WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,301–1,350 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Contact Form Maker Plugin contact-form-maker SQL Injection WordPress Contact Form Maker Plugin 1.12.20 SQL Injection ≤ 1.12.20 CVE-2018-25347 VulnCheck
7.6 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons SQL Injection ≤ 4.29.0 Fixed in 4.29.1 CVE-2026-42383 Patchstack
7.5 High Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin creative-mail-by-constant-contact SQL Injection Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter No login needed ≤ 1.6.9 CVE-2026-3985 Wordfence
7.5 High WP with Spritz Plugin Local File Inclusion WordPress Plugin WP with Spritz 1.0 Remote File Inclusion No login needed 1.0 CVE-2018-25329 VulnCheck
7.5 High Malware Security and Bruteforce Firewall Plugin Path Traversal WordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory Traversal No login needed ≤ 4.20.72 CVE-2021-47977 VulnCheck
8.8 High Backup and Restore Plugin backup-and-restore-for-wp Arbitrary File Deletion WordPress Plugin Backup and Restore 1.0.3 Arbitrary File Deletion 1.0.3 CVE-2021-47979 VulnCheck
7.2 High WP Learn Manager Plugin learn-manager Cross-Site Scripting WordPress Plugin WP Learn Manager 1.1.2 Stored XSS No login needed 1.1.2 CVE-2021-47975 VulnCheck
7.5 High Digital Publications Plugin Path Traversal WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS No login needed 1.6.9 CVE-2020-37245 VulnCheck
8.2 High Membership Plugin membership-for-woocommerce SQL Injection WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx No login needed 1.4.7 CVE-2020-37244 VulnCheck
8.2 High Pricing Table Plugin pricing-table-by-supsystic SQL Injection WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS No login needed 1.8.6, 1.8.7 CVE-2020-37243 VulnCheck
8.2 High Ultimate Maps Plugin ultimate-maps-by-supsystic SQL Injection WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx No login needed 1.1.12 CVE-2020-37242 VulnCheck
8.8 High HS Brand Logo Slider Plugin hs-brand-logo-slider Arbitrary File Upload WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload 2.1 CVE-2020-37227 VulnCheck
7.5 High WPGraphQL Plugin wp-graphql Denial of Service WordPress Plugin WPGraphQL 1.3.5 Denial of Service No login needed 1.3.5 CVE-2021-47959 VulnCheck
8.1 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Deletion No login needed ≤ 2.5.2 CVE-2026-4030 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Export No login needed ≤ 2.5.2 CVE-2026-4029 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Backup Interception No login needed ≤ 2.5.2 CVE-2026-4031 Wordfence
8.1 High coreActivity: Activity Logging Plugin coreactivity PHP Object Injection Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field No login needed ≤ 3.0 CVE-2026-7635 Wordfence
7.1 High MonsterInsights Plugin google-analytics-for-wordpress Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset ≤ 10.1.2 CVE-2026-5371 Wordfence
7.7 High WP Travel Plugin wp-travel SQL Injection ≤ 11.4.0 Fixed in 11.5.0 CVE-2026-45218 Patchstack
8.5 High Xpro Elementor Addons Plugin xpro-elementor-addons SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-45214 Patchstack
7.6 High BEAR Plugin woo-bulk-editor SQL Injection ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2026-45213 Patchstack
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
8.5 High Views for WPForms Plugin views-for-wpforms-lite SQL Injection ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-42742 Patchstack
8.5 High Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin views-for-ninja-forms SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-42741 Patchstack
8.2 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.53 Fixed in 1.0.54 CVE-2026-39432 Patchstack
8.2 High Survey & Poll Plugin SQL Injection WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params No login needed 1.5.7.3 CVE-2021-47941 VulnCheck
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
7.6 High Team Member Plugin team-showcase-supreme SQL Injection ≤ 8.5 Fixed in 8.6 CVE-2025-68060 Patchstack
7.5 High WordPress Plugin Backup Migration Plugin Information Disclosure WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download No login needed 1.2.8 CVE-2023-54346 VulnCheck
7.5 High AWP Classifieds Plugin another-wordpress-classifieds-plugin SQL Injection Unauthenticated SQL Injection via 'regions' No login needed ≤ 4.4.5 CVE-2026-5100 Wordfence
7.1 High User Registration Plugin user-registration Cross-Site Scripting No login needed ≤ 5.1.5 Fixed in 5.1.6 CVE-2026-42652 Patchstack
7.6 High TaxoPress Plugin simple-tags SQL Injection ≤ 3.44.0 Fixed in 3.45.0 CVE-2026-42646 Patchstack
7.3 High SureForms Pro Plugin sureforms-pro Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-42377 Patchstack
7.7 High Templately Plugin templately Information Disclosure Sensitive Data Exposure ≤ 3.6.1 Fixed in 3.6.2 CVE-2026-42379 Patchstack
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
8.1 High Contact Form by WPForms Plugin wpforms-lite Cross-Site Request Forgery No login needed ≤ 1.10.0.2 Fixed in 1.10.0.3 CVE-2026-40764 Patchstack
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
7.1 High Cerato Plugin cerato Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.18 CVE-2025-58920 Patchstack
8.1 High VideoPro Plugin videopro Local File Inclusion No login needed ≤ 2.3.8.1 CVE-2025-58913 Patchstack
7.5 High Case Theme User Plugin case-theme-user Local File Inclusion No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-5804 Patchstack
8.2 High adivaha Travel Plugin adiaha-hotel SQL Injection WordPress adivaha Travel Plugin 2.3 SQL Injection via pid No login needed 2.3 CVE-2023-54359 VulnCheck
7.5 High OrganicFood Theme organicfood Local File Inclusion ≤ 3.6.4 CVE-2026-39684 Patchstack
7.5 High Homeo Theme homeo Local File Inclusion ≤ 1.2.59 CVE-2026-39681 Patchstack
7.5 High Freeio Theme freeio Local File Inclusion ≤ 1.3.21 CVE-2026-39679 Patchstack
7.5 High Emphires Theme emphires Local File Inclusion ≤ 3.9 CVE-2026-39677 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only