WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium User Access Manager Plugin user-access-manager Cross-Site Scripting Reflected Cross-Site Scripting via 'tab_group_section' Parameter No login needed ≤ 2.3.18 CVE-2026-19797 Wordfence
7.2 High Repeater Fields for Gravity Forms Plugin repeater-for-gravity-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values No login needed ≤ 3.0.4 CVE-2026-84293 Wordfence
6.1 Medium Product Filter for WooCommerce by WBW Plugin woo-product-filter Cross-Site Scripting Reflected Cross-Site Scripting via 'wpf_fid' Parameter No login needed ≤ 3.4.2 CVE-2026-7804 Wordfence
7.2 High Shopping Cart & eCommerce Store Plugin wp-easycart Privilege Escalation Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action ≤ 5.9.3 CVE-2026-17553 Wordfence
6.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting ≤ 3.1.11 CVE-2026-13709 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15667 Wordfence
7.5 High Eventin Plugin wp-event-solution Local File Inclusion Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter ≤ 4.1.22 CVE-2026-15406 Wordfence
8.8 High FireBox Plugin firebox Remote Code Execution Authenticated (Author+) Remote Code Execution to Privilege Escalation ≤ 3.1.10 CVE-2026-76801 Wordfence
7.2 High Contact Form to DB by BestWebSoft Plugin contact-form-to-db Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter No login needed ≤ 1.7.5 CVE-2026-13359 Wordfence
5.3 Medium Eventin Plugin wp-event-solution Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Creation and Status Manipulation via 'status' Parameter No login needed ≤ 4.1.22 CVE-2026-12956 Wordfence
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
6.5 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.10.3.1 CVE-2026-18021 Wordfence
6.5 Medium WPML Multilingual CMS Plugin Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ ≤ 4.9.5 CVE-2026-17509 Wordfence
6.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' ≤ 4.3.9.1 CVE-2026-12230 Wordfence
6.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter ≤ 3.3.205 CVE-2026-76931 Wordfence
7.5 High Event Tickets and Registration Plugin event-tickets Broken Access Control Missing Authorization to Unauthenticated Stripe Credentials Update No login needed ≤ 5.27.4 CVE-2026-3174 Wordfence
8.8 High Live Composer Plugin live-composer-page-builder PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Shortcode ≤ 2.1.18 CVE-2026-16502 Wordfence
7.1 High EDD Product Catalog Feed by PixelYourSite Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter ≤ 1.0.2 CVE-2026-9331 Wordfence
7.2 High Hide My WP Ghost Plugin hide-my-wp Server-Side Request Forgery No login needed ≤ 7.0.09 Fixed in 7.0.10 CVE-2026-81806 Patchstack
7.5 High WooCommerce Plugin woocommerce Denial of Service Denial of Service Attack No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-48888 Patchstack
7.1 High Unbounce Landing Pages Plugin unbounce Broken Access Control ≤ 1.1.4 CVE-2026-81781 Patchstack
7.5 High Csomagpontok és szállítási címkék WooCommerce-hez Plugin hungarian-pickup-points-for-woocommerce Broken Access Control No login needed < 4.2.8 Fixed in 4.2.8 CVE-2026-81790 Patchstack
7.1 High Easy Appointments Plugin easy-appointments Cross-Site Scripting No login needed ≤ 4.0.2.1 CVE-2026-81798 Patchstack
7.1 High Open User Map Plugin open-user-map Cross-Site Scripting No login needed ≤ 1.4.50 Fixed in 1.4.51 CVE-2026-84818 Patchstack
7.1 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting No login needed ≤ 3.6.5.1 Fixed in 3.6.5.2 CVE-2026-84817 Patchstack
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
7.5 High WP Fusion (Pro) Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter ≤ 3.47.13 CVE-2026-14444 Wordfence
6.5 Medium Email Subscribers & Newsletters Plugin email-subscribers Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field No login needed ≤ 5.9.27 CVE-2026-12757 Wordfence
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion No login needed ≤ 2.2.0 CVE-2026-8279 Wordfence
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field No login needed ≤ 3.15.7 CVE-2026-6431 Wordfence
5.3 Medium Otter Blocks Plugin otter-blocks Broken Access Control Missing Authorization to Unauthenticated Purchase Verification Bypass No login needed ≤ 3.1.7 CVE-2026-4945 Wordfence
5.4 Medium Flamingo Plugin flamingo Broken Access Control Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search ≤ 2.6.2 CVE-2026-12853 Wordfence
6.4 Medium Powerkit Plugin powerkit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing ≤ 3.0.4 CVE-2026-2390 Wordfence
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags No login needed 3.14.10 – < 3.15.2 Fixed in 3.15.2 CVE-2026-80437 WPScan
4.8 Medium Redirection for Contact Form 7 Plugin wpcf7-redirect Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags No login needed 2.2.7 – < 3.2.11 Fixed in 3.2.11 CVE-2026-80439 WPScan
4.8 Medium JetFormBuilder Plugin Content Injection Unauthenticated Email Header Injection via Send Email Action No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19862 WPScan
6.5 Medium JetFormBuilder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19859 WPScan
5.3 Medium B2BKing Plugin Broken Access Control Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection No login needed < 5.2.40 Fixed in 5.2.40 CVE-2026-85038 WPScan
7.5 High Kirki Plugin kirki Cross-Site Scripting Unauthenticated Stored XSS via HTML Entity Decoding No login needed 6.2.1 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84219 WPScan
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via Slider Elements' additional_settings < 5.9.9 Fixed in 5.9.9 CVE-2026-84028 WPScan
6.5 Medium SureCart Plugin surecart Broken Access Control Unauthenticated Account Creation with Automatic Login No login needed < 4.7.0 Fixed in 4.7.0 CVE-2026-75793 WPScan
8.8 High SureCart Plugin surecart Privilege Escalation Subscriber+ Administrator Account Takeover 4.0.0 – < 4.6.3 Fixed in 4.6.3 CVE-2026-18480 WPScan
4.3 Medium Real Estate Papi Theme Cross-Site Request Forgery Subscriber+ Plugin Installation ≤ 1.0.5 CVE-2026-13159 WPScan
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Account Takeover via '_acf_objects' Object Identifier No login needed ≤ 3.29.12 CVE-2026-75816 Wordfence
7.5 High HivePress Authentication Plugin hivepress-authentication Authentication Bypass Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator No login needed ≤ 1.1.4 CVE-2026-18056 Wordfence
9.8 Critical MemberDash Plugin Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter No login needed ≤ 1.8.5 CVE-2026-16310 Wordfence
4.3 Medium Ninja Forms - Save Progress Plugin Broken Access Control Save Progress <= 3.0.30 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Data Deletion via admin-ajax.php with admin_init Hook ≤ 3.0.30 CVE-2026-15550 Wordfence
8.8 High Nokri – Job Board Theme Broken Access Control Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover ≤ 1.6.4 CVE-2025-9049 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only