WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,301–1,350 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter No login needed ≤ 4.4.1 CVE-2026-14989 Wordfence
8.8 High Various Newfold Plugins Various Versions Plugin wp-module-data Authentication Bypass Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret ≤ 2.3.5, ≤ 2.5.2, ≤ 2.9.7, … CVE-2026-80099 Wordfence
8.8 High YITH WooCommerce Waitlist Premium Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user ≤ 3.35.0 CVE-2026-14359 Wordfence
7.2 High PublishPress Capabilities Plugin capability-manager-enhanced Privilege Escalation Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant ≤ 2.50.0 CVE-2026-75927 Wordfence
6.4 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program Plugin mycred Cross-Site Scripting Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute ≤ 3.2.4 CVE-2026-17149 Wordfence
4.3 Medium Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) Plugin wp-event-solution Broken Access Control Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption ≤ 4.1.22 CVE-2026-15398 Wordfence
6.5 Medium WPMR Google Feed Manager for WooCommerce Plugin wp-product-feed-manager SQL Injection Authenticated (Administrator+) SQL Injection via 'feed' Parameter ≤ 2.23.7 CVE-2026-19778 Wordfence
4.3 Medium Checkout Custom Fields Builder for WooCommerce Plugin checkout-custom-fields-builder-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter ≤ 1.1.5 CVE-2026-19802 Wordfence
6.5 Medium Contact Form 7 Captcha Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation No login needed 0.1.7 – < 0.1.9 Fixed in 0.1.9 CVE-2026-85117 WPScan
5.3 Medium WP Express Checkout Plugin Price Manipulation Unauthenticated Payment Bypass via wpec_process_empty_payment No login needed < 2.5.0 Fixed in 2.5.0 CVE-2026-83537 WPScan
4.8 Medium Hustle Plugin wordpress-popup Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Success Message Placeholders No login needed 7.0.0.1 – < 7.8.14.2 Fixed in 7.8.14.2 CVE-2026-80440 WPScan
6.5 Medium Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Comment Text No login needed < 6.87 Fixed in 6.87 CVE-2026-19855 WPScan
5.4 Medium Orbit Fox Plugin Cross-Site Scripting Contributor+ Stored XSS via Beaver Builder Pricing Table Widget < 3.0.9 Fixed in 3.0.9 CVE-2026-85418 WPScan
5.4 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 4.4.2 Fixed in 4.4.2 CVE-2026-85133 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Information Disclosure Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan 4.0.2 – < 4.4.2 Fixed in 4.4.2 CVE-2026-85132 WPScan
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Price Manipulation Unauthenticated Price Manipulation via IDOR No login needed < 3.7 Fixed in 3.7 CVE-2026-85037 WPScan
5.3 Medium Kirki Plugin kirki Information Disclosure Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter No login needed 6.2.1 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84222 WPScan
4.1 Medium Quentn WP Plugin quentn-wp SQL Injection Admin+ SQLi via 'orderby'/'order' Parameter < 1.2.15 Fixed in 1.2.15 CVE-2026-84113 WPScan
8.6 High Quentn WP Plugin quentn-wp SQL Injection Unauthenticated SQLi via 'qntn_wp' Parameter No login needed 1.2.13 – < 1.2.15 Fixed in 1.2.15 CVE-2026-84068 WPScan
6.8 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Table Widget 3.7.1 – < 3.10.4 Fixed in 3.10.4 CVE-2026-83541 WPScan
5.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Unauthenticated Course Enrollment Disclosure No login needed 1.3.1 – < 3.4.0 Fixed in 3.4.0 CVE-2026-82848 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Banner Settings Overwrite and A/B Test Data Reset 3.6.5 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82185 WPScan
5.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Unauthenticated IAB TCF Consent Option Update No login needed 3.5.0 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82184 WPScan
4.7 Medium Groundhogg Plugin Open Redirect Open Redirect via 'redirect_to' Parameter No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-81741 WPScan
5.3 Medium SupportCandy Plugin supportcandy Information Disclosure Unauthenticated Ticket Content Disclosure via Auth Code Leak No login needed 3.3.6 – < 3.5.3 Fixed in 3.5.3 CVE-2026-81022 WPScan
5.3 Medium SupportCandy Plugin supportcandy Information Disclosure Unauthenticated Ticket Attachment Disclosure No login needed 3.2.9 – < 3.5.3 Fixed in 3.5.3 CVE-2026-81021 WPScan
5.9 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control Subscriber+ Stored Payment Method Assignment via IDOR 1.1.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80341 WPScan
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Information Disclosure Unauthenticated Customer PII Disclosure via order-pay No login needed 1.0.0 – < 2.0.26 Fixed in 2.0.26 CVE-2026-80340 WPScan
5.3 Medium Payment Plugins for Stripe WooCommerce Plugin woo-stripe-payment Information Disclosure Unauthenticated Customer PII Disclosure via order-pay No login needed 4.0.0 – < 4.0.12 Fixed in 4.0.12 CVE-2026-80339 WPScan
6.5 Medium Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Subscriber+ Gift Card Theft and Destruction via Unauthorized Redemption < 3.2.10 Fixed in 3.2.10 CVE-2026-75861 WPScan
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-18042 WPScan
7.5 High Loops & Logic Plugin Information Disclosure Unauthenticated User Data and Site Option Disclosure No login needed < 4.3.0 Fixed in 4.3.0 CVE-2026-16960 WPScan
8.6 High ELEX WooCommerce Request a Quote Plugin elex-request-a-quote SQL Injection Unauthenticated SQLi via variation_id No login needed < 2.4.1 Fixed in 2.4.1 CVE-2026-14962 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13146 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Payment Reset No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13144 WPScan
6.8 Medium Content Mask Plugin content-mask Cross-Site Scripting Contributor+ Stored XSS via Post Scripts and Styles 1.7.1 – < 1.8.5.6 Fixed in 1.8.5.6 CVE-2025-15690 WPScan
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode ≤ 10.8.0 CVE-2026-75905 Wordfence
4.3 Medium ilGhera Reviso Exporter for WooCommerce Plugin wc-exporter-for-reviso Broken Access Control Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function ≤ 1.2.3 CVE-2026-8615 Wordfence
5.3 Medium WPFunnels Plugin wpfunnels Broken Access Control Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation via 'wpfnl_load_payment' AJAX Action No login needed ≤ 3.12.13 CVE-2026-84908 Wordfence
7.2 High WPBot Plugin chatbot Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter No login needed ≤ 8.7.3 CVE-2026-83593 Wordfence
8.1 High Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Authentication Bypass Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint No login needed ≤ 3.9.8 CVE-2026-76009 Wordfence
4.3 Medium Awesome Support Plugin awesome-support Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter ≤ 6.3.9 CVE-2026-19946 Wordfence
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter ≤ 2.2.1 CVE-2026-19945 Wordfence
5.4 Medium Eventin Plugin wp-event-solution Broken Access Control Missing Authorization to Authenticated (Subscriber+) Notification Flow Management via notification-flow REST API Endpoint ≤ 4.1.17 CVE-2026-11821 Wordfence
6.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter ≤ 4.5.5 CVE-2026-75966 Wordfence
4.9 Medium WP Crowdfunding Plugin wp-crowdfunding SQL Injection Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta ≤ 2.2.1 CVE-2026-19944 Wordfence
4.9 Medium Mail Mint Plugin mail-mint SQL Injection Authenticated (Custom+) SQL Injection via 'status' Parameter ≤ 1.31.0 CVE-2026-19800 Wordfence
6.6 Medium Ninja Forms Plugin ninja-forms PHP Object Injection Authenticated (Administrator+) PHP Object Injection via Form Import ≤ 3.14.6 CVE-2026-11363 Wordfence
6.4 Medium My Calendar Plugin my-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes ≤ 3.8.3 CVE-2026-77187 Wordfence
6.4 Medium My Calendar Plugin my-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'fallback' Shortcode Attribute ≤ 3.8.3 CVE-2026-77186 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only