Fixed in 1.56.1 CVE-2026-28143 Patchstack
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.6.4.1 Fixed in 3.6.4.2 CVE-2026-28140 Patchstack
8.8 High Forminator Plugin forminator Privilege Escalation ≤ 1.56.0 Fixed in 1.56.0.1 CVE-2026-28111 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.13.1 Fixed in 3.8.13.2 CVE-2026-28082 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-66712 Patchstack
7.5 High Breakdance Plugin breakdance Broken Access Control No login needed < 2.7 Fixed in 2.7 CVE-2026-65551 Patchstack
7.2 High FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More Plugin formgent Cross-Site Scripting Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.9.2 CVE-2025-15028 Wordfence
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13154 WPScan
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13153 WPScan
8.2 High Checkimate Plugin Broken Access Control Unauthenticated License Deactivation via Hardcoded Secret No login needed ≤ 1.0.13 CVE-2026-14829 WPScan
7.5 High Events Manager Plugin events-manager Information Disclosure Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads No login needed < 7.4 Fixed in 7.4 CVE-2026-18050 WPScan
7.5 High Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Price Manipulation Unauthenticated Payment Intent Amount Manipulation No login needed < 8.5.2 Fixed in 8.5.2 CVE-2026-16734 WPScan
8.2 High Newsletters Plugin newsletters-lite Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via SNS Bounce Handler No login needed < 4.16 Fixed in 4.16 CVE-2026-16268 WPScan
7.2 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.6 CVE-2026-18510 Wordfence
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field No login needed ≤ 1.56.1 CVE-2026-18325 Wordfence
8.8 High File Manager Plugin file-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter 6.0 – 6.9 CVE-2026-15991 Wordfence
7.2 High FluentSMTP Plugin fluent-smtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs No login needed ≤ 2.2.95 CVE-2026-16636 Wordfence
8.1 High Content Egg Plugin content-egg Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion ≤ 11.3.0 CVE-2026-15979 Wordfence
7.2 High Independent Analytics Plugin independent-analytics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.15.0 CVE-2026-17506 Wordfence
7.5 High wiseCampaign Plugin wisecampaign Broken Access Control Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API No login needed ≤ 1.1.16 CVE-2026-7529 Wordfence
7.2 High wp-downloadmanager Plugin wp-downloadmanager Arbitrary File Upload Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal ≤ 1.69 CVE-2026-18933 TuranSec
8.1 High MailChimp Forms by MailMunch Plugin mailchimp-forms-by-mailmunch Broken Access Control Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action ≤ 3.2.7 CVE-2026-7520 Wordfence
7.2 High ShopLentor Plugin woolentor-addons Other Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API ≤ 3.3.7 CVE-2026-6020 Wordfence
7.5 High Page and Post Restriction Plugin page-and-post-restriction Broken Access Control Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API No login needed ≤ 1.4.1 CVE-2026-12000 Wordfence
8.1 High Search Analytics for WP Plugin search-analytics Cross-Site Request Forgery No login needed ≤ 1.4.16 CVE-2026-7444 Wordfence
7.5 High TableOn Plugin posts-table-filterable SQL Injection Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter No login needed ≤ 1.0.5.1 CVE-2026-18881 Wordfence
7.2 High Backup Migration Plugin backup-backup Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'file' Parameter ≤ 2.1.1 CVE-2026-7693 Wordfence
8.8 High LightSync Pro Plugin lightsyncpro Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.1.6 CVE-2026-6147 Wordfence
8.2 High WPFormify Plugin wpformify Broken Access Control Missing Authorization No login needed ≤ 1.1.1 CVE-2026-6627 Wordfence
7.3 High Material Dashboard Plugin material-dashboard Broken Access Control Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion No login needed ≤ 1.4.10 CVE-2026-6079 Wordfence
7.5 High AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.4.6 CVE-2026-6639 Wordfence
7.5 High Contest Gallery Plugin contest-gallery Authentication Bypass Unauthenticated Login-Protection and 2FA Bypass via post_cg_login < 30.0.7 Fixed in 30.0.7 CVE-2026-16055 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only