WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,251–1,300 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Dokan Pro Plugin dokan-pro PHP Object Injection ≤ 5.0.2 CVE-2026-65493 Patchstack
7.1 High Dokan Pro Plugin dokan-pro Cross-Site Scripting No login needed < 5.0.7 Fixed in 5.0.7 CVE-2026-65492 Patchstack
7.1 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65488 Patchstack
7.5 High Vino Theme vino Local File Inclusion ≤ 1.9 CVE-2026-65481 Patchstack
7.5 High Tonda Core Plugin tonda-core Local File Inclusion ≤ 2.1.2 CVE-2026-65477 Patchstack
7.6 High Uncanny Automator Plugin uncanny-automator SQL Injection ≤ 7.3.2 Fixed in 7.4.0 CVE-2026-65462 Patchstack
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 11.2.0 Fixed in 11.2.1 CVE-2026-65454 Patchstack
8.5 High MapSVG Plugin mapsvg SQL Injection ≤ 8.14.0 Fixed in 8.14.1 CVE-2026-65451 Patchstack
8.5 High MapSVG Plugin mapsvg-lite-interactive-vector-maps SQL Injection ≤ 8.14.0 Fixed in 8.14.1 CVE-2026-65450 Patchstack
7.5 High PayU India Plugin payu-india Broken Access Control No login needed ≤ 3.8.9 Fixed in 3.9.0 CVE-2026-61954 Patchstack
7.1 High Form Vibes – Database Manager for Forms Plugin form-vibes Cross-Site Scripting Database Manager for Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2026-61947 Patchstack
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
7.5 High WPDM – Premium Packages Plugin wpdm-premium-packages Broken Access Control Premium Packages plugin <= 6.2.0 - Broken Access Control No login needed ≤ 6.2.0 Fixed in 7.0.0 CVE-2026-61943 Patchstack
7.5 High Ziina Plugin ziina Authentication Bypass Broken Authentication No login needed ≤ 1.2.21 Fixed in 1.2.22 CVE-2026-59554 Patchstack
7.5 High Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Broken Access Control No login needed ≤ 9.1.4 Fixed in 9.1.5 CVE-2026-59547 Patchstack
8.1 High miniOrange Discord Integration Plugin miniorange-discord-integration Authentication Bypass Broken Authentication No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-59545 Patchstack
7.7 High Kali Forms Plugin kali-forms Arbitrary File Deletion ≤ 2.4.18 Fixed in 2.4.19 CVE-2026-59542 Patchstack
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
7.1 High Easy Form Builder Plugin easy-form-builder Cross-Site Scripting No login needed ≤ 4.0.12 Fixed in 4.0.13 CVE-2026-59517 Patchstack
7.1 High Product Enquiry for WooCommerce Plugin enquiry-quotation-for-woocommerce Cross-Site Scripting No login needed ≤ 2.2.34.43 Fixed in 2.2.34.44 CVE-2026-59512 Patchstack
7.1 High AffiliateWP Plugin affiliate-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.34.0 Fixed in 2.34.1 CVE-2026-57809 Patchstack
8.8 High ApusListing Theme apuslisting Cross-Site Request Forgery No login needed ≤ 1.2.63 Fixed in 1.2.64 CVE-2026-57785 Patchstack
7.1 High Grand Photography Theme grandphotography Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.8 CVE-2026-57769 Patchstack
7.1 High WP Google Maps Pro Plugin wp-google-maps-pro Cross-Site Scripting No login needed ≤ 10.1.02 Fixed in 10.1.03 CVE-2026-57767 Patchstack
7.1 High Breakdance Plugin breakdance Cross-Site Scripting No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-57735 Patchstack
7.1 High Smart Manager Plugin smart-manager-for-wp-e-commerce Cross-Site Scripting No login needed ≤ 8.90.0 Fixed in 8.91.0 CVE-2026-57704 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.8.5 Fixed in 12.8.6 CVE-2026-57701 Patchstack
7.1 High Slider Pro Plugin sliderpro Cross-Site Scripting No login needed ≤ 4.8.13 Fixed in 4.8.14 CVE-2026-57699 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Arbitrary File Deletion ≤ 1.6.5 Fixed in 1.6.6 CVE-2026-57696 Patchstack
7.1 High Sprout Clients Plugin sprout-clients Cross-Site Scripting No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2026-57428 Patchstack
7.1 High Download Monitor - WPForms Lock Plugin dlm-wpforms-lock Cross-Site Scripting WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2026-57427 Patchstack
7.1 High Coaching Theme coaching Cross-Site Scripting No login needed ≤ 3.9.2 Fixed in 3.9.3 CVE-2026-57397 Patchstack
7.1 High Funnel Kit Funnel Builder PRO Plugin funnel-builder-pro Cross-Site Scripting No login needed ≤ 3.15.0.7 Fixed in 3.15.0.8 CVE-2026-57374 Patchstack
7.1 High Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.9.1 Fixed in 11.9.2 CVE-2026-57370 Patchstack
7.1 High WP Booking System Plugin wp-booking-system-premium Broken Access Control < 5.12.8.1 Fixed in 5.12.8.1 CVE-2026-57367 Patchstack
8.5 High eRoom Plugin eroom-zoom-meetings-webinar SQL Injection ≤ 1.7.1 CVE-2026-25405 Patchstack
8.5 High Create Plugin mediavine-create SQL Injection ≤ 2.5.3 Fixed in 2.5.4 CVE-2026-24552 Patchstack
8.8 High MDJM Event Management Plugin mobile-dj-manager Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers ≤ 1.7.8.4 CVE-2026-15017 Wordfence
7.5 High Product Designer for WooCommerce WordPress | Lumise Plugin SQL Injection Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload No login needed ≤ 2.1.1 CVE-2026-9713 Wordfence
7.2 High ARforms Plugin arforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'password' Field Values No login needed ≤ 7.2.1 CVE-2026-12421 Wordfence
7.5 High Security Ninja (Premium) Plugin Authentication Bypass Two-Factor Authentication Bypass via secnin_skip_2fa No login needed < 5.290 Fixed in 5.290 CVE-2026-14291 WPScan
7.5 High Praison AI SEO Plugin Broken Access Control Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) No login needed < 5.0.7 Fixed in 5.0.7 CVE-2026-12082 WPScan
7.2 High FormCraft Plugin formcraft-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters No login needed ≤ 3.9.14 CVE-2026-7232 Wordfence
7.2 High SUMO Reward Points for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter No login needed ≤ 32.7.0 CVE-2026-7534 Wordfence
7.5 High Events Manager Plugin events-manager SQL Injection Unauthenticated SQL Injection via PHP Object Injection in Booking Registration No login needed < 7.3.7 Fixed in 7.3.7 CVE-2026-12987 WPScan
8.8 High Product Addons – WowAddons Plugin Cross-Site Scripting WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload No login needed < 1.6.15 Fixed in 1.6.15 CVE-2026-12968 WPScan
8.1 High WP Foodbakery Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action ≤ 4.9 CVE-2026-15802 Wordfence
7.5 High Ninja Forms Plugin ninja-forms Other Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields No login needed < 3.14.9 Fixed in 3.14.9 CVE-2026-65052 VulnCheck
7.2 High MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint ≤ 8.14.0 CVE-2026-1771 Wordfence
7.5 High Bpost Shipping Platform Plugin SQL Injection Unauthenticated SQL Injection No login needed < 3.2.3 Fixed in 3.2.3 CVE-2026-8082 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only