WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Event Booking Manager for WooCommerce (Pro) Plugin Price Manipulation Unauthenticated Payment Bypass via Client-Controlled Ticket Price No login needed < 5.0.3 Fixed in 5.0.3 CVE-2026-16067 WPScan
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default No login needed < 3.14.10 Fixed in 3.14.10 CVE-2026-15256 WPScan
5.3 Medium Security Optimizer – The All-In-One Protection Plugin Other The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password No login needed 1.5.8 – < 1.6.5 Fixed in 1.6.5 CVE-2026-13342 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Amount-Blind PayPal Verification No login needed < 6.0.9.5 Fixed in 6.0.9.5 CVE-2026-15208 WPScan
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated Payment Bypass via Price Manipulation No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-15149 WPScan
5.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Unauthenticated Payment Bypass and Booking Confirmation via IDOR No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15147 WPScan
5.3 Medium Simple Membership Plugin simple-membership Price Manipulation Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification No login needed < 4.7.7 Fixed in 4.7.7 CVE-2026-14936 WPScan
5.3 Medium Easy Booking Plugin woocommerce-easy-booking-system Other Unauthenticated Minimum Booking Duration Bypass No login needed < 3.5.0 Fixed in 3.5.0 CVE-2026-14831 WPScan
5.9 Medium GetPaid Plugin Price Manipulation Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification No login needed < 2.8.55 Fixed in 2.8.55 CVE-2026-12901 WPScan
5.3 Medium WP Travel Engine Plugin wp-travel-engine Price Manipulation Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification No login needed < 6.8.2 Fixed in 6.8.2 CVE-2026-12501 WPScan
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated PayPal Payment Bypass No login needed < 2.3.2 Fixed in 2.3.2 CVE-2026-15152 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Price Manipulation Unauthenticated Payment Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-14842 WPScan
4.3 Medium Tutor LMS Plugin tutor Information Disclosure Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass < 3.9.14 Fixed in 3.9.14 CVE-2026-14306 WPScan
5.9 Medium Formidable Forms Plugin formidable Price Manipulation Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status No login needed < 6.32.1 Fixed in 6.32.1 CVE-2026-11361 WPScan
6.8 Medium Dataverse Integration Plugin Information Disclosure Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure < 2.91 Fixed in 2.91 CVE-2026-5336 WPScan
5.9 Medium Subscribe to Comments Plugin subscribe-to-comments Cross-Site Scripting ≤ 2.3.1 CVE-2026-66706 Patchstack
6.5 Medium MailOptin Plugin mailoptin Cross-Site Scripting ≤ 1.2.78.0 Fixed in 1.2.78.1 CVE-2026-66703 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Broken Access Control No login needed ≤ 3.16.5 Fixed in 3.16.6 CVE-2026-66701 Patchstack
5.3 Medium Dokan Plugin dokan-lite Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66699 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Information Disclosure Sensitive Data Exposure ≤ 3.7.8 Fixed in 3.7.8.1 CVE-2026-66696 Patchstack
6.5 Medium W3 Total Cache Plugin w3-total-cache Path Traversal No login needed ≤ 2.10.2 Fixed in 2.10.3 CVE-2026-66695 Patchstack
4.3 Medium Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66692 Patchstack
6.5 Medium Ultimate Addons for Elementor Plugin ultimate-elementor Cross-Site Scripting ≤ 1.45.2 Fixed in 1.45.2.1 CVE-2026-66688 Patchstack
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
5.3 Medium Featured Video Plus Plugin featured-video-plus Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-66685 Patchstack
5.3 Medium Export Import Menus Plugin export-import-menus Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.2 CVE-2026-66684 Patchstack
5.3 Medium Custom CSS and JavaScript Plugin custom-css-and-javascript Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.16 CVE-2026-66683 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
4.3 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Broken Access Control ≤ 6.1.1 CVE-2026-66678 Patchstack
6.5 Medium Legal Text Connector of the IT-Recht Kanzlei Plugin legal-texts-connector-it-recht-kanzlei Broken Access Control No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2026-66452 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Authentication Bypass Broken Authentication No login needed ≤ 4.1.9 Fixed in 4.1.10 CVE-2026-66451 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Authentication Bypass Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication No login needed ≤ 1.9.0 Fixed in 2.0.0 CVE-2026-66425 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting ≤ 6.4.24 Fixed in 6.4.25 CVE-2026-61959 Patchstack
5.3 Medium SureCart Plugin surecart Broken Access Control No login needed ≤ 4.6.2 Fixed in 4.6.3 CVE-2026-32548 Patchstack
5.3 Medium CAPTCHA 4WP Plugin advanced-nocaptcha-recaptcha Authentication Bypass Captcha Bypass No login needed ≤ 7.6.0 CVE-2026-32469 Patchstack
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.9.0 Fixed in 8.9.1 CVE-2026-28180 Patchstack
5.9 Medium FiboSearch Plugin ajax-search-for-woocommerce Cross-Site Scripting ≤ 1.33.0 Fixed in 1.34.0 CVE-2026-28179 Patchstack
6.5 Medium Powerkit Plugin powerkit Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-28178 Patchstack
5.3 Medium YITH WooCommerce Zoom Magnifier Plugin yith-woocommerce-zoom-magnifier Information Disclosure Sensitive Data Exposure No login needed ≤ 2.52.0 Fixed in 2.52.1 CVE-2026-28169 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-25403 Patchstack
4.3 Medium RealHomes Memberships Plugin inspiry-memberships Price Manipulation Subscriber+ Membership Payment Bypass < 3.1.0 Fixed in 3.1.0 CVE-2026-15246 WPScan
6.4 Medium UsersWP Plugin userswp Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution ≤ 1.2.69 CVE-2026-18501 Wordfence
5.3 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Content Injection Unauthenticated SMTP Header Injection No login needed ≤ 8.3.15 CVE-2026-0673 Wordfence
4.3 Medium Accelerate Theme accelerate Broken Access Control Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation ≤ 1.5.3 CVE-2025-9266 Wordfence
5.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Missing Authorization to Block Visibility Bypass via ai_ajax No login needed ≤ 2.8.16 CVE-2026-11983 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 5.3.2 CVE-2026-5391 Wordfence
6.4 Medium PostX Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block ≤ 5.0.13 CVE-2026-5158 Wordfence
6.5 Medium Google Authenticator Plugin google-authenticator Cross-Site Request Forgery Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF No login needed < 0.56 Fixed in 0.56 CVE-2026-14204 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only