WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,301–1,350 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High CRT Addons for Elementor Plugin Cross-Site Scripting Unauthenticated Stored XSS via Contact Form No login needed < 1.6.7 Fixed in 1.6.7 CVE-2026-11767 WPScan
7.1 High Tag Groups Plugin Cross-Site Scripting Reflected XSS via 'tag_groups_task' Parameter No login needed < 2.2.0 Fixed in 2.2.0 CVE-2026-9833 WPScan
8.1 High Passwordless Login by VentraConnect Plugin Privilege Escalation Unauthenticated Account Takeover via Email OTP Brute Force No login needed < 1.4.1 Fixed in 1.4.1 CVE-2026-13142 WPScan
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected XSS via c_search No login needed < 4.4.1 Fixed in 4.4.1 CVE-2026-12970 WPScan
7.5 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored XSS via CF-IPCountry Header No login needed < 5.5.0 Fixed in 5.5.0 CVE-2026-12592 WPScan
8.6 High Modern Events Calendar (Lite & Pro) Plugin SQL Injection Unauthenticated SQL Injection via mec_list_load_more No login needed < 7.34.0 Fixed in 7.34.0 CVE-2026-11349 WPScan
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-10081 WPScan
8.1 High User Registration & Membership Plugin user-registration Privilege Escalation Unauthenticated Privilege Escalation via Unbound members_data Membership ID No login needed < 5.2.3 Fixed in 5.2.3 CVE-2026-11961 WPScan
7.5 High PhonePe Payment Solutions Plugin phonepe-payment-solutions Price Manipulation Unauthenticated Payment Bypass via Forged Callback No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-11575 WPScan
7.5 High LearnPress Plugin learnpress Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints No login needed ≤ 4.4.1 CVE-2026-13765 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary File Upload Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion ≤ 4.16.18 CVE-2026-13352 Wordfence
7.2 High Kali Forms Plugin kali-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value No login needed ≤ 2.4.18 CVE-2026-15395 Wordfence
8.8 High WPFunnels Plugin wpfunnels Privilege Escalation Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter ≤ 3.12.8 CVE-2026-15103 Wordfence
8.8 High Loco Translate Plugin loco-translate Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter No login needed ≤ 2.8.5 CVE-2026-15005 Wordfence
8.8 High Digits: WordPress Mobile Number Signup and Login Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter ≤ 9.1.0.5 CVE-2026-13741 Wordfence
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token No login needed ≤ 7.3.1.4 CVE-2026-15008 Wordfence
7.2 High Breakdance Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Webhook Action Details No login needed ≤ 2.7.1 CVE-2026-7543 Wordfence
7.1 High FunnelKit Plugin funnel-builder Cross-Site Scripting Reflected XSS via Divi Optin Form No login needed < 3.15.0.6 Fixed in 3.15.0.6 CVE-2026-12978 WPScan
8.1 High Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Privilege Escalation Unauthenticated Account Takeover via Malleable Recovery-Link Token No login needed < 6.8.2 Fixed in 6.8.2 CVE-2026-12585 WPScan
8.8 High Redux Framework Plugin redux-framework Privilege Escalation Subscriber+ Privilege Escalation to Administrator < 4.5.13 Fixed in 4.5.13 CVE-2026-12525 WPScan
7.2 High RPB Chessboard Plugin rpb-chessboard Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 8.1.2 CVE-2026-13042 Wordfence
7.5 High Advance Product Search- Voice & Ajax Search for WooCommerce Plugin th-advance-product-search SQL Injection Unauthenticated SQL Injection via 's' and 'match' Parameter No login needed ≤ 1.4.4 CVE-2026-12753 Wordfence
7.5 High Gravity Forms Plugin Path Traversal Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter No login needed ≤ 2.10.4 CVE-2026-12997 Wordfence
8.6 High Quotes Llama Plugin quotes-llama SQL Injection Unauthenticated SQL Injection via sc Parameter No login needed < 3.1.6 Fixed in 3.1.6 CVE-2026-12512 WPScan
8.1 High Shibboleth Plugin shibboleth Authentication Bypass Unauthenticated Administrator Account Creation via Identity Header Spoofing No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-12281 WPScan
8.1 High Newsletters Plugin newsletters-lite PHP Object Injection Unauthenticated PHP Object Injection via Subscriber Custom Field No login needed < 4.15 Fixed in 4.15 CVE-2026-12583 WPScan
8.1 High AI Engine Plugin ai-engine Path Traversal Editor+ Arbitrary File Write via Path Traversal < 3.5.5 Fixed in 3.5.5 CVE-2026-12511 WPScan
7.1 High ووسلام – همگام سازی ووکامرس و باسلام Plugin sync-basalam Cross-Site Request Forgery همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-61956 Patchstack
7.6 High گرویتی فرم فارسی Plugin persian-gravity-forms SQL Injection ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-61955 Patchstack
7.2 High Real Testimonials Plugin testimonial-free PHP Object Injection ≤ 3.1.15 Fixed in 3.1.16 CVE-2026-59521 Patchstack
7.1 High ICS Calendar Plugin ics-calendar Cross-Site Scripting No login needed ≤ 12.1.1 Fixed in 12.1.1.1 CVE-2026-59516 Patchstack
7.1 High Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting No login needed ≤ 3.15.0.8 Fixed in 3.15.0.9 CVE-2026-57816 Patchstack
7.5 High Forminator Plugin forminator Path Traversal Arbitrary File Download No login needed ≤ 1.55.0.2 Fixed in 1.55.1 CVE-2026-57815 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.55.0.1 Fixed in 1.55.0.2 CVE-2026-57814 Patchstack
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.4 Fixed in 4.7.5 CVE-2026-57810 Patchstack
7.5 High Tonda Theme tonda Local File Inclusion ≤ 2.5 CVE-2026-57805 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-57804 Patchstack
7.5 High Struktur Core Plugin struktur-core Local File Inclusion < 2.7 Fixed in 2.7 CVE-2026-57803 Patchstack
7.5 High Struktur Theme struktur Local File Inclusion < 2.7 Fixed in 2.7 CVE-2026-57802 Patchstack
7.5 High SetSail Theme setsail Local File Inclusion ≤ 2.1 CVE-2026-57801 Patchstack
7.5 High Overworld Plugin overworld Local File Inclusion ≤ 1.5 CVE-2026-57800 Patchstack
7.5 High Nuss Plugin nuss Local File Inclusion ≤ 1.3.6 CVE-2026-57799 Patchstack
7.5 High NewsPlus Shortcodes Plugin newsplus-shortcodes Local File Inclusion ≤ 4.2.0 CVE-2026-57798 Patchstack
7.5 High Leedo Theme leedo Local File Inclusion ≤ 3.0.0 CVE-2026-57796 Patchstack
7.5 High Kitchor Theme kitchor Local File Inclusion ≤ 1.4.3 CVE-2026-57795 Patchstack
7.5 High Golo Framework Plugin golo-framework Local File Inclusion ≤ 1.7.3 CVE-2026-57794 Patchstack
7.5 High Flow Plugin flow Local File Inclusion ≤ 1.8 CVE-2026-57793 Patchstack
7.5 High Dør Plugin dor Local File Inclusion ≤ 2.4.1 CVE-2026-57792 Patchstack
7.5 High Brook Plugin brook Local File Inclusion ≤ 2.9.0 CVE-2026-57791 Patchstack
7.5 High Billey Theme billey Local File Inclusion ≤ 2.1.8 CVE-2026-57790 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only