WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1,301–1,350 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | CRT Addons for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Contact Form No login needed |
< 1.6.7 Fixed in 1.6.7 |
CVE-2026-11767 |
WPScan | |
| 7.1 High | Tag Groups | Cross-Site Scripting Reflected XSS via 'tag_groups_task' Parameter No login needed |
< 2.2.0 Fixed in 2.2.0 |
CVE-2026-9833 |
WPScan | |
| 8.1 High | Passwordless Login by VentraConnect | Privilege Escalation Unauthenticated Account Takeover via Email OTP Brute Force No login needed |
< 1.4.1 Fixed in 1.4.1 |
CVE-2026-13142 |
WPScan | |
| 7.1 High | LearnPress | Cross-Site Scripting Reflected XSS via c_search No login needed |
< 4.4.1 Fixed in 4.4.1 |
CVE-2026-12970 |
WPScan | |
| 7.5 High | SlimStat Analytics | Cross-Site Scripting Unauthenticated Stored XSS via CF-IPCountry Header No login needed |
< 5.5.0 Fixed in 5.5.0 |
CVE-2026-12592 |
WPScan | |
| 8.6 High | Modern Events Calendar (Lite & Pro) | SQL Injection Unauthenticated SQL Injection via mec_list_load_more No login needed |
< 7.34.0 Fixed in 7.34.0 |
CVE-2026-11349 |
WPScan | |
| 8.8 High | Unlimited Elements for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed |
< 2.0.11 Fixed in 2.0.11 |
CVE-2026-10081 |
WPScan | |
| 8.1 High | User Registration & Membership | Privilege Escalation Unauthenticated Privilege Escalation via Unbound members_data Membership ID No login needed |
< 5.2.3 Fixed in 5.2.3 |
CVE-2026-11961 |
WPScan | |
| 7.5 High | PhonePe Payment Solutions | Price Manipulation Unauthenticated Payment Bypass via Forged Callback No login needed |
< 3.1.0 Fixed in 3.1.0 |
CVE-2026-11575 |
WPScan | |
| 7.5 High | LearnPress | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints No login needed |
≤ 4.4.1 |
CVE-2026-13765 |
Wordfence | |
| 8.8 High | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | Arbitrary File Upload Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion |
≤ 4.16.18 |
CVE-2026-13352 |
Wordfence | |
| 7.2 High | Kali Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value No login needed |
≤ 2.4.18 |
CVE-2026-15395 |
Wordfence | |
| 8.8 High | WPFunnels | Privilege Escalation Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter |
≤ 3.12.8 |
CVE-2026-15103 |
Wordfence | |
| 8.8 High | Loco Translate | Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter No login needed |
≤ 2.8.5 |
CVE-2026-15005 |
Wordfence | |
| 8.8 High | Digits: WordPress Mobile Number Signup and Login | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter |
≤ 9.1.0.5 |
CVE-2026-13741 |
Wordfence | |
| 8.1 High | Uncanny Automator | PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token No login needed |
≤ 7.3.1.4 |
CVE-2026-15008 |
Wordfence | |
| 7.2 High | Breakdance | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Webhook Action Details No login needed |
≤ 2.7.1 |
CVE-2026-7543 |
Wordfence | |
| 7.1 High | FunnelKit | Cross-Site Scripting Reflected XSS via Divi Optin Form No login needed |
< 3.15.0.6 Fixed in 3.15.0.6 |
CVE-2026-12978 |
WPScan | |
| 8.1 High | Abandoned Cart Lite for WooCommerce | Privilege Escalation Unauthenticated Account Takeover via Malleable Recovery-Link Token No login needed |
< 6.8.2 Fixed in 6.8.2 |
CVE-2026-12585 |
WPScan | |
| 8.8 High | Redux Framework | Privilege Escalation Subscriber+ Privilege Escalation to Administrator |
< 4.5.13 Fixed in 4.5.13 |
CVE-2026-12525 |
WPScan | |
| 7.2 High | RPB Chessboard | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed |
≤ 8.1.2 |
CVE-2026-13042 |
Wordfence | |
| 7.5 High | Advance Product Search- Voice & Ajax Search for WooCommerce | SQL Injection Unauthenticated SQL Injection via 's' and 'match' Parameter No login needed |
≤ 1.4.4 |
CVE-2026-12753 |
Wordfence | |
| 7.5 High | Gravity Forms | Path Traversal Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter No login needed |
≤ 2.10.4 |
CVE-2026-12997 |
Wordfence | |
| 8.6 High | Quotes Llama | SQL Injection Unauthenticated SQL Injection via sc Parameter No login needed |
< 3.1.6 Fixed in 3.1.6 |
CVE-2026-12512 |
WPScan | |
| 8.1 High | Shibboleth | Authentication Bypass Unauthenticated Administrator Account Creation via Identity Header Spoofing No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-12281 |
WPScan | |
| 8.1 High | Newsletters | PHP Object Injection Unauthenticated PHP Object Injection via Subscriber Custom Field No login needed |
< 4.15 Fixed in 4.15 |
CVE-2026-12583 |
WPScan | |
| 8.1 High | AI Engine | Path Traversal Editor+ Arbitrary File Write via Path Traversal |
< 3.5.5 Fixed in 3.5.5 |
CVE-2026-12511 |
WPScan | |
| 7.1 High | ووسلام – همگام سازی ووکامرس و باسلام | Cross-Site Request Forgery همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2026-61956 |
Patchstack | |
| 7.6 High | گرویتی فرم فارسی | SQL Injection |
≤ 3.0.2 Fixed in 3.0.3 |
CVE-2026-61955 |
Patchstack | |
| 7.2 High | Real Testimonials | PHP Object Injection |
≤ 3.1.15 Fixed in 3.1.16 |
CVE-2026-59521 |
Patchstack | |
| 7.1 High | ICS Calendar | Cross-Site Scripting No login needed |
≤ 12.1.1 Fixed in 12.1.1.1 |
CVE-2026-59516 |
Patchstack | |
| 7.1 High | Funnel Builder by FunnelKit | Cross-Site Scripting No login needed |
≤ 3.15.0.8 Fixed in 3.15.0.9 |
CVE-2026-57816 |
Patchstack | |
| 7.5 High | Forminator | Path Traversal Arbitrary File Download No login needed |
≤ 1.55.0.2 Fixed in 1.55.1 |
CVE-2026-57815 |
Patchstack | |
| 7.1 High | Forminator | Cross-Site Scripting No login needed |
≤ 1.55.0.1 Fixed in 1.55.0.2 |
CVE-2026-57814 |
Patchstack | |
| 8.5 High | APIExperts Square for WooCommerce | SQL Injection |
≤ 4.7.4 Fixed in 4.7.5 |
CVE-2026-57810 |
Patchstack | |
| 7.5 High | Tonda | Local File Inclusion |
≤ 2.5 |
CVE-2026-57805 |
Patchstack | |
| 7.5 High | TheGem Theme Elements (for Elementor) | Local File Inclusion |
< 5.12.1.1 Fixed in 5.12.1.1 |
CVE-2026-57804 |
Patchstack | |
| 7.5 High | Struktur Core | Local File Inclusion |
< 2.7 Fixed in 2.7 |
CVE-2026-57803 |
Patchstack | |
| 7.5 High | Struktur | Local File Inclusion |
< 2.7 Fixed in 2.7 |
CVE-2026-57802 |
Patchstack | |
| 7.5 High | SetSail | Local File Inclusion |
≤ 2.1 |
CVE-2026-57801 |
Patchstack | |
| 7.5 High | Overworld | Local File Inclusion |
≤ 1.5 |
CVE-2026-57800 |
Patchstack | |
| 7.5 High | Nuss | Local File Inclusion |
≤ 1.3.6 |
CVE-2026-57799 |
Patchstack | |
| 7.5 High | NewsPlus Shortcodes | Local File Inclusion |
≤ 4.2.0 |
CVE-2026-57798 |
Patchstack | |
| 7.5 High | Leedo | Local File Inclusion |
≤ 3.0.0 |
CVE-2026-57796 |
Patchstack | |
| 7.5 High | Kitchor | Local File Inclusion |
≤ 1.4.3 |
CVE-2026-57795 |
Patchstack | |
| 7.5 High | Golo Framework | Local File Inclusion |
≤ 1.7.3 |
CVE-2026-57794 |
Patchstack | |
| 7.5 High | Flow | Local File Inclusion |
≤ 1.8 |
CVE-2026-57793 |
Patchstack | |
| 7.5 High | Dør | Local File Inclusion |
≤ 2.4.1 |
CVE-2026-57792 |
Patchstack | |
| 7.5 High | Brook | Local File Inclusion |
≤ 2.9.0 |
CVE-2026-57791 |
Patchstack | |
| 7.5 High | Billey | Local File Inclusion |
≤ 2.1.8 |
CVE-2026-57790 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.