WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,301–1,350 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Salon Booking System – Free Version Plugin Information Disclosure Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure ≤ 10.31.0 CVE-2026-17020 WPScan
5.3 Medium Pinpoint Booking System Plugin Price Manipulation Unauthenticated Arbitrary Booking Price Manipulation No login needed ≤ 2.9.9.7.1 CVE-2026-15229 WPScan
5.4 Medium Block User Account Plugin block-user-account Authentication Bypass Subscriber+ Account Block Bypass via Application Passwords < 2.0.1 Fixed in 2.0.1 CVE-2026-18960 WPScan
5.5 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion < 5.2.6 Fixed in 5.2.6 CVE-2026-18934 WPScan
5.8 Medium Term Pages Plugin SQL Injection Unauthenticated SQL Injection via tp_lookup No login needed < 2.0.0 Fixed in 2.0.0 CVE-2026-16949 WPScan
5.4 Medium Hotel Booking Lite Plugin Broken Access Control Subscriber+ Customer Data Modification via IDOR < 6.2.3 Fixed in 6.2.3 CVE-2026-15238 WPScan
5.3 Medium Hotel Booking Lite Plugin Broken Access Control Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint No login needed < 6.2.3 Fixed in 6.2.3 CVE-2026-15237 WPScan
5.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 5.116.0 Fixed in 5.116.0 CVE-2026-14941 WPScan
5.3 Medium Podcast Player Plugin podcast-player Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 8.3.1 Fixed in 8.3.1 CVE-2026-14860 WPScan
4.8 Medium Advanced Excerpt Plugin advanced-excerpt Cross-Site Scripting Admin+ Stored XSS via Ellipsis Setting < 4.5 Fixed in 4.5 CVE-2026-13701 WPScan
4.9 Medium CubeWP Framework Plugin cubewp-framework Information Disclosure Contributor+ Arbitrary Post and User Meta Disclosure via IDOR ≤ 1.1.30 CVE-2026-17018 WPScan
5.4 Medium Saitama Addon Pack Plugin cc-addon-pack Cross-Site Scripting Contributor+ Stored XSS via Post Meta ≤ 1.0.8 CVE-2026-17010 WPScan
4.3 Medium Library Management System Plugin library-management-system SQL Injection Subscriber+ SQL Injection via Filter Value < 3.6.7 Fixed in 3.6.7 CVE-2026-18666 WPScan
5.3 Medium Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed ≤ 3.1.0 CVE-2026-17012 WPScan
6.1 Medium JetEngine Plugin Cross-Site Scripting Unauthenticated Stored XSS via Form File Upload (SVG) No login needed < 3.8.13.1 Fixed in 3.8.13.1 CVE-2026-17019 WPScan
6.1 Medium LWS Optimize Plugin lws-optimize Cross-Site Scripting Unauthenticated Stored XSS via Real User Monitoring No login needed < 4.1.2 Fixed in 4.1.2 CVE-2026-16032 WPScan
6.5 Medium Cancel Order & Request Woocommerce Plugin Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed < 1.3.4.34 Fixed in 1.3.4.34 CVE-2026-18603 WPScan
6.5 Medium WP Maps Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-18465 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-18037 WPScan
5.3 Medium WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Deletion Unauthenticated Export ZIP File Deletion via delexportzips No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-17014 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-16992 WPScan
4.3 Medium Solace Extra Plugin solace-extra Cross-Site Request Forgery Subscriber+ Post Meta Update via solace_update_sitebuilder_status < 1.6.1 Fixed in 1.6.1 CVE-2026-16965 WPScan
5.0 Medium AI Engine Plugin ai-engine Path Traversal Subscriber+ Arbitrary File Read via Audio Transcription < 3.6.6 Fixed in 3.6.6 CVE-2026-16955 WPScan
4.8 Medium AI Engine Plugin ai-engine Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed < 3.6.4 Fixed in 3.6.4 CVE-2026-16953 WPScan
5.3 Medium Download Monitor Plugin download-monitor Broken Access Control Unauthenticated Download Log Injection No login needed < 5.2.6 Fixed in 5.2.6 CVE-2026-16608 WPScan
6.5 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ User and Unpublished Listing Disclosure < 1.5.5 Fixed in 1.5.5 CVE-2026-16595 WPScan
6.5 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ Contact Message and User Data Disclosure < 1.5.5 Fixed in 1.5.5 CVE-2026-16590 WPScan
5.4 Medium Dokan Plugin Broken Access Control Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16574 WPScan
6.5 Medium WP Statistics Plugin wp-statistics Information Disclosure Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers < 14.16.10 Fixed in 14.16.10 CVE-2026-16562 WPScan
6.8 Medium YMC Filter Plugin ymc-smart-filter Cross-Site Scripting Author+ Stored XSS via SVG Icon Upload < 3.12.9 Fixed in 3.12.9 CVE-2026-16559 WPScan
5.4 Medium YMC Filter Plugin ymc-smart-filter Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema 3.6.0 – < 3.12.8 Fixed in 3.12.8 CVE-2026-16558 WPScan
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed < 7.9.4 Fixed in 7.9.4 CVE-2026-16535 WPScan
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Price Manipulation Unauthenticated Booking Price Manipulation via tcost Parameter No login needed < 1.5.88 Fixed in 1.5.88 CVE-2026-16282 WPScan
4.8 Medium Newsletters Plugin newsletters-lite Authentication Bypass Unauthenticated API Authentication Bypass via Type Juggling No login needed < 4.16 Fixed in 4.16 CVE-2026-16269 WPScan
6.4 Medium Easy Accordion Plugin easy-accordion-free Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute ≤ 3.1.8 CVE-2026-18988 Wordfence
6.5 Medium code-embed Plugin Cross-Site Scripting Contributor Stored Cross-Site Scripting via Remote URL Embed < 2.6.1 CVE-2026-48093 GitHub_M
5.3 Medium shareopenly Plugin shareopenly Cross-Site Scripting ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output No login needed < 1.2.1 CVE-2026-48094 GitHub_M
5.3 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed < 1.42.0 Fixed in 1.42.0 CVE-2026-15239 WPScan
5.9 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed < 2.0.1 Fixed in 2.0.1 CVE-2026-15211 WPScan
5.3 Medium WP Events Manager Plugin wp-events-manager Price Manipulation Unauthenticated Payment Bypass and Booking Status Update via IDOR No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-15148 WPScan
6.5 Medium WP Maps Plugin wp-google-map-plugin Denial of Service Subscriber+ Denial of Service < 4.9.7 Fixed in 4.9.7 CVE-2026-16265 WPScan
6.5 Medium MStore API Plugin mstore-api Information Disclosure Subscriber+ Order and Customer PII Disclosure via IDOR < 4.21.0 Fixed in 4.21.0 CVE-2026-16039 WPScan
5.4 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting Author+ Stored XSS via Attachment Alt-Text < 5.5.2 Fixed in 5.5.2 CVE-2026-15386 WPScan
6.5 Medium Templately Plugin templately Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed < 3.7.1 Fixed in 3.7.1 CVE-2026-15359 WPScan
5.4 Medium BNE Testimonials Plugin bne-testimonials Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode < 2.0.8.2 Fixed in 2.0.8.2 CVE-2026-15245 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR < 2.0.1 Fixed in 2.0.1 CVE-2026-15214 WPScan
6.1 Medium wpDiscuz Plugin Cross-Site Scripting Unauthenticated Stored XSS via Image URL Conversion No login needed < 7.6.60 Fixed in 7.6.60 CVE-2026-15032 WPScan
6.1 Medium Subscribe2 Plugin subscribe2 Cross-Site Scripting Reflected XSS via email Parameter No login needed < 10.46 Fixed in 10.46 CVE-2026-14331 WPScan
6.4 Medium Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes ≤ 3.5.43 CVE-2026-12801 Wordfence
6.5 Medium Stream Plugin stream Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API ≤ 4.2.0 CVE-2026-11907 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only