WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,301–1,350 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Salon Booking System – Free Version | Information Disclosure Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure |
≤ 10.31.0 |
CVE-2026-17020 |
WPScan | |
| 5.3 Medium | Pinpoint Booking System | Price Manipulation Unauthenticated Arbitrary Booking Price Manipulation No login needed |
≤ 2.9.9.7.1 |
CVE-2026-15229 |
WPScan | |
| 5.4 Medium | Block User Account | Authentication Bypass Subscriber+ Account Block Bypass via Application Passwords |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-18960 |
WPScan | |
| 5.5 Medium | RSS Aggregator by Feedzy | Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-18934 |
WPScan | |
| 5.8 Medium | Term Pages | SQL Injection Unauthenticated SQL Injection via tp_lookup No login needed |
< 2.0.0 Fixed in 2.0.0 |
CVE-2026-16949 |
WPScan | |
| 5.4 Medium | Hotel Booking Lite | Broken Access Control Subscriber+ Customer Data Modification via IDOR |
< 6.2.3 Fixed in 6.2.3 |
CVE-2026-15238 |
WPScan | |
| 5.3 Medium | Hotel Booking Lite | Broken Access Control Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint No login needed |
< 6.2.3 Fixed in 6.2.3 |
CVE-2026-15237 |
WPScan | |
| 5.4 Medium | Customer Reviews for WooCommerce | Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions |
< 5.116.0 Fixed in 5.116.0 |
CVE-2026-14941 |
WPScan | |
| 5.3 Medium | Podcast Player | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
< 8.3.1 Fixed in 8.3.1 |
CVE-2026-14860 |
WPScan | |
| 4.8 Medium | Advanced Excerpt | Cross-Site Scripting Admin+ Stored XSS via Ellipsis Setting |
< 4.5 Fixed in 4.5 |
CVE-2026-13701 |
WPScan | |
| 4.9 Medium | CubeWP Framework | Information Disclosure Contributor+ Arbitrary Post and User Meta Disclosure via IDOR |
≤ 1.1.30 |
CVE-2026-17018 |
WPScan | |
| 5.4 Medium | Saitama Addon Pack | Cross-Site Scripting Contributor+ Stored XSS via Post Meta |
≤ 1.0.8 |
CVE-2026-17010 |
WPScan | |
| 4.3 Medium | Library Management System | SQL Injection Subscriber+ SQL Injection via Filter Value |
< 3.6.7 Fixed in 3.6.7 |
CVE-2026-18666 |
WPScan | |
| 5.3 Medium | Restore PayPal Standard for WooCommerce | Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed |
≤ 3.1.0 |
CVE-2026-17012 |
WPScan | |
| 6.1 Medium | JetEngine | Cross-Site Scripting Unauthenticated Stored XSS via Form File Upload (SVG) No login needed |
< 3.8.13.1 Fixed in 3.8.13.1 |
CVE-2026-17019 |
WPScan | |
| 6.1 Medium | LWS Optimize | Cross-Site Scripting Unauthenticated Stored XSS via Real User Monitoring No login needed |
< 4.1.2 Fixed in 4.1.2 |
CVE-2026-16032 |
WPScan | |
| 6.5 Medium | Cancel Order & Request Woocommerce | Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed |
< 1.3.4.34 Fixed in 1.3.4.34 |
CVE-2026-18603 |
WPScan | |
| 6.5 Medium | WP Maps Pro | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
< 6.1.3 Fixed in 6.1.3 |
CVE-2026-18465 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-18037 |
WPScan | |
| 5.3 Medium | WP Photo Album Plus | Arbitrary File Deletion Unauthenticated Export ZIP File Deletion via delexportzips No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-17014 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-16992 |
WPScan | |
| 4.3 Medium | Solace Extra | Cross-Site Request Forgery Subscriber+ Post Meta Update via solace_update_sitebuilder_status |
< 1.6.1 Fixed in 1.6.1 |
CVE-2026-16965 |
WPScan | |
| 5.0 Medium | AI Engine | Path Traversal Subscriber+ Arbitrary File Read via Audio Transcription |
< 3.6.6 Fixed in 3.6.6 |
CVE-2026-16955 |
WPScan | |
| 4.8 Medium | AI Engine | Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed |
< 3.6.4 Fixed in 3.6.4 |
CVE-2026-16953 |
WPScan | |
| 5.3 Medium | Download Monitor | Broken Access Control Unauthenticated Download Log Injection No login needed |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-16608 |
WPScan | |
| 6.5 Medium | WP Directory Kit | Information Disclosure Subscriber+ User and Unpublished Listing Disclosure |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16595 |
WPScan | |
| 6.5 Medium | WP Directory Kit | Information Disclosure Subscriber+ Contact Message and User Data Disclosure |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16590 |
WPScan | |
| 5.4 Medium | Dokan | Broken Access Control Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint |
< 5.0.11 Fixed in 5.0.11 |
CVE-2026-16574 |
WPScan | |
| 6.5 Medium | WP Statistics | Information Disclosure Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers |
< 14.16.10 Fixed in 14.16.10 |
CVE-2026-16562 |
WPScan | |
| 6.8 Medium | YMC Filter | Cross-Site Scripting Author+ Stored XSS via SVG Icon Upload |
< 3.12.9 Fixed in 3.12.9 |
CVE-2026-16559 |
WPScan | |
| 5.4 Medium | YMC Filter | Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema |
3.6.0 – < 3.12.8 Fixed in 3.12.8 |
CVE-2026-16558 |
WPScan | |
| 6.1 Medium | Link Library | Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-16535 |
WPScan | |
| 5.3 Medium | Appointment Hour Booking | Price Manipulation Unauthenticated Booking Price Manipulation via tcost Parameter No login needed |
< 1.5.88 Fixed in 1.5.88 |
CVE-2026-16282 |
WPScan | |
| 4.8 Medium | Newsletters | Authentication Bypass Unauthenticated API Authentication Bypass via Type Juggling No login needed |
< 4.16 Fixed in 4.16 |
CVE-2026-16269 |
WPScan | |
| 6.4 Medium | Easy Accordion | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute |
≤ 3.1.8 |
CVE-2026-18988 |
Wordfence | |
| 6.5 Medium | code-embed | Cross-Site Scripting Contributor Stored Cross-Site Scripting via Remote URL Embed |
< 2.6.1 |
CVE-2026-48093 |
GitHub_M | |
| 5.3 Medium | shareopenly | Cross-Site Scripting ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output No login needed |
< 1.2.1 |
CVE-2026-48094 |
GitHub_M | |
| 5.3 Medium | Simple CAPTCHA with Cloudflare Turnstile | Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed |
< 1.42.0 Fixed in 1.42.0 |
CVE-2026-15239 |
WPScan | |
| 5.9 Medium | Subscriptions for WooCommerce | Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15211 |
WPScan | |
| 5.3 Medium | WP Events Manager | Price Manipulation Unauthenticated Payment Bypass and Booking Status Update via IDOR No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-15148 |
WPScan | |
| 6.5 Medium | WP Maps | Denial of Service Subscriber+ Denial of Service |
< 4.9.7 Fixed in 4.9.7 |
CVE-2026-16265 |
WPScan | |
| 6.5 Medium | MStore API | Information Disclosure Subscriber+ Order and Customer PII Disclosure via IDOR |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16039 |
WPScan | |
| 5.4 Medium | Meow Gallery | Cross-Site Scripting Author+ Stored XSS via Attachment Alt-Text |
< 5.5.2 Fixed in 5.5.2 |
CVE-2026-15386 |
WPScan | |
| 6.5 Medium | Templately | Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-15359 |
WPScan | |
| 5.4 Medium | BNE Testimonials | Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode |
< 2.0.8.2 Fixed in 2.0.8.2 |
CVE-2026-15245 |
WPScan | |
| 4.3 Medium | Subscriptions for WooCommerce | Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15214 |
WPScan | |
| 6.1 Medium | wpDiscuz | Cross-Site Scripting Unauthenticated Stored XSS via Image URL Conversion No login needed |
< 7.6.60 Fixed in 7.6.60 |
CVE-2026-15032 |
WPScan | |
| 6.1 Medium | Subscribe2 | Cross-Site Scripting Reflected XSS via email Parameter No login needed |
< 10.46 Fixed in 10.46 |
CVE-2026-14331 |
WPScan | |
| 6.4 Medium | Ultra Addons for Contact Form 7 | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes |
≤ 3.5.43 |
CVE-2026-12801 |
Wordfence | |
| 6.5 Medium | Stream | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API |
≤ 4.2.0 |
CVE-2026-11907 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.