WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,151–1,200 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 24 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Client Invoicing by Sprout Invoices Plugin Broken Access Control Subscriber+ Private Note Overwrite via si_edit_private_note < 20.8.16 Fixed in 20.8.16 CVE-2026-87797 WPScan
8.8 High Add User Autocomplete Plugin add-user-autocomplete Privilege Escalation Subscriber+ Privilege Escalation < 1.2 Fixed in 1.2 CVE-2026-87759 WPScan
6.8 Medium WP Highlight Box Plugin Cross-Site Scripting Contributor+ Stored XSS via highlight-box Shortcode ≤ 1.0 CVE-2026-86790 WPScan
9.8 Critical WP Component Plugin Privilege Escalation Unauthenticated Privilege Escalation via Arbitrary Blog Option Update No login needed ≤ 2.2.4 CVE-2026-85681 WPScan
9.8 Critical WP Images Upload on Piclect Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0 CVE-2026-84171 WPScan
8.1 High IDB Ecommerce (wpStoreCart 5) Plugin PHP Object Injection Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php No login needed ≤ 5.0.7 CVE-2026-84099 WPScan
8.6 High Album Cover Finder Plugin SQL Injection Unauthenticated SQLi via and_action No login needed ≤ 0.7.0 CVE-2026-84047 WPScan
2.2 Low BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Information Disclosure Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-84025 WPScan
4.3 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84024 WPScan
6.5 Medium BEAR - Bulk Editor and Products Manager Professional for WooCommerce Plugin Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF No login needed < 1.2.2 Fixed in 1.2.2 CVE-2026-84023 WPScan
2.7 Low Masteriyo LMS Plugin learning-management-system Information Disclosure Instructor+ Arbitrary Post Disclosure via IDOR 1.14.0 – < 3.4.1 Fixed in 3.4.1 CVE-2026-82851 WPScan
6.8 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Course Highlights < 3.4.1 Fixed in 3.4.1 CVE-2026-82847 WPScan
9.9 Critical Masteriyo LMS Plugin learning-management-system PHP Object Injection Subscriber+ PHP Object Injection < 3.4.1 Fixed in 3.4.1 CVE-2026-82845 WPScan
8.8 High BE REST Endpoints Plugin Cross-Site Scripting Unauthenticated Stored XSS and Widget Manipulation No login needed ≤ 1.0.0 CVE-2026-81742 WPScan
7.1 High Export & Import WPBakery Page Builder Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.2 CVE-2026-81429 WPScan
9.8 Critical DS Ad Rotator Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 0.8 CVE-2026-81402 WPScan
7.2 High Gpx2Graphics Plugin Arbitrary File Upload Arbitrary File Upload via CSRF ≤ 0.3 CVE-2026-81090 WPScan
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
8.6 High SAMO Forms Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 1.0.0 CVE-2026-80491 WPScan
5.3 Medium SureRank Plugin Information Disclosure Unauthenticated Author Email Disclosure via Person Schema No login needed 1.6.2 – < 1.10.1 Fixed in 1.10.1 CVE-2026-78152 WPScan
5.5 Medium Temporary Login Without Password Plugin temporary-login-without-password Broken Access Control Authenticated Temporary Access Revocation Bypass via Application Passwords < 1.9.9 Fixed in 1.9.9 CVE-2026-77753 WPScan
7.2 High Temporary Login Without Password Plugin temporary-login-without-password Privilege Escalation Multisite Subsite Admin+ Network Super Admin Privilege Escalation 1.5 – < 1.9.9 Fixed in 1.9.9 CVE-2026-77752 WPScan
7.2 High Amelia Plugin Privilege Escalation Amelia Manager+ WordPress Account Takeover < 2.4.10 Fixed in 2.4.10 CVE-2026-77705 WPScan
5.3 Medium Amelia Pro Plugin Price Manipulation Unauthenticated Payment Bypass No login needed 9.0 – < 9.8.1 Fixed in 9.8.1 CVE-2026-77689 WPScan
9.6 Critical WebTotem Backups Plugin wt-backups Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Path Traversal < 1.1.0 Fixed in 1.1.0 CVE-2026-77006 WPScan
9.6 Critical Code Monkeys Proposals Plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Path Traversal ≤ 1.0.1 CVE-2026-77005 WPScan
9.8 Critical Frontegg SAML SSO Plugin Privilege Escalation Unauthenticated Account Takeover via Unverified SAMLResponse No login needed ≤ 1.0.1 CVE-2026-75800 WPScan
6.8 Medium Custom Menu Wizard Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode Attributes ≤ 3.3.1 CVE-2026-83532 WPScan
5.3 Medium ElasticPress Plugin elasticpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-62088 Patchstack
7.1 High Master Addons for Elementor Plugin master-addons Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-62089 Patchstack
4.3 Medium Site Kit by Google Plugin google-site-kit Cross-Site Request Forgery No login needed ≤ 1.186.0 Fixed in 1.187.0 CVE-2026-62139 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.16.1 Fixed in 45.16.2 CVE-2026-62138 Patchstack
5.3 Medium bbPress Plugin bbpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.14 Fixed in 2.6.15 CVE-2026-62137 Patchstack
5.3 Medium Flexible Quantity – Measurement Price Calculator for WooCommerce Plugin flexible-quantity-measurement-price-calculator-for-woocommerce Broken Access Control Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control No login needed ≤ 2.3.21 Fixed in 2.3.22 CVE-2026-62136 Patchstack
5.3 Medium Booktics Plugin booktics Broken Access Control No login needed ≤ 1.0.24 Fixed in 1.0.25 CVE-2026-62135 Patchstack
4.3 Medium Starter Templates Plugin astra-sites Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.5 Fixed in 4.7.6 CVE-2026-62134 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 3.4.0 - Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62132 Patchstack
5.3 Medium Passster Plugin content-protector Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-62114 Patchstack
4.3 Medium Slim SEO Plugin slim-seo Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.10.0 Fixed in 4.10.1 CVE-2026-62113 Patchstack
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-62112 Patchstack
6.5 Medium Simple Payment Plugin simple-payment Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.6 CVE-2026-62111 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.9.9 Fixed in 5.9.10 CVE-2026-62110 Patchstack
7.6 High Sky Addons for Elementor Plugin sky-elementor-addons SQL Injection ≤ 3.8.4 Fixed in 3.8.5 CVE-2026-62109 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system PHP Object Injection LMS plugin <= 3.4.0 - PHP Object Injection ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62107 Patchstack
8.8 High SMS Alert Order Notifications Plugin sms-alert Privilege Escalation ≤ 3.9.9 Fixed in 4.0.0 CVE-2026-62106 Patchstack
9.8 Critical ThemeREX Addons Plugin trx_addons PHP Object Injection No login needed < 2.45.0 Fixed in 2.45.0 CVE-2026-62105 Patchstack
9.8 Critical Everest Forms Plugin everest-forms PHP Object Injection No login needed ≤ 3.6.0 Fixed in 3.6.1 CVE-2026-62103 Patchstack
8.8 High Gato GraphQL Plugin gatographql Privilege Escalation ≤ 19.2.3 Fixed in 19.2.4 CVE-2026-62102 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only