WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,401–1,450 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | Mail Mint | PHP Object Injection Unauthenticated PHP Object Injection in Arbitrary Form Fields No login needed |
≤ 1.31.0 |
CVE-2026-10196 |
Wordfence | |
| 5.4 Medium | LearnDash LMS | Broken Access Control Unauthenticated Arbitrary Course Enrollment via REST Endpoint |
4.25.0 – 5.1.6 |
CVE-2026-12843 |
Wordfence | |
| 6.4 Medium | Pods | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute |
≤ 3.3.9.1 |
CVE-2026-76573 |
Wordfence | |
| 9.8 Critical | Post Grid and Gutenberg Blocks – ComboBlocks | Remote Code Execution ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection No login needed |
2.2.85 – 2.3.32 |
CVE-2024-11080 |
Wordfence | |
| 8.8 High | Abandoned Cart Pro for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation |
≤ 10.7.1 |
CVE-2026-81543 |
Wordfence | |
| 7.2 High | Contact Form by Supsystic | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via IP Address Header No login needed |
≤ 1.10.2 |
CVE-2026-83625 |
Wordfence | |
| 4.3 Medium | Custom Contact Forms | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters |
≤ 7.16 |
CVE-2026-75018 |
Wordfence | |
| 6.4 Medium | Gallery : FooGallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute |
≤ 3.3.2 |
CVE-2026-85414 |
Wordfence | |
| 6.1 Medium | Unlimited Elements For Elementor | Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed |
≤ 2.0.17 |
CVE-2026-75586 |
Wordfence | |
| 5.0 Medium | Divi | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter |
≤ 4.27.6 |
CVE-2026-4361 |
Wordfence | |
| 7.2 High | QuickCal | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters No login needed |
≤ 1.0.20 |
CVE-2026-15984 |
Wordfence | |
| 6.4 Medium | Divi | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter |
≤ 4.27.6 |
CVE-2026-3853 |
Wordfence | |
| 7.2 High | W3 Total Cache | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator No login needed |
≤ 2.10.5 |
CVE-2026-78438 |
Wordfence | |
| 8.8 High | Welcart e-Commerce | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback No login needed |
≤ 2.12.1 |
CVE-2026-19887 |
Wordfence | |
| 7.2 High | SureForms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload No login needed |
≤ 2.12.2 |
CVE-2026-18406 |
Wordfence | |
| 7.2 High | Ninja Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key No login needed |
≤ 3.15.1 |
CVE-2026-19769 |
Wordfence | |
| 7.2 High | Gravity Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Post Body Field Value No login needed |
≤ 2.10.5 |
CVE-2026-16649 |
Wordfence | |
| 6.5 Medium | WP File Download | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter |
≤ 6.3.8 |
CVE-2026-14975 |
Wordfence | |
| 7.2 High | Spam protection, Honeypot, Anti-Spam by CleanTalk | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder No login needed |
≤ 6.86 |
CVE-2026-77830 |
Wordfence | |
| 6.1 Medium | Beaver Builder Plugin (Pro Version) | Cross-Site Scripting Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter No login needed |
≤ 2.11.0.1 |
CVE-2026-18843 |
Wordfence | |
| 6.8 Medium | YT Player | SQL Injection Contributor+ SQLi via ytp_ajax |
< 2.1.0 Fixed in 2.1.0 |
CVE-2026-84937 |
WPScan | |
| 5.3 Medium | EmbedPress | Broken Access Control Unauthenticated Google Reviews API Quota Consumption and Database Bloat No login needed |
4.6.0 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-84936 |
WPScan | |
| 8.0 High | HT Menu | Cross-Site Scripting Subscriber+ Stored XSS via Menu Settings |
< 1.2.7 Fixed in 1.2.7 |
CVE-2026-84935 |
WPScan | |
| 8.0 High | JCH Optimize | Cross-Site Scripting Subscriber+ Stored XSS via getcacheinfo Task Override |
< 6.0.1 Fixed in 6.0.1 |
CVE-2026-84934 |
WPScan | |
| 6.8 Medium | Joli Table Of Contents | Cross-Site Scripting Author+ Stored XSS via joli-toc Shortcode Theme Attribute |
< 3.0.3 Fixed in 3.0.3 |
CVE-2026-84931 |
WPScan | |
| 6.8 Medium | CatFolders Document Gallery | Cross-Site Scripting Author+ Stored XSS via titleTag Block Attribute |
< 2.0.7 Fixed in 2.0.7 |
CVE-2026-84930 |
WPScan | |
| 2.7 Low | EmbedPress | Broken Access Control Contributor+ Google Reviews Modification |
4.6.0 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-84927 |
WPScan | |
| 2.7 Low | EmbedPress | Information Disclosure Contributor+ Administrator Email Disclosure via Google Reviews REST Route |
4.6.0 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-84926 |
WPScan | |
| 4.9 Medium | Eventin | Broken Access Control Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization |
< 4.1.22 Fixed in 4.1.22 |
CVE-2026-84901 |
WPScan | |
| 6.8 Medium | VikWidgetsLoader | Cross-Site Scripting Contributor+ Stored XSS via Gutenberg Block class_suffix |
1.11.0 – < 1.12.0 Fixed in 1.12.0 |
CVE-2026-84899 |
WPScan | |
| 6.6 Medium | Eventin | Local File Inclusion Contributor+ LFI via Event Layout Meta |
< 4.1.21 Fixed in 4.1.21 |
CVE-2026-84898 |
WPScan | |
| 6.8 Medium | King Addons for Elementor | Cross-Site Scripting Contributor+ Stored XSS via Magazine Grid Widget |
< 51.1.77 Fixed in 51.1.77 |
CVE-2026-84896 |
WPScan | |
| 2.7 Low | The Events Calendar | Information Disclosure Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API |
< 6.17.3.1 Fixed in 6.17.3.1 |
CVE-2026-84745 |
WPScan | |
| 2.2 Low | Kirki | Broken Access Control Authenticated Collaboration Comment Status Modification via IDOR |
6.0.0 – < 6.3.0 Fixed in 6.3.0 |
CVE-2026-84225 |
WPScan | |
| 6.8 Medium | Kirki | SQL Injection Editor+ SQLi via Content Manager Field ID |
6.0.0 – < 6.3.0 Fixed in 6.3.0 |
CVE-2026-84221 |
WPScan | |
| 6.8 Medium | Bold Page Builder | Cross-Site Scripting Contributor+ Stored XSS via Multiple Shortcode Element Attributes |
< 5.9.8 Fixed in 5.9.8 |
CVE-2026-84022 |
WPScan | |
| 6.8 Medium | Bold Page Builder | Cross-Site Scripting Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL |
< 5.9.8 Fixed in 5.9.8 |
CVE-2026-84021 |
WPScan | |
| 6.8 Medium | Greenshift | Cross-Site Scripting Contributor+ Stored XSS via Block Animation customProps Attribute |
< 13.2.0 Fixed in 13.2.0 |
CVE-2026-83544 |
WPScan | |
| 4.1 Medium | Greenshift | Server-Side Request Forgery Contributor+ SSRF via get-csv-to-json REST Endpoint |
< 13.2.0 Fixed in 13.2.0 |
CVE-2026-83543 |
WPScan | |
| 6.8 Medium | Masteriyo LMS | Cross-Site Scripting Instructor+ Stored XSS via Course Custom Fields |
1.18.0 – < 3.4.0 Fixed in 3.4.0 |
CVE-2026-82846 |
WPScan | |
| 8.6 High | Music Store – WordPress eCommerce | SQL Injection WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler No login needed |
1.0.245 – < 1.4.5 Fixed in 1.4.5 |
CVE-2026-82304 |
WPScan | |
| 5.3 Medium | Accept Stripe Payments | Broken Access Control Unauthenticated Product Substitution via IDOR No login needed |
< 2.1.4 Fixed in 2.1.4 |
CVE-2026-81424 |
WPScan | |
| 4.3 Medium | Accept Stripe Payments | Open Redirect Open Redirect via IPN Handler No login needed |
< 2.1.4 Fixed in 2.1.4 |
CVE-2026-81423 |
WPScan | |
| 7.1 High | IPGP Visitors Origin | Cross-Site Scripting Reflected XSS No login needed |
1.3 – < 1.6 Fixed in 1.6 |
CVE-2026-81404 |
WPScan | |
| 3.7 Low | My Private Site | Information Disclosure Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap No login needed |
< 4.2.3 Fixed in 4.2.3 |
CVE-2026-81348 |
WPScan | |
| 9.8 Critical | SEO Flow by LupsOnline | Privilege Escalation Unauthenticated Privilege Escalation via API Key Authentication No login needed |
3.0.0 – < 3.0.3 Fixed in 3.0.3 |
CVE-2026-78362 |
WPScan | |
| 2.7 Low | Post Carousel | Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR |
4.0.0 – < 4.0.8 Fixed in 4.0.8 |
CVE-2026-78150 |
WPScan | |
| 5.3 Medium | Post Carousel | Information Disclosure Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id No login needed |
4.0.0 – < 4.0.8 Fixed in 4.0.8 |
CVE-2026-78149 |
WPScan | |
| 8.8 High | RegistrationMagic | Authentication Bypass Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation No login needed |
5.0.1.8 – < 6.0.9.9 Fixed in 6.0.9.9 |
CVE-2026-77826 |
WPScan | |
| 4.7 Medium | JetFormBuilder | Cross-Site Scripting Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails No login needed |
< 3.6.5.2 Fixed in 3.6.5.2 |
CVE-2026-19861 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.