WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,101–1,150 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.7 High design-scuole-wordpress-theme Theme Path Traversal Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme No login needed 2.6.0 – 2.18.1 CVE-2026-87791 ENISA
7.2 High MotoPress Hotel Booking Plugin motopress-hotel-booking-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' No login needed ≤ 6.2.4 CVE-2026-90650 Wordfence
6.4 Medium Bridge - Creative Multipurpose Theme Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute ≤ 30.8.9.1 CVE-2026-15609 Wordfence
8.8 High Consulting - Business, Finance Theme Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX ≤ 6.7.16 CVE-2026-14805 Wordfence
6.4 Medium Job Postings Plugin job-postings Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter ≤ 2.8.1 CVE-2026-18063 Wordfence
6.5 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter ≤ 3.7.7 CVE-2026-89141 Wordfence
7.5 High Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce Plugin wp-event-solution Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter ≤ 4.1.23 CVE-2026-75983 Wordfence
6.4 Medium Eventin Plugin wp-event-solution Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter ≤ 4.1.23 CVE-2026-15402 Wordfence
5.3 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Unauthenticated Unpublished Listing Disclosure via map_infowindow No login needed ≤ 1.5.7 CVE-2026-18232 WPScan
6.8 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings ≤ 1.5.7 CVE-2026-16593 WPScan
2.7 Low WP Directory Kit Plugin wpdirectorykit Information Disclosure Contributor+ Non-Public Listing Field Disclosure via Shortcodes ≤ 1.5.7 CVE-2026-16592 WPScan
5.3 Medium 3D FlipBook Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed ≤ 1.16.20 CVE-2026-15758 Wordfence
5.4 Medium Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors Plugin publishpress-authors Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter ≤ 4.15.0 CVE-2026-85657 Wordfence
6.4 Medium ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets Plugin shopengine Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter ≤ 4.9.5 CVE-2026-85575 Wordfence
4.3 Medium Really Simple Security Plugin really-simple-ssl Broken Access Control Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler < 9.8.2 Fixed in 9.8.2 CVE-2026-82519 VulnCheck
8.6 High Domain For Sale Plugin domain-for-sale Broken Access Control ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API No login needed < 3.5.2 Fixed in 3.5.2 CVE-2026-89023 VulnCheck
4.3 Medium Quads Ads Manager for Google AdSense Plugin quick-adsense-reloaded Price Manipulation Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL 3.0.4 – < 3.0.5 Fixed in 3.0.5 CVE-2026-89050 WPScan
7.5 High MDJM Event Management and Mobile Events Manager Plugin Broken Access Control Unauthenticated Arbitrary Post Deletion No login needed < 1.7.8.5, ≤ 1.4.8.3 Fixed in 1.7.8.5 CVE-2026-88802 WPScan
8.8 High YouTube Embed Plugin Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed 10.0 – 10.3 CVE-2026-88793 WPScan
8.8 High Hoo Companion Plugin Cross-Site Scripting Unauthenticated Stored XSS via Theme Settings Import No login needed 1.0.2 – 1.0.2 CVE-2026-85129 WPScan
10.0 Critical CryptoPayment Gateway Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router No login needed 1.2.1 – 1.2.2 CVE-2026-81648 WPScan
8.8 High GenieWords Plugin Cross-Site Scripting Unauthenticated Stored XSS and Configuration Overwrite No login needed 1.5.27 – 1.5.34 CVE-2026-74933 WPScan
7.5 High Really Simple Security Plugin really-simple-ssl Authentication Bypass Unauthenticated 2FA Bypass via Email Provider State Demotion 9.5.10.1 – < 9.8.1 Fixed in 9.8.1 CVE-2026-89080 WPScan
5.3 Medium Bookit Plugin bookit-for-cal-com Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed < 2.6.0.1 Fixed in 2.6.0.1 CVE-2026-88995 WPScan
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
5.4 Medium Simple Membership Plugin simple-membership Privilege Escalation Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref < 4.7.8 Fixed in 4.7.8 CVE-2026-88764 WPScan
3.7 Low User Registration & Membership Plugin user-registration Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed 5.0 – < 5.2.8 Fixed in 5.2.8 CVE-2026-86407 WPScan
7.5 High User Registration & Membership Plugin user-registration Privilege Escalation Subscriber+ Privilege Escalation via Membership Purchase 4.4.6 – < 5.2.8 Fixed in 5.2.8 CVE-2026-86406 WPScan
4.7 Medium User Registration & Membership Plugin user-registration Open Redirect Unauthenticated Open Redirect via Login Redirect Parameters No login needed < 5.2.8 Fixed in 5.2.8 CVE-2026-80072 WPScan
7.2 High User Registration & Membership Plugin user-registration Privilege Escalation Author+ Privilege Escalation to Administrator < 5.2.8 Fixed in 5.2.8 CVE-2026-80071 WPScan
5.3 Medium Social Contact Form (FormyChat) Plugin Information Disclosure Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry No login needed < 2.15.8 Fixed in 2.15.8 CVE-2026-77773 WPScan
8.8 High MemberPress Corporate Accounts Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation ≤ 1.5.39 CVE-2026-15451 Wordfence
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter ≤ 2.4.9 CVE-2026-10148 Wordfence
6.5 Medium Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp SQL Injection Authenticated (Subscriber+) SQL Injection via Parameter Name ≤ 5.1.24 CVE-2026-77161 Wordfence
5.3 Medium DT LMS Plugin dt-lms-lite Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions No login needed ≤ 1.1 CVE-2026-11355 Wordfence
8.8 High Tutor LMS Plugin tutor PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution ≤ 4.0.7 CVE-2026-78175 Wordfence
9.8 Critical The Events Calendar Plugin the-events-calendar Remote Code Execution Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation No login needed ≤ 6.17.3 CVE-2026-78159 Wordfence
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 6.17.4 CVE-2026-78006 Wordfence
7.5 High GEO my WP Plugin geo-my-wp Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.5.5.3 CVE-2026-85200 Wordfence
6.5 Medium MPG Plugin multiple-pages-generator-by-porthas SQL Injection Unauthenticated SQL Injection via URL Path ≤ 4.2.1 CVE-2026-85198 Wordfence
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed ≤ 1.7.1066 CVE-2026-17585 Wordfence
7.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Unauthenticated SQL Injection via 'compare' Parameter No login needed ≤ 4.7.11 CVE-2026-16482 Wordfence
4.9 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control Contributor+ Arbitrary Product Deletion via Shortcode < 3.1.1 Fixed in 3.1.1 CVE-2026-87919 WPScan
5.3 Medium WPBot Plugin chatbot Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed < 8.5.7 Fixed in 8.5.7 CVE-2026-87918 WPScan
5.3 Medium WPBot Plugin chatbot Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed 8.4.9 – < 8.6.0 Fixed in 8.6.0 CVE-2026-87916 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87892 WPScan
6.5 Medium Rox Appointment Booking Plugin rox-appointment-booking Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87891 WPScan
8.0 High YayPricing Plugin yaypricing Cross-Site Scripting Subscriber+ Stored XSS via save_page_data REST Route < 3.5.7 Fixed in 3.5.7 CVE-2026-87888 WPScan
7.5 High Zonify Plugin zonify Information Disclosure Unauthenticated Account Login Token Disclosure No login needed < 1.0.5 Fixed in 1.0.5 CVE-2026-87842 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only