WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,101–1,150 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium WP Data Access Plugin wp-data-access Broken Access Control No login needed ≤ 5.5.80 Fixed in 5.5.81 CVE-2026-66595 Patchstack
6.6 Medium WP Cafe Pro Plugin wpcafe-pro Local File Inclusion < 3.0.15 Fixed in 3.0.15 CVE-2026-66586 Patchstack
6.5 Medium Altair Theme altair Broken Access Control No login needed ≤ 5.2.2 CVE-2025-53999 Patchstack
6.8 Medium Kirki Plugin kirki Cross-Site Scripting Editor+ Stored XSS via Font Zip Upload < 6.2.3 Fixed in 6.2.3 CVE-2026-74992 WPScan
6.8 Medium GutenKit Plugin gutenkit-blocks-addon Cross-Site Scripting Author+ Stored XSS via SVG Upload < 2.5.0 Fixed in 2.5.0 CVE-2026-19697 WPScan
6.8 Medium Admin and Site Enhancements Plugin Cross-Site Scripting Author+ Stored XSS via SVG Upload over XML-RPC < 9.0.1 Fixed in 9.0.1 CVE-2026-19615 WPScan
6.6 Medium Royal Elementor Addons Plugin Remote Code Execution Admin+ Remote Code Execution via Widget Builder < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13405 WPScan
5.3 Medium AI Agent by SiteGround Plugin sg-ai-studio Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint No login needed ≤ 1.2.7 CVE-2026-17153 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control < 2.0.8 Fixed in 2.0.8 CVE-2026-73363 Patchstack
6.4 Medium EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content ≤ 8.7.3 CVE-2026-15446 Wordfence
5.4 Medium WPS Bidouille Plugin wps-bidouille Information Disclosure Subscriber+ User Email Disclosure via wps_get_users < 1.33.5 Fixed in 1.33.5 CVE-2026-19782 WPScan
5.3 Medium Membership For WooCommerce Plugin membership-for-woocommerce Information Disclosure Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-19709 WPScan
6.5 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Arbitrary Media Attachment Read via IDOR < 4.5.4 Fixed in 4.5.4 CVE-2026-19417 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Cross-Patient Appointment Modification via IDOR No login needed < 4.5.4 Fixed in 4.5.4 CVE-2026-19416 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18779 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Information Disclosure Unauthenticated Customer PII Disclosure via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18778 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Arbitrary Appointment Status Change via update_appointment_status No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18777 WPScan
5.4 Medium WP Maps Plugin wp-google-map-plugin Broken Access Control Subscriber+ Unlimited Autoloaded Option Creation < 4.9.8 Fixed in 4.9.8 CVE-2026-18466 WPScan
5.3 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Unauthenticated User Email Disclosure via select_2_ajax_user No login needed < 1.5.7 Fixed in 1.5.7 CVE-2026-18231 WPScan
6.8 Medium JetEngine Plugin Cross-Site Scripting Author+ Stored XSS via SVG Upload < 3.8.14 Fixed in 3.8.14 CVE-2026-18202 WPScan
4.3 Medium SmartCrawl Plugin Information Disclosure Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration < 3.16.3 Fixed in 3.16.3 CVE-2026-16979 WPScan
5.3 Medium YayCurrency Plugin yaycurrency Information Disclosure Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration No login needed < 3.3.5 Fixed in 3.3.5 CVE-2026-16058 WPScan
6.8 Medium Easy Media Replace Plugin Cross-Site Scripting Author+ Stored XSS via Attachment Title ≤ 0.2.0 CVE-2026-15253 WPScan
4.7 Medium TenWeb Speed Optimizer Plugin Cross-Site Scripting Unauthenticated Stored XSS via Critical CSS Token Bypass No login needed < 2.33.5 Fixed in 2.33.5 CVE-2026-14287 WPScan
4.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14196 WPScan
6.5 Medium Eventin Plugin wp-event-solution Broken Access Control Contributor+ Schedule Deletion and Modification via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13175 WPScan
6.4 Medium Speed Optimizer Plugin sg-cachepress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes ≤ 7.8.0 CVE-2026-15421 Wordfence
4.3 Medium PPWP: Password Protect Pages, Posts & Full or Partial Content Plugin Broken Access Control Improper Authorization To Authenticated (Contributor+) Master Password Exposure ≤ 1.9.15 CVE-2025-11729 Wordfence
5.9 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 2.17.0 Fixed in 2.17.1 CVE-2026-27365 Patchstack
5.4 Medium B2BKing Plugin b2bking-wholesale-for-woocommerce Broken Access Control ≤ 5.2.30 Fixed in 5.2.40 CVE-2026-66589 Patchstack
6.5 Medium Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting ≤ 3.39 Fixed in 3.40 CVE-2026-66591 Patchstack
6.5 Medium Draft List Plugin simple-draft-list Cross-Site Scripting ≤ 2.6.4 Fixed in 2.6.5 CVE-2026-66603 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.7 CVE-2026-74009 Patchstack
5.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Information Disclosure Sensitive Data Exposure No login needed ≤ 2.17.22 CVE-2026-74008 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure No login needed ≤ 1.16.20 CVE-2026-74007 Patchstack
4.3 Medium WP Table Builder Plugin wp-table-builder Broken Access Control ≤ 2.2.0 CVE-2026-74006 Patchstack
5.4 Medium Gravity Booster – Styles & Layouts for Gravity Forms Plugin styles-and-layouts-for-gravity-forms Broken Access Control Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control ≤ 6.0 CVE-2026-74004 Patchstack
4.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control ≤ 1.2.6 CVE-2026-74003 Patchstack
5.4 Medium User Registration Plugin user-registration Authentication Bypass Broken Authentication ≤ 5.2.6 Fixed in 5.2.7 CVE-2026-73995 Patchstack
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control ≤ 3.7.41 Fixed in 3.7.42 CVE-2026-73404 Patchstack
6.5 Medium Flutterwave WooCommerce Plugin rave-woocommerce-payment-gateway Authentication Bypass Broken Authentication No login needed ≤ 3.3.0 CVE-2026-73399 Patchstack
6.5 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Authentication Bypass Broken Authentication No login needed 3.2.0 CVE-2026-73398 Patchstack
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
4.9 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Path Traversal Arbitrary File Download ≤ 6.6.47 Fixed in 6.6.48 CVE-2026-73383 Patchstack
6.5 Medium Contact Form by Supsystic Plugin contact-form-by-supsystic Authentication Bypass Bypass Vulnerability No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73379 Patchstack
6.5 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Cross-Site Scripting ≤ 4.3.9 Fixed in 4.4.0 CVE-2026-73359 Patchstack
6.5 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.16.5.1 Fixed in 4.16.6 CVE-2026-73352 Patchstack
6.5 Medium GiveWP Plugin give Broken Access Control No login needed < 4.16.6 Fixed in 4.16.6 CVE-2026-73348 Patchstack
6.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Privilege Escalation ≤ 3.7.41 Fixed in 3.7.42 CVE-2026-68568 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.8.172 CVE-2026-68565 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only