WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,101–1,150 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.7 High | design-scuole-wordpress-theme | Path Traversal Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme No login needed |
2.6.0 – 2.18.1 |
CVE-2026-87791 |
ENISA | |
| 7.2 High | MotoPress Hotel Booking | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' No login needed |
≤ 6.2.4 |
CVE-2026-90650 |
Wordfence | |
| 6.4 Medium | Bridge - Creative Multipurpose | Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute |
≤ 30.8.9.1 |
CVE-2026-15609 |
Wordfence | |
| 8.8 High | Consulting - Business, Finance | Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX |
≤ 6.7.16 |
CVE-2026-14805 |
Wordfence | |
| 6.4 Medium | Job Postings | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'position_button' Parameter |
≤ 2.8.1 |
CVE-2026-18063 |
Wordfence | |
| 6.5 Medium | AI Engine | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter |
≤ 3.7.7 |
CVE-2026-89141 |
Wordfence | |
| 7.5 High | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter |
≤ 4.1.23 |
CVE-2026-75983 |
Wordfence | |
| 6.4 Medium | Eventin | Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter |
≤ 4.1.23 |
CVE-2026-15402 |
Wordfence | |
| 5.3 Medium | WP Directory Kit | Information Disclosure Unauthenticated Unpublished Listing Disclosure via map_infowindow No login needed |
≤ 1.5.7 |
CVE-2026-18232 |
WPScan | |
| 6.8 Medium | WP Directory Kit | SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings |
≤ 1.5.7 |
CVE-2026-16593 |
WPScan | |
| 2.7 Low | WP Directory Kit | Information Disclosure Contributor+ Non-Public Listing Field Disclosure via Shortcodes |
≤ 1.5.7 |
CVE-2026-16592 |
WPScan | |
| 5.3 Medium | 3D FlipBook | Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed |
≤ 1.16.20 |
CVE-2026-15758 |
Wordfence | |
| 5.4 Medium | Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter |
≤ 4.15.0 |
CVE-2026-85657 |
Wordfence | |
| 6.4 Medium | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets | Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter |
≤ 4.9.5 |
CVE-2026-85575 |
Wordfence | |
| 4.3 Medium | Really Simple Security | Broken Access Control Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler |
< 9.8.2 Fixed in 9.8.2 |
CVE-2026-82519 |
VulnCheck | |
| 8.6 High | Domain For Sale | Broken Access Control ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API No login needed |
< 3.5.2 Fixed in 3.5.2 |
CVE-2026-89023 |
VulnCheck | |
| 4.3 Medium | Quads Ads Manager for Google AdSense | Price Manipulation Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL |
3.0.4 – < 3.0.5 Fixed in 3.0.5 |
CVE-2026-89050 |
WPScan | |
| 7.5 High | MDJM Event Management and Mobile Events Manager | Broken Access Control Unauthenticated Arbitrary Post Deletion No login needed |
< 1.7.8.5, ≤ 1.4.8.3 Fixed in 1.7.8.5 |
CVE-2026-88802 |
WPScan | |
| 8.8 High | YouTube Embed | Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed |
10.0 – 10.3 |
CVE-2026-88793 |
WPScan | |
| 8.8 High | Hoo Companion | Cross-Site Scripting Unauthenticated Stored XSS via Theme Settings Import No login needed |
1.0.2 – 1.0.2 |
CVE-2026-85129 |
WPScan | |
| 10.0 Critical | CryptoPayment Gateway | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router No login needed |
1.2.1 – 1.2.2 |
CVE-2026-81648 |
WPScan | |
| 8.8 High | GenieWords | Cross-Site Scripting Unauthenticated Stored XSS and Configuration Overwrite No login needed |
1.5.27 – 1.5.34 |
CVE-2026-74933 |
WPScan | |
| 7.5 High | Really Simple Security | Authentication Bypass Unauthenticated 2FA Bypass via Email Provider State Demotion |
9.5.10.1 – < 9.8.1 Fixed in 9.8.1 |
CVE-2026-89080 |
WPScan | |
| 5.3 Medium | Bookit | Information Disclosure Unauthenticated Appointment PII Disclosure via Availability Check No login needed |
< 2.6.0.1 Fixed in 2.6.0.1 |
CVE-2026-88995 |
WPScan | |
| 4.2 Medium | rtMedia for WordPress, BuddyPress and bbPress | Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR |
< 4.7.12 Fixed in 4.7.12 |
CVE-2026-88912 |
WPScan | |
| 5.4 Medium | Simple Membership | Privilege Escalation Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref |
< 4.7.8 Fixed in 4.7.8 |
CVE-2026-88764 |
WPScan | |
| 3.7 Low | User Registration & Membership | Information Disclosure Unauthenticated User Data Disclosure via Membership Thank You Page No login needed |
5.0 – < 5.2.8 Fixed in 5.2.8 |
CVE-2026-86407 |
WPScan | |
| 7.5 High | User Registration & Membership | Privilege Escalation Subscriber+ Privilege Escalation via Membership Purchase |
4.4.6 – < 5.2.8 Fixed in 5.2.8 |
CVE-2026-86406 |
WPScan | |
| 4.7 Medium | User Registration & Membership | Open Redirect Unauthenticated Open Redirect via Login Redirect Parameters No login needed |
< 5.2.8 Fixed in 5.2.8 |
CVE-2026-80072 |
WPScan | |
| 7.2 High | User Registration & Membership | Privilege Escalation Author+ Privilege Escalation to Administrator |
< 5.2.8 Fixed in 5.2.8 |
CVE-2026-80071 |
WPScan | |
| 5.3 Medium | Social Contact Form (FormyChat) | Information Disclosure Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry No login needed |
< 2.15.8 Fixed in 2.15.8 |
CVE-2026-77773 |
WPScan | |
| 8.8 High | MemberPress Corporate Accounts | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation |
≤ 1.5.39 |
CVE-2026-15451 |
Wordfence | |
| 6.4 Medium | Booking for Appointments and Events Calendar – Amelia | Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter |
≤ 2.4.9 |
CVE-2026-10148 |
Wordfence | |
| 6.5 Medium | Smart Marketing SMS and Newsletters Forms | SQL Injection Authenticated (Subscriber+) SQL Injection via Parameter Name |
≤ 5.1.24 |
CVE-2026-77161 |
Wordfence | |
| 5.3 Medium | DT LMS | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions No login needed |
≤ 1.1 |
CVE-2026-11355 |
Wordfence | |
| 8.8 High | Tutor LMS | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution |
≤ 4.0.7 |
CVE-2026-78175 |
Wordfence | |
| 9.8 Critical | The Events Calendar | Remote Code Execution Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation No login needed |
≤ 6.17.3 |
CVE-2026-78159 |
Wordfence | |
| 9.8 Critical | The Events Calendar | PHP Object Injection Unauthenticated PHP Object Injection to Remote Code Execution No login needed |
≤ 6.17.4 |
CVE-2026-78006 |
Wordfence | |
| 7.5 High | GEO my WP | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 4.5.5.3 |
CVE-2026-85200 |
Wordfence | |
| 6.5 Medium | MPG | SQL Injection Unauthenticated SQL Injection via URL Path |
≤ 4.2.1 |
CVE-2026-85198 |
Wordfence | |
| 5.3 Medium | Royal Addons for Elementor | Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed |
≤ 1.7.1066 |
CVE-2026-17585 |
Wordfence | |
| 7.5 High | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection Unauthenticated SQL Injection via 'compare' Parameter No login needed |
≤ 4.7.11 |
CVE-2026-16482 |
Wordfence | |
| 4.9 Medium | Product XML Feed Manager for WooCommerce | Broken Access Control Contributor+ Arbitrary Product Deletion via Shortcode |
< 3.1.1 Fixed in 3.1.1 |
CVE-2026-87919 |
WPScan | |
| 5.3 Medium | WPBot | Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed |
< 8.5.7 Fixed in 8.5.7 |
CVE-2026-87918 |
WPScan | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed |
8.4.9 – < 8.6.0 Fixed in 8.6.0 |
CVE-2026-87916 |
WPScan | |
| 5.3 Medium | Rox Appointment Booking | Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed |
1.0.9 – < 1.2.3 Fixed in 1.2.3 |
CVE-2026-87894 |
WPScan | |
| 5.3 Medium | Rox Appointment Booking | Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed |
< 1.2.0 Fixed in 1.2.0 |
CVE-2026-87892 |
WPScan | |
| 6.5 Medium | Rox Appointment Booking | Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed |
< 1.2.0 Fixed in 1.2.0 |
CVE-2026-87891 |
WPScan | |
| 8.0 High | YayPricing | Cross-Site Scripting Subscriber+ Stored XSS via save_page_data REST Route |
< 3.5.7 Fixed in 3.5.7 |
CVE-2026-87888 |
WPScan | |
| 7.5 High | Zonify | Information Disclosure Unauthenticated Account Login Token Disclosure No login needed |
< 1.0.5 Fixed in 1.0.5 |
CVE-2026-87842 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.