WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,101–1,150 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding No login needed < 6.2.7 Fixed in 6.2.7 CVE-2026-16036 WPScan
7.5 High WP 2FA Plugin wp-2fa Authentication Bypass Two-Factor Authentication Bypass via Passkeys Provider No login needed < 4.1.0 Fixed in 4.1.0 CVE-2026-15372 WPScan
8.1 High YayPricing Plugin yaypricing Information Disclosure Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure < 3.5.7 Fixed in 3.5.7 CVE-2026-15230 WPScan
8.1 High Zportals Plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload < 6.3.4 Fixed in 6.3.4 CVE-2026-14553 WPScan
7.5 High User Registration & Membership Plugin user-registration Broken Access Control Unauthenticated Account Creation While Registration Disabled No login needed < 5.2.6 Fixed in 5.2.6 CVE-2026-16736 WPScan
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization < 5.0.11 Fixed in 5.0.11 CVE-2026-16605 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16604 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Category-Locked Content Disclosure via Core REST API No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16603 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16602 WPScan
7.5 High Bit Form Plugin bit-form Cross-Site Scripting Unauthenticated Stored XSS via SVG Signature Upload No login needed < 3.2.0 Fixed in 3.2.0 CVE-2026-16573 WPScan
7.5 High Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed < 3.6.12 Fixed in 3.6.12 CVE-2026-16561 WPScan
8.8 High Smart Popup by Supsystic Plugin popup-by-supsystic Privilege Escalation Unauthenticated Privilege Escalation to Administrator ≤ 1.12.0 CVE-2026-18322 Wordfence
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
7.2 High VikRentItems Flexible Rental Management System Plugin vikrentitems Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2026-16143 Wordfence
8.8 High Dokan Plugin dokan-lite Broken Access Control Missing Authorization to Authenticated (Vendor+) Privilege Escalation <=5.0.2 CVE-2026-8761 Wordfence
8.0 High Create Block Plugin Remote Code Execution Admin+ PHP Code Injection via Pattern Save (Multisite) < 2.10.0 Fixed in 2.10.0 CVE-2026-16623 WPScan
8.6 High LogMyTrip Plugin SQL Injection Unauthenticated SQL Injection via 'tid' Cookie No login needed ≤ 1.9 CVE-2026-16572 WPScan
8.1 High SM Page Duplicator Plugin SQL Injection Editor+ SQL Injection via Page Duplication ≤ 1.0.0 CVE-2026-16539 WPScan
8.1 High Chama Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.0.13 Fixed in 1.0.13 CVE-2025-15672 WPScan
7.5 High Gallery for Google Photos Plugin Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-15236 WPScan
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint No login needed < 1.6.12.6 Fixed in 1.6.12.6 CVE-2026-16540 WPScan
7.5 High WooCommerce Product Attachment Plugin Broken Access Control Unauthenticated Arbitrary Media Download No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-16285 WPScan
7.5 High Huge IT Login Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.4 CVE-2026-16261 WPScan
8.1 High Lenxel WP Theme Privilege Escalation Unauthenticated Account Takeover via Arbitrary Password Reset No login needed ≤ 1.0.31 CVE-2026-12586 WPScan
7.5 High ChatBot for eCommerce – WoowBot Plugin Broken Access Control WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response No login needed < 4.8.4 Fixed in 4.8.4 CVE-2026-15241 WPScan
7.5 High SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile No login needed < 3.9.8 Fixed in 3.9.8 CVE-2026-15206 WPScan
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Booking Manager+ Missing Authorization via rtb_reset_notifications No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15151 WPScan
7.5 High CubeWP Framework Plugin cubewp-framework Path Traversal Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter No login needed ≤ 1.1.30 CVE-2026-13339 Wordfence
7.5 High User Access Manager Plugin user-access-manager Path Traversal Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter No login needed ≤ 2.3.15 CVE-2026-18352 Wordfence
8.8 High Pronamic Pay Plugin pronamic-ideal Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Gravity Forms 'Update user role' Field ≤ 10.1.0 CVE-2026-16635 Wordfence
8.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter ≤ 9.2.3 CVE-2026-15450 Wordfence
7.2 High MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder Plugin mailchimp-subscribe-sm Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field Values No login needed ≤ 4.3.3 CVE-2026-15052 Wordfence
8.1 High Kali Forms Plugin kali-forms Remote Code Execution Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter No login needed ≤ 2.4.20 CVE-2026-16144 Wordfence
8.8 High AI Engine Plugin ai-engine Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match No login needed ≤ 3.6.5 CVE-2026-15988 Wordfence
7.5 High Mapster WP Maps Plugin mapster-wp-maps Information Disclosure Unauthenticated Private and Draft Post Content Disclosure No login needed < 1.24.0 Fixed in 1.24.0 CVE-2026-14839 WPScan
7.1 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Cross-Site Scripting Reflected XSS via wdpAjax No login needed < 5.0.0 Fixed in 5.0.0 CVE-2026-13725 WPScan
7.2 High Theme Demo Import Plugin Arbitrary File Upload Admin+ Arbitrary File Upload ≤ 1.1.3 CVE-2026-13157 WPScan
7.2 High Everest Toolkit Plugin Arbitrary File Upload Admin+ Arbitrary File Upload ≤ 1.2.3 CVE-2026-13158 WPScan
8.1 High Profile Builder Plugin Privilege Escalation Unauthenticated Account Takeover via Auto-Login After Registration No login needed < 3.16.4 Fixed in 3.16.4 CVE-2026-15368 WPScan
7.2 High HUSKY - Products Filter Professional for WooCommerce Plugin Local File Inclusion Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view < 1.4.1 Fixed in 1.4.1 CVE-2026-15244 WPScan
8.1 High Login/Signup Popup Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Rate Limit Bypass No login needed < 3.2.5 Fixed in 3.2.5 CVE-2026-14836 WPScan
8.8 High DynamicKit for Elementor Plugin dynamickit-elementor Privilege Escalation Unauthenticated Account Takeover via Password Reset Link Host Injection No login needed < 1.0.3 Fixed in 1.0.3 CVE-2026-14596 WPScan
8.1 High Chat On Desk Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset OTP Bypass No login needed < 1.0.9 Fixed in 1.0.9 CVE-2026-14309 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Privilege Escalation Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta ≤ 2.0.0 CVE-2026-15414 Wordfence
7.5 High Bit integrations Plugin bit-integrations Path Traversal Unauthenticated Arbitrary File Read via Optional CF7 File Field No login needed ≤ 2.9.0 CVE-2026-15006 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field No login needed < 3.29.9 Fixed in 3.29.9 CVE-2026-13609 WPScan
8.1 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret No login needed < 6.2.6 Fixed in 6.2.6 CVE-2026-12695 WPScan
7.2 High ElementsKit Lite Plugin Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13392 WPScan
8.6 High Kirki Plugin kirki SQL Injection Unauthenticated SQL Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12721 WPScan
7.5 High Kirki Plugin kirki PHP Object Injection Unauthenticated PHP Object Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12720 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only