WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,401–1,450 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 29 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection Unauthenticated PHP Object Injection in Arbitrary Form Fields No login needed ≤ 1.31.0 CVE-2026-10196 Wordfence
5.4 Medium LearnDash LMS Plugin Broken Access Control Unauthenticated Arbitrary Course Enrollment via REST Endpoint 4.25.0 – 5.1.6 CVE-2026-12843 Wordfence
6.4 Medium Pods Plugin pods Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute ≤ 3.3.9.1 CVE-2026-76573 Wordfence
9.8 Critical Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Remote Code Execution ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection No login needed 2.2.85 – 2.3.32 CVE-2024-11080 Wordfence
8.8 High Abandoned Cart Pro for WooCommerce Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 10.7.1 CVE-2026-81543 Wordfence
7.2 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via IP Address Header No login needed ≤ 1.10.2 CVE-2026-83625 Wordfence
4.3 Medium Custom Contact Forms Plugin custom-contact-forms Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters ≤ 7.16 CVE-2026-75018 Wordfence
6.4 Medium Gallery : FooGallery Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute ≤ 3.3.2 CVE-2026-85414 Wordfence
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed ≤ 2.0.17 CVE-2026-75586 Wordfence
5.0 Medium Divi Theme Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter ≤ 4.27.6 CVE-2026-4361 Wordfence
7.2 High QuickCal Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters No login needed ≤ 1.0.20 CVE-2026-15984 Wordfence
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter ≤ 4.27.6 CVE-2026-3853 Wordfence
7.2 High W3 Total Cache Plugin w3-total-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator No login needed ≤ 2.10.5 CVE-2026-78438 Wordfence
8.8 High Welcart e-Commerce Plugin usc-e-shop Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback No login needed ≤ 2.12.1 CVE-2026-19887 Wordfence
7.2 High SureForms Plugin sureforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload No login needed ≤ 2.12.2 CVE-2026-18406 Wordfence
7.2 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key No login needed ≤ 3.15.1 CVE-2026-19769 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Post Body Field Value No login needed ≤ 2.10.5 CVE-2026-16649 Wordfence
6.5 Medium WP File Download Plugin wp-file-download Path Traversal Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter ≤ 6.3.8 CVE-2026-14975 Wordfence
7.2 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed ≤ 6.86 CVE-2026-77830 Wordfence
6.1 Medium Beaver Builder Plugin (Pro Version) Plugin Cross-Site Scripting Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter No login needed ≤ 2.11.0.1 CVE-2026-18843 Wordfence
6.8 Medium YT Player Plugin SQL Injection Contributor+ SQLi via ytp_ajax < 2.1.0 Fixed in 2.1.0 CVE-2026-84937 WPScan
5.3 Medium EmbedPress Plugin embedpress Broken Access Control Unauthenticated Google Reviews API Quota Consumption and Database Bloat No login needed 4.6.0 – < 4.6.4 Fixed in 4.6.4 CVE-2026-84936 WPScan
8.0 High HT Menu Plugin ht-menu-lite Cross-Site Scripting Subscriber+ Stored XSS via Menu Settings < 1.2.7 Fixed in 1.2.7 CVE-2026-84935 WPScan
8.0 High JCH Optimize Plugin jch-optimize Cross-Site Scripting Subscriber+ Stored XSS via getcacheinfo Task Override < 6.0.1 Fixed in 6.0.1 CVE-2026-84934 WPScan
6.8 Medium Joli Table Of Contents Plugin joli-table-of-contents Cross-Site Scripting Author+ Stored XSS via joli-toc Shortcode Theme Attribute < 3.0.3 Fixed in 3.0.3 CVE-2026-84931 WPScan
6.8 Medium CatFolders Document Gallery Plugin Cross-Site Scripting Author+ Stored XSS via titleTag Block Attribute < 2.0.7 Fixed in 2.0.7 CVE-2026-84930 WPScan
2.7 Low EmbedPress Plugin embedpress Broken Access Control Contributor+ Google Reviews Modification 4.6.0 – < 4.6.4 Fixed in 4.6.4 CVE-2026-84927 WPScan
2.7 Low EmbedPress Plugin embedpress Information Disclosure Contributor+ Administrator Email Disclosure via Google Reviews REST Route 4.6.0 – < 4.6.4 Fixed in 4.6.4 CVE-2026-84926 WPScan
4.9 Medium Eventin Plugin wp-event-solution Broken Access Control Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization < 4.1.22 Fixed in 4.1.22 CVE-2026-84901 WPScan
6.8 Medium VikWidgetsLoader Plugin vikwidgetsloader Cross-Site Scripting Contributor+ Stored XSS via Gutenberg Block class_suffix 1.11.0 – < 1.12.0 Fixed in 1.12.0 CVE-2026-84899 WPScan
6.6 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ LFI via Event Layout Meta < 4.1.21 Fixed in 4.1.21 CVE-2026-84898 WPScan
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Magazine Grid Widget < 51.1.77 Fixed in 51.1.77 CVE-2026-84896 WPScan
2.7 Low The Events Calendar Plugin the-events-calendar Information Disclosure Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API < 6.17.3.1 Fixed in 6.17.3.1 CVE-2026-84745 WPScan
2.2 Low Kirki Plugin kirki Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84225 WPScan
6.8 Medium Kirki Plugin kirki SQL Injection Editor+ SQLi via Content Manager Field ID 6.0.0 – < 6.3.0 Fixed in 6.3.0 CVE-2026-84221 WPScan
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via Multiple Shortcode Element Attributes < 5.9.8 Fixed in 5.9.8 CVE-2026-84022 WPScan
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL < 5.9.8 Fixed in 5.9.8 CVE-2026-84021 WPScan
6.8 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Contributor+ Stored XSS via Block Animation customProps Attribute < 13.2.0 Fixed in 13.2.0 CVE-2026-83544 WPScan
4.1 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Server-Side Request Forgery Contributor+ SSRF via get-csv-to-json REST Endpoint < 13.2.0 Fixed in 13.2.0 CVE-2026-83543 WPScan
6.8 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Course Custom Fields 1.18.0 – < 3.4.0 Fixed in 3.4.0 CVE-2026-82846 WPScan
8.6 High Music Store – WordPress eCommerce Plugin music-store SQL Injection WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler No login needed 1.0.245 – < 1.4.5 Fixed in 1.4.5 CVE-2026-82304 WPScan
5.3 Medium Accept Stripe Payments Plugin stripe-payments Broken Access Control Unauthenticated Product Substitution via IDOR No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-81424 WPScan
4.3 Medium Accept Stripe Payments Plugin stripe-payments Open Redirect Open Redirect via IPN Handler No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-81423 WPScan
7.1 High IPGP Visitors Origin Plugin Cross-Site Scripting Reflected XSS No login needed 1.3 – < 1.6 Fixed in 1.6 CVE-2026-81404 WPScan
3.7 Low My Private Site Plugin jonradio-private-site Information Disclosure Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap No login needed < 4.2.3 Fixed in 4.2.3 CVE-2026-81348 WPScan
9.8 Critical SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Privilege Escalation Unauthenticated Privilege Escalation via API Key Authentication No login needed 3.0.0 – < 3.0.3 Fixed in 3.0.3 CVE-2026-78362 WPScan
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
5.3 Medium Post Carousel Plugin Information Disclosure Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id No login needed 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78149 WPScan
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation No login needed 5.0.1.8 – < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77826 WPScan
4.7 Medium JetFormBuilder Plugin Cross-Site Scripting Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails No login needed < 3.6.5.2 Fixed in 3.6.5.2 CVE-2026-19861 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only