WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,151–1,200 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.5.91 CVE-2026-66679 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.19 CVE-2026-66651 Patchstack
6.5 Medium WP Tab Widget Plugin wp-tab-widget Cross-Site Scripting ≤ 1.2.11 CVE-2026-66646 Patchstack
6.5 Medium Table Of Contents Block Plugin table-of-contents-block Cross-Site Scripting ≤ 1.5.0 CVE-2026-66645 Patchstack
6.5 Medium Typing Effect Plugin animated-typing-effect Cross-Site Scripting ≤ 1.3.7 CVE-2026-66644 Patchstack
6.5 Medium Wufoo Shortcode Plugin wufoo-shortcode Cross-Site Scripting ≤ 1.55 CVE-2026-66643 Patchstack
6.5 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Cross-Site Scripting ≤ 4.6.8 CVE-2026-66641 Patchstack
6.5 Medium Login With Ajax Plugin login-with-ajax Cross-Site Scripting ≤ 4.5.1 CVE-2026-66640 Patchstack
6.5 Medium WPZOOM Forms – Contact Form Plugin for Gutenberg Plugin wpzoom-forms Cross-Site Scripting Contact Form plugin for Gutenberg plugin <= 2.0.4 - Cross Site Scripting (XSS) ≤ 2.0.4 CVE-2026-66639 Patchstack
6.5 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting ≤ 3.29.10 CVE-2026-66638 Patchstack
6.5 Medium Featured Video Plus Plugin featured-video-plus Cross-Site Scripting ≤ 2.3.3 CVE-2026-66637 Patchstack
6.5 Medium Wise Chat Plugin wise-chat Cross-Site Scripting ≤ 3.4 CVE-2026-66636 Patchstack
4.3 Medium Modal Survey Plugin modal-survey Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2.2.3 CVE-2026-66634 Patchstack
6.0 Medium [Aotuman] Grab WeChat Articles Plugin apoyl-grabweixin Server-Side Request Forgery ≤ 2.0.1 CVE-2026-32467 Patchstack
5.3 Medium ShopSmart Loyalty for WooCommerce Plugin Information Disclosure Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone No login needed ≤ 1.0.0 CVE-2026-14832 WPScan
5.9 Medium WooMS Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure No login needed ≤ 9.14 CVE-2026-13700 WPScan
4.3 Medium Kirki Plugin kirki Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter ≤ 6.1.1 CVE-2026-18347 Wordfence
4.9 Medium Kirki Plugin kirki Path Traversal Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter ≤ 6.1.1 CVE-2026-17604 Wordfence
6.5 Medium WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Deletion No login needed ≤ 7.10.09 CVE-2026-17608 Wordfence
5.3 Medium Forminator Forms Plugin forminator Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter No login needed ≤ 1.55.0.2 CVE-2026-12998 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.8 CVE-2026-2357 Wordfence
6.5 Medium Visualizer Plugin visualizer Information Disclosure Contributor+ Cross-User Chart Configuration Disclosure < 4.0.7 Fixed in 4.0.7 CVE-2026-19726 WPScan
6.1 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Quiz Description No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-19712 WPScan
6.5 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Broken Access Control Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request < 7.0.7 Fixed in 7.0.7 CVE-2026-19711 WPScan
6.5 Medium ECS Plugin Information Disclosure Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source < 4.3.10 Fixed in 4.3.10 CVE-2026-19613 WPScan
5.7 Medium Manual Image Crop Plugin manual-image-crop Broken Access Control Subscriber+ Arbitrary Attachment Image Overwrite via IDOR < 1.15 Fixed in 1.15 CVE-2026-15384 WPScan
5.4 Medium Divi Theme Cross-Site Scripting Contributor+ Stored XSS via Social Media Follow Skype URL 5.0 – < 5.9.0 Fixed in 5.9.0 CVE-2026-13712 WPScan
4.9 Medium WC Vendors Plugin wc-vendors SQL Injection Authenticated (Shop Manager+) SQL Injection via 'status' Parameter ≤ 2.7.0 CVE-2026-15351 Wordfence
6.5 Medium The School Management Plugin school-management-system SQL Injection Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter ≤ 5.4 CVE-2026-9767 Wordfence
4.9 Medium Slider Hero with Video Background, Animation Plugin slider-hero SQL Injection Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) ≤ 9.1.7 CVE-2026-17582 Wordfence
6.4 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 4.9.0 CVE-2026-16775 Wordfence
4.3 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Broken Access Control Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter ≤ 3.11.5 CVE-2026-15345 Wordfence
6.5 Medium StoreEngine Plugin storeengine Path Traversal Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL ≤ 2.1.1 CVE-2026-15056 Wordfence
6.6 Medium Turnkey bbPress by WeaverTheme Plugin weaver-for-bbpress PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 1.7.1 CVE-2026-10035 Wordfence
6.4 Medium Snippet Shortcodes Plugin shortcode-variables Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 5.2.0 CVE-2026-16758 Wordfence
4.9 Medium User Login History Plugin user-login-history SQL Injection Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter ≤ 2.1.7 CVE-2026-2283 Wordfence
6.4 Medium SureDash Plugin suredash Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute ≤ 1.10.3 CVE-2026-18402 Wordfence
6.4 Medium Video Gallery Plugin youtube-showcase Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode ≤ 4.0.4 CVE-2026-15790 Wordfence
6.4 Medium Toocheke Companion Plugin toocheke-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta ≤ 2.10 CVE-2026-15604 Wordfence
4.3 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action ≤ 2.8.5 CVE-2026-16779 Wordfence
6.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute ≤ 1.4.0 CVE-2026-15726 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option ≤ 11.2.1 CVE-2026-15963 Wordfence
6.1 Medium Advanced File Manager Plugin file-manager-advanced Cross-Site Scripting Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter No login needed ≤ 5.4.12 CVE-2026-15009 Wordfence
4.3 Medium Password Protect WordPress Lite Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update ≤ 1.9.20 CVE-2025-10005 Wordfence
6.4 Medium Loco Translate Plugin loco-translate Cross-Site Scripting Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments ≤ 2.8.7 CVE-2026-15066 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints ≤ 3.5.2 CVE-2026-13167 Wordfence
5.3 Medium Product Table & List Builder For WooCommerce Plugin wc-product-table-lite Content Injection Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter No login needed ≤ 5.6.0 CVE-2026-15441 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure ≤ 1.6.12.10 CVE-2026-13358 Wordfence
6.4 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter ≤ 11.2.1 CVE-2026-11780 Wordfence
6.5 Medium Fullscreen Galleria Plugin fullscreen-galleria SQL Injection Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content ≤ 1.6.12 CVE-2026-16079 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only