WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,251–1,300 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | AcyMailing SMTP Newsletter | Broken Access Control |
≤ 10.11.1 Fixed in 11.0.0 |
CVE-2026-28181 |
Patchstack | |
| 6.5 Medium | WP Event SOlution | Information Disclosure Sensitive Data Exposure |
≤ 4.1.18 Fixed in 4.1.19 |
CVE-2026-28174 |
Patchstack | |
| 6.5 Medium | Service Finder Booking | Broken Access Control |
≤ 6.2 |
CVE-2026-28159 |
Patchstack | |
| 6.5 Medium | Do Lasso | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 358 |
CVE-2026-28155 |
Patchstack | |
| 6.5 Medium | Tourfic | Broken Access Control |
≤ 2.23.1 Fixed in 2.23.2 |
CVE-2026-27999 |
Patchstack | |
| 6.5 Medium | Popup by Supsystic | Cross-Site Scripting |
≤ 1.11.2 Fixed in 1.12.0 |
CVE-2026-27537 |
Patchstack | |
| 5.4 Medium | Ecwid by Lightspeed Ecommerce Shopping Cart | Broken Access Control Subscriber+ Store Disconnection via 'ec_disconnect' Action |
< 7.0.9 Fixed in 7.0.9 |
CVE-2026-14332 |
WPScan | |
| 6.4 Medium | PPWP – Password Protect Pages | Cross-Site Scripting Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.9.21 |
CVE-2026-3639 |
Wordfence | |
| 5.4 Medium | ShopEngine | Information Disclosure Customer PII Disclosure via Forced Authentication No login needed |
< 4.9.3 Fixed in 4.9.3 |
CVE-2026-19088 |
WPScan | |
| 5.3 Medium | TLP Food Menu | Broken Access Control Unauthenticated Reservation Status Modification No login needed |
< 6.0.2 Fixed in 6.0.2 |
CVE-2026-13328 |
WPScan | |
| 5.3 Medium | Prevent Direct Access – Protect WordPress Files | Broken Access Control Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access No login needed |
≤ 2.8.8.8 |
CVE-2026-3835 |
Wordfence | |
| 6.5 Medium | draft-list | Cross-Site Scripting Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes |
< 2.6.4 |
CVE-2026-49466 |
GitHub_M | |
| 5.3 Medium | Quick PayPal Payments | Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed |
≤ 5.7.50 |
CVE-2026-17008 |
WPScan | |
| 5.3 Medium | Payment Button for PayPal | Price Manipulation Unauthenticated Payment Price Manipulation No login needed |
≤ 1.2.3.44 |
CVE-2026-16990 |
WPScan | |
| 6.5 Medium | Kirki | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Email Actions No login needed |
< 6.2.1 Fixed in 6.2.1 |
CVE-2026-16747 |
WPScan | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-16621 |
WPScan | |
| 5.3 Medium | Welcart e-Commerce | Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed |
< 2.11.33 Fixed in 2.11.33 |
CVE-2026-15213 |
WPScan | |
| 6.5 Medium | Wallet System for WooCommerce | Price Manipulation Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount |
< 2.7.10 Fixed in 2.7.10 |
CVE-2026-15045 |
WPScan | |
| 5.4 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget |
< 1.7.1065 Fixed in 1.7.1065 |
CVE-2026-19217 |
WPScan | |
| 5.3 Medium | Order Sync with Zendesk for WooCommerce | Information Disclosure Unauthenticated Customer Order Data Disclosure No login needed |
< 2.2.3 Fixed in 2.2.3 |
CVE-2026-19073 |
WPScan | |
| 4.3 Medium | ProSolution WP Client | Broken Access Control Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-19052 |
WPScan | |
| 6.4 Medium | ProSolution WP Client | Server-Side Request Forgery Subscriber+ SSRF via proSol_url_validate |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-19050 |
WPScan | |
| 4.3 Medium | WP Photo Album Plus | Arbitrary File Upload Subscriber+ Cross-Album File Upload via Missing Authorization |
< 9.2.09.002 Fixed in 9.2.09.002 |
CVE-2026-18962 |
WPScan | |
| 6.5 Medium | WPC Admin Columns | Information Disclosure Subscriber+ Arbitrary User/Post/Term Meta Disclosure |
< 2.3.4 Fixed in 2.3.4 |
CVE-2026-18943 |
WPScan | |
| 4.3 Medium | Cookie Consent | Broken Access Control Subscriber+ MaxMind License Key Update |
0.0.9 – < 0.0.10 Fixed in 0.0.10 |
CVE-2026-18046 |
WPScan | |
| 5.3 Medium | User Access Manager | Information Disclosure Unauthenticated Restricted Content Disclosure via REST API No login needed |
< 2.3.15 Fixed in 2.3.15 |
CVE-2026-18035 |
WPScan | |
| 6.1 Medium | WP Photo Album Plus | Cross-Site Scripting Reflected XSS via lbstart No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-17013 |
WPScan | |
| 5.3 Medium | WP Travel Engine | Information Disclosure Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart No login needed |
< 6.8.5 Fixed in 6.8.5 |
CVE-2026-16737 |
WPScan | |
| 5.4 Medium | Welcart e-Commerce | Cross-Site Scripting Author+ Stored XSS via Product Name |
< 2.11.34 Fixed in 2.11.34 |
CVE-2026-16066 |
WPScan | |
| 4.3 Medium | Cookie Consent | Information Disclosure Subscriber+ Consent Settings Update and Consent Log Disclosure |
< 0.0.10 Fixed in 0.0.10 |
CVE-2026-15388 |
WPScan | |
| 5.4 Medium | Patterns Kit | Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link |
≤ 1.0.3 |
CVE-2026-15249 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Broken Access Control Subscriber+ Campaign Creation via Missing Authorization |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14859 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Information Disclosure Subscriber+ Order Data Disclosure via IDOR |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14858 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Broken Access Control Subscriber+ Campaign Update Modification via IDOR |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14857 |
WPScan | |
| 4.3 Medium | KiviCare | Information Disclosure Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR |
< 4.5.2 Fixed in 4.5.2 |
CVE-2026-13612 |
WPScan | |
| 4.3 Medium | Eventin | Information Disclosure Contributor+ Order Information Disclosure via IDOR |
4.1.9 – < 4.1.20 Fixed in 4.1.20 |
CVE-2026-13177 |
WPScan | |
| 6.5 Medium | Eventin | Information Disclosure Contributor+ Customer PII Disclosure via REST API |
< 4.1.20 Fixed in 4.1.20 |
CVE-2026-13168 |
WPScan | |
| 6.5 Medium | LearnPress | Information Disclosure Subscriber+ Sensitive Information Exposure via AI Assistant |
< 4.4.4 Fixed in 4.4.4 |
CVE-2026-12976 |
WPScan | |
| 4.3 Medium | Ray Enterprise Translation | Broken Access Control Subscriber+ Language Addition and Deletion |
≤ 1.7.3 |
CVE-2026-14549 |
WPScan | |
| 6.5 Medium | Ray Enterprise Translation | Broken Access Control Subscriber+ Arbitrary API Token Update |
≤ 1.7.3 |
CVE-2026-14548 |
WPScan | |
| 6.4 Medium | Kirki - Freeform Page Builder, Website Builder & Customizer | Cross-Site Scripting Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode |
≤ 6.2.0 |
CVE-2026-16974 |
Wordfence | |
| 6.5 Medium | sucuri-wordpress-plugin | Path Traversal Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php |
≤ 2.7.3 |
CVE-2026-73033 |
VulnCheck | |
| 5.4 Medium | WP Umbrella | Cross-Site Request Forgery No login needed |
2.24.2 – 2.26.2 Fixed in 2.27.0 |
CVE-2026-66642 |
Patchstack | |
| 6.5 Medium | Copy & Delete Posts | Broken Access Control Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-19077 |
WPScan | |
| 5.3 Medium | Advanced Classifieds & Directory Pro | Information Disclosure Unauthenticated Non-Public Listing Custom Field Disclosure No login needed |
< 3.4.3 Fixed in 3.4.3 |
CVE-2026-19074 |
WPScan | |
| 4.3 Medium | FoodBoxBooker | Broken Access Control Subscriber+ Arbitrary User Profile Update |
< 1.0.8 Fixed in 1.0.8 |
CVE-2026-18200 |
WPScan | |
| 6.8 Medium | s2Member | Cross-Site Scripting Contributor+ Stored XSS via Shortcode |
< 260805 Fixed in 260805 |
CVE-2026-15047 |
WPScan | |
| 4.8 Medium | Salon Booking System – Free Version | Broken Access Control Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback No login needed |
≤ 10.30.33 |
CVE-2026-17023 |
WPScan | |
| 4.1 Medium | Vitepos | SQL Injection Admin+ SQL Injection via product-details-report |
< 3.6.0 Fixed in 3.6.0 |
CVE-2026-14238 |
WPScan | |
| 5.3 Medium | Salon Booking System – Free Version | Broken Access Control Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering No login needed |
< 10.30.34 Fixed in 10.30.34 |
CVE-2026-17021 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.