WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,201–1,250 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Gravity Booster Plugin styles-and-layouts-for-gravity-forms Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter ≤ 5.26 CVE-2026-12477 Wordfence
5.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field ≤ 4.16.19 CVE-2026-18385 Wordfence
4.9 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection Authenticated (Admin+) SQL Injection via 'additional_params' Parameter ≤ 9.2.4 CVE-2026-15602 Wordfence
4.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter ≤ 27.7 CVE-2026-12905 Wordfence
4.4 Medium Admin Custom Login Plugin admin-custom-login Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting ≤ 3.6.4 CVE-2026-2487 Wordfence
6.5 Medium WPML Multilingual CMS Plugin sitepress-multilingual-cms SQL Injection Authenticated (Translator+) SQL Injection via 'sorting' Parameter ≤ 4.9.5 CVE-2026-12248 Wordfence
4.3 Medium ECS Plugin Broken Access Control Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers < 4.3.8 Fixed in 4.3.8 CVE-2026-18807 WPScan
6.5 Medium Backup Migration Plugin backup-backup Privilege Escalation Admin+ Privilege Escalation via Post-Restore Auto-Login < 2.1.7 Fixed in 2.1.7 CVE-2026-18216 WPScan
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Team Member+ User Email Disclosure via Users and Customers REST Endpoints < 1.6.12.17 Fixed in 1.6.12.17 CVE-2026-16541 WPScan
5.4 Medium ECS Plugin Cross-Site Scripting Contributor+ Stored XSS via Dynamic Repeater Bindings < 4.3.8 Fixed in 4.3.8 CVE-2026-14230 WPScan
5.3 Medium ECS Plugin Information Disclosure Unauthenticated Private Content Disclosure via ecsload No login needed < 4.3.8 Fixed in 4.3.8 CVE-2026-14229 WPScan
4.9 Medium Invisible Anti-Spam & CAPTCHA Plugin gdpr-compliant-recaptcha-for-all-forms SQL Injection Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values ≤ 5.1 CVE-2026-16146 Wordfence
4.9 Medium Invisible Anti-Spam & CAPTCHA Plugin gdpr-compliant-recaptcha-for-all-forms SQL Injection Authenticated (Editor+) SQL Injection via 'key' Parameter ≤ 5.1 CVE-2026-16094 Wordfence
6.4 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter ≤ 1.2.2 CVE-2026-15948 Wordfence
6.5 Medium KiviCare Plugin kivicare-clinic-management-system SQL Injection Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter ≤ 4.5.1 CVE-2026-15453 Wordfence
6.4 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter ≤ 2.10.2.2 CVE-2026-17090 Wordfence
6.5 Medium Contest Gallery Plugin contest-gallery SQL Injection Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' ≤ 30.0.7 CVE-2026-16586 Wordfence
5.3 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause ≤ 1.15.44 CVE-2026-15993 Wordfence
6.5 Medium Groundhogg Plugin groundhogg SQL Injection Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter ≤ 4.5.14 CVE-2026-18387 Wordfence
5.3 Medium Pinpoint Booking System Plugin booking-system Price Manipulation Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter No login needed ≤ 2.9.9.6.8 CVE-2026-12128 Wordfence
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action No login needed ≤ 3.2.36 CVE-2026-8840 Wordfence
6.5 Medium Image Uploader for Welcart Plugin image-uploader-for-welcart SQL Injection Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter ≤ 1.4.6 CVE-2026-16080 Wordfence
5.9 Medium Epeken All Kurir Plugin epeken-all-kurir Authentication Bypass Unauthenticated Order Payment Confirmation Forgery No login needed ≤ 2.1.4 CVE-2026-16739 WPScan
6.8 Medium Embed Google Photos Album Easily Plugin Cross-Site Scripting Contributor+ Stored XSS via link Shortcode Attribute ≤ 2.2.1 CVE-2026-14290 WPScan
4.9 Medium affiliate-toolkit Plugin affiliate-toolkit-starter SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.8.8 CVE-2026-12743 Wordfence
6.5 Medium Bit Form Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection via 'filterText' Parameter ≤ 3.2.0 CVE-2026-16810 Wordfence
4.3 Medium Astro Booking Engine Plugin astro-booking-engine Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 1.4.0 CVE-2025-10308 Wordfence
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.6 Fixed in 5.2.7 CVE-2026-73403 Patchstack
5.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.3.7 Fixed in 0.1.3.8 CVE-2026-73401 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting < 4.16.6 Fixed in 4.16.6 CVE-2026-73357 Patchstack
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control No login needed < 4.22.10 Fixed in 4.22.10 CVE-2026-73353 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed < 4.16.6 Fixed in 4.16.6 CVE-2026-73349 Patchstack
5.9 Medium WP Data Access Plugin wp-data-access Cross-Site Scripting ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-73344 Patchstack
6.5 Medium Featured Image from URL Plugin featured-image-from-url Cross-Site Scripting ≤ 5.3.3 Fixed in 6.0.0 CVE-2026-73340 Patchstack
6.5 Medium Motors Plugin motors-car-dealership-classified-listings Broken Access Control ≤ 1.4.113 Fixed in 1.4.114 CVE-2026-66693 Patchstack
6.3 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Broken Access Control AcyChecker plugin <= 2.0.0 - Broken Access Control ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66689 Patchstack
6.5 Medium WpBookingly Plugin service-booking-manager Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-66687 Patchstack
6.5 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Broken Access Control PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control No login needed ≤ 2.5.1 CVE-2026-66660 Patchstack
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
6.5 Medium Accordion Plugin accordions-wp Cross-Site Scripting ≤ 3.0.6 CVE-2026-66471 Patchstack
6.5 Medium FluentCommunity Plugin fluent-community Cross-Site Scripting ≤ 2.7.5 Fixed in 2.7.7 CVE-2026-66467 Patchstack
6.5 Medium Internal Link Optimiser Plugin internal-link-finder Broken Access Control No login needed ≤ 5.2.7 CVE-2026-66464 Patchstack
6.5 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Cross-Site Scripting ≤ 1.18.1 CVE-2026-66460 Patchstack
6.5 Medium AI for SEO Plugin ai-for-seo Broken Access Control No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-66459 Patchstack
6.5 Medium Profile Extra Fields by BestWebSoft Plugin profile-extra-fields Cross-Site Scripting ≤ 1.3.4 CVE-2026-66456 Patchstack
6.0 Medium ReactPress Plugin reactpress Broken Access Control ≤ 3.4.0 CVE-2026-66455 Patchstack
6.5 Medium WP Social Avatar Plugin wp-social-avatar Broken Access Control No login needed ≤ 1.5 CVE-2026-66454 Patchstack
6.5 Medium Payment Forms for Paystack Plugin payment-forms-for-paystack Information Disclosure Sensitive Data Exposure ≤ 4.0.5 CVE-2026-66444 Patchstack
6.5 Medium Secure Card Gateway for ePay Paycenter (Piraeus Bank) Plugin secure-card-gateway-for-epay-paycenter-piraeus-bank Broken Access Control No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2026-61978 Patchstack
6.5 Medium AcyMailing SMTP Newsletter Plugin acymailing Cross-Site Scripting ≤ 10.11.1 Fixed in 11.0.0 CVE-2026-28182 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only