WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,251–1,300 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium AcyMailing SMTP Newsletter Plugin acymailing Broken Access Control ≤ 10.11.1 Fixed in 11.0.0 CVE-2026-28181 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Information Disclosure Sensitive Data Exposure ≤ 4.1.18 Fixed in 4.1.19 CVE-2026-28174 Patchstack
6.5 Medium Service Finder Booking Plugin sf-booking Broken Access Control ≤ 6.2 CVE-2026-28159 Patchstack
6.5 Medium Do Lasso Plugin lasso Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 358 CVE-2026-28155 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.23.1 Fixed in 2.23.2 CVE-2026-27999 Patchstack
6.5 Medium Popup by Supsystic Plugin popup-by-supsystic Cross-Site Scripting ≤ 1.11.2 Fixed in 1.12.0 CVE-2026-27537 Patchstack
5.4 Medium Ecwid by Lightspeed Ecommerce Shopping Cart Plugin ecwid-shopping-cart Broken Access Control Subscriber+ Store Disconnection via 'ec_disconnect' Action < 7.0.9 Fixed in 7.0.9 CVE-2026-14332 WPScan
6.4 Medium PPWP – Password Protect Pages Plugin password-protect-page Cross-Site Scripting Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.9.21 CVE-2026-3639 Wordfence
5.4 Medium ShopEngine Plugin Information Disclosure Customer PII Disclosure via Forced Authentication No login needed < 4.9.3 Fixed in 4.9.3 CVE-2026-19088 WPScan
5.3 Medium TLP Food Menu Plugin Broken Access Control Unauthenticated Reservation Status Modification No login needed < 6.0.2 Fixed in 6.0.2 CVE-2026-13328 WPScan
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Broken Access Control Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access No login needed ≤ 2.8.8.8 CVE-2026-3835 Wordfence
6.5 Medium draft-list Plugin Cross-Site Scripting Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes < 2.6.4 CVE-2026-49466 GitHub_M
5.3 Medium Quick PayPal Payments Plugin quick-paypal-payments Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed ≤ 5.7.50 CVE-2026-17008 WPScan
5.3 Medium Payment Button for PayPal Plugin wp-paypal Price Manipulation Unauthenticated Payment Price Manipulation No login needed ≤ 1.2.3.44 CVE-2026-16990 WPScan
6.5 Medium Kirki Plugin kirki Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Email Actions No login needed < 6.2.1 Fixed in 6.2.1 CVE-2026-16747 WPScan
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-16621 WPScan
5.3 Medium Welcart e-Commerce Plugin usc-e-shop Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed < 2.11.33 Fixed in 2.11.33 CVE-2026-15213 WPScan
6.5 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Price Manipulation Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount < 2.7.10 Fixed in 2.7.10 CVE-2026-15045 WPScan
5.4 Medium Royal Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget < 1.7.1065 Fixed in 1.7.1065 CVE-2026-19217 WPScan
5.3 Medium Order Sync with Zendesk for WooCommerce Plugin mwb-zendesk-woo-order-sync Information Disclosure Unauthenticated Customer Order Data Disclosure No login needed < 2.2.3 Fixed in 2.2.3 CVE-2026-19073 WPScan
4.3 Medium ProSolution WP Client Plugin prosolution-wp-client Broken Access Control Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls < 2.0.9 Fixed in 2.0.9 CVE-2026-19052 WPScan
6.4 Medium ProSolution WP Client Plugin prosolution-wp-client Server-Side Request Forgery Subscriber+ SSRF via proSol_url_validate < 2.0.9 Fixed in 2.0.9 CVE-2026-19050 WPScan
4.3 Medium WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload Subscriber+ Cross-Album File Upload via Missing Authorization < 9.2.09.002 Fixed in 9.2.09.002 CVE-2026-18962 WPScan
6.5 Medium WPC Admin Columns Plugin wpc-admin-columns Information Disclosure Subscriber+ Arbitrary User/Post/Term Meta Disclosure < 2.3.4 Fixed in 2.3.4 CVE-2026-18943 WPScan
4.3 Medium Cookie Consent Plugin Broken Access Control Subscriber+ MaxMind License Key Update 0.0.9 – < 0.0.10 Fixed in 0.0.10 CVE-2026-18046 WPScan
5.3 Medium User Access Manager Plugin user-access-manager Information Disclosure Unauthenticated Restricted Content Disclosure via REST API No login needed < 2.3.15 Fixed in 2.3.15 CVE-2026-18035 WPScan
6.1 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Reflected XSS via lbstart No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-17013 WPScan
5.3 Medium WP Travel Engine Plugin wp-travel-engine Information Disclosure Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart No login needed < 6.8.5 Fixed in 6.8.5 CVE-2026-16737 WPScan
5.4 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Author+ Stored XSS via Product Name < 2.11.34 Fixed in 2.11.34 CVE-2026-16066 WPScan
4.3 Medium Cookie Consent Plugin Information Disclosure Subscriber+ Consent Settings Update and Consent Log Disclosure < 0.0.10 Fixed in 0.0.10 CVE-2026-15388 WPScan
5.4 Medium Patterns Kit Plugin Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link ≤ 1.0.3 CVE-2026-15249 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Creation via Missing Authorization < 2.2.1 Fixed in 2.2.1 CVE-2026-14859 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Information Disclosure Subscriber+ Order Data Disclosure via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14858 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Update Modification via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14857 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Information Disclosure Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR < 4.5.2 Fixed in 4.5.2 CVE-2026-13612 WPScan
4.3 Medium Eventin Plugin wp-event-solution Information Disclosure Contributor+ Order Information Disclosure via IDOR 4.1.9 – < 4.1.20 Fixed in 4.1.20 CVE-2026-13177 WPScan
6.5 Medium Eventin Plugin wp-event-solution Information Disclosure Contributor+ Customer PII Disclosure via REST API < 4.1.20 Fixed in 4.1.20 CVE-2026-13168 WPScan
6.5 Medium LearnPress Plugin learnpress Information Disclosure Subscriber+ Sensitive Information Exposure via AI Assistant < 4.4.4 Fixed in 4.4.4 CVE-2026-12976 WPScan
4.3 Medium Ray Enterprise Translation Plugin Broken Access Control Subscriber+ Language Addition and Deletion ≤ 1.7.3 CVE-2026-14549 WPScan
6.5 Medium Ray Enterprise Translation Plugin Broken Access Control Subscriber+ Arbitrary API Token Update ≤ 1.7.3 CVE-2026-14548 WPScan
6.4 Medium Kirki - Freeform Page Builder, Website Builder & Customizer Plugin Cross-Site Scripting Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode ≤ 6.2.0 CVE-2026-16974 Wordfence
6.5 Medium sucuri-wordpress-plugin Plugin Path Traversal Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php ≤ 2.7.3 CVE-2026-73033 VulnCheck
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
6.5 Medium Copy & Delete Posts Plugin Broken Access Control Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization < 1.5.5 Fixed in 1.5.5 CVE-2026-19077 WPScan
5.3 Medium Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Information Disclosure Unauthenticated Non-Public Listing Custom Field Disclosure No login needed < 3.4.3 Fixed in 3.4.3 CVE-2026-19074 WPScan
4.3 Medium FoodBoxBooker Plugin foodboxbooker Broken Access Control Subscriber+ Arbitrary User Profile Update < 1.0.8 Fixed in 1.0.8 CVE-2026-18200 WPScan
6.8 Medium s2Member Plugin s2member Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 260805 Fixed in 260805 CVE-2026-15047 WPScan
4.8 Medium Salon Booking System – Free Version Plugin Broken Access Control Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback No login needed ≤ 10.30.33 CVE-2026-17023 WPScan
4.1 Medium Vitepos Plugin vitepos-lite SQL Injection Admin+ SQL Injection via product-details-report < 3.6.0 Fixed in 3.6.0 CVE-2026-14238 WPScan
5.3 Medium Salon Booking System – Free Version Plugin Broken Access Control Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering No login needed < 10.30.34 Fixed in 10.30.34 CVE-2026-17021 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only