WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 101–150 of 29,007 vulnerabilities

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Divi Membership Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'form_id' Parameter No login needed ≤ 2.2.0 CVE-2026-19652 Wordfence
6.4 Medium ThemeREX Addons Plugin trx_addons Server-Side Request Forgery ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102797 Patchstack
6.5 Medium ThemeREX Addons Plugin trx_addons Cross-Site Scripting ≤ 2.46.0 Fixed in 2.47.0 CVE-2026-102798 Patchstack
5.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.4.9 Fixed in 4.4.9.1 CVE-2026-104403 Patchstack
4.3 Medium Advanced Ads Plugin advanced-ads Information Disclosure Sensitive Data Exposure ≤ 2.0.26 CVE-2026-94180 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.71 CVE-2026-94405 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key No login needed ≤ 14.16.14 CVE-2026-97652 Wordfence
7.2 High W3 Total Cache Plugin w3-total-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 2.10.6 CVE-2026-87920 Wordfence
6.1 Medium All in One SEO Plugin all-in-one-seo-pack Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL Pathname No login needed ≤ 5.0.1.1 CVE-2026-85492 Wordfence
9.8 Critical WPMobile.App Plugin wpappninja Privilege Escalation Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter No login needed ≤ 11.82 CVE-2026-94541 Wordfence
9.8 Critical JSON API Auth Plugin json-api-auth Authentication Bypass Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response No login needed ≤ 3.1.2 CVE-2026-97637 Wordfence
5.3 Medium Appointment Booking Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter No login needed ≤ 5.7.1 CVE-2026-94432 Wordfence
6.5 Medium Event Tickets and Registration Plugin event-tickets SQL Injection Authenticated (Contributor+) SQL Injection via 'orderby' Parameter ≤ 5.29.5 CVE-2026-97634 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name ≤ 3.3.70 CVE-2026-97338 Wordfence
6.4 Medium Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter ≤ 6.1.1 CVE-2026-96647 Wordfence
7.2 High No External Links Plugin mihdan-no-external-links Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect No login needed ≤ 5.2.0 CVE-2026-95670 Wordfence
7.2 High Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview No login needed ≤ 4.13.0 CVE-2026-93756 Wordfence
7.2 High Kubio AI Page Builder Plugin kubio Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) No login needed ≤ 2.9.2 CVE-2026-100107 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action No login needed ≤ 3.6.5.4 CVE-2026-97342 Wordfence
7.2 High Mang Board Plugin mangboard Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter No login needed ≤ 2.4.2 CVE-2026-96871 Wordfence
7.2 High Relevanssi Premium Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter No login needed ≤ 2.31.4 CVE-2026-103426 Wordfence
3.1 Low Otter Blocks Plugin otter-blocks Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget ≤ 3.2.6 CVE-2026-102002 Wordfence
7.2 High Newsletter Plugin newsletter Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter No login needed ≤ 9.4.0 CVE-2026-96566 Wordfence
7.2 High Download Monitor Plugin download-monitor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor No login needed ≤ 5.2.10 CVE-2026-100182 Wordfence
7.2 High Relevanssi Plugin relevanssi Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 4.28.3 CVE-2026-97641 Wordfence
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor SQL Injection Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter ≤ 5.0.18 CVE-2026-12951 Wordfence
7.2 High CMB2 Plugin cmb2 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field No login needed ≤ 2.13.1 CVE-2026-102772 Wordfence
7.2 High CMB2 Plugin cmb2 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type No login needed ≤ 2.13.0 CVE-2026-97336 Wordfence
7.2 High DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.6.0 CVE-2026-95817 Wordfence
7.2 High GSpeech TTS Plugin gspeech Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.22.0 CVE-2026-96578 Wordfence
7.2 High MW WP Form Plugin mw-wp-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta) No login needed ≤ 5.1.7 CVE-2026-96567 Wordfence
6.1 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder No login needed ≤ 13.2.0 CVE-2026-93880 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 5.122.0 CVE-2026-97663 Wordfence
4.3 Medium MStore API Plugin mstore-api Price Manipulation Subscriber+ Payment Bypass via 'status' Parameter 4.21.1 – < 4.22.1 Fixed in 4.22.1 CVE-2026-97219 WPScan
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
5.3 Medium WebToffee Gift Cards for WooCommerce Plugin wt-gift-cards-woocommerce Price Manipulation Unauthenticated Gift Card Amount Manipulation via wt_credit_amount No login needed < 1.3.1 Fixed in 1.3.1 CVE-2026-91020 WPScan
5.3 Medium Easy PayPal & Stripe Buy Now Button Plugin wp-ecommerce-paypal Price Manipulation Unauthenticated Payment Amount Manipulation via Client-Supplied Price No login needed 1.8 – < 2.0.6 Fixed in 2.0.6 CVE-2026-90987 WPScan
5.3 Medium WP Edit Password Protected Plugin Broken Access Control Unauthenticated Site-Wide Access Mode Bypass via REST API No login needed 2.0.0 – < 2.0.7 Fixed in 2.0.7 CVE-2026-90952 WPScan
5.4 Medium Popup Maker WP Plugin Broken Access Control Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization 1.2.2.1 – 1.4.5 CVE-2026-85005 WPScan
6.5 Medium The Events Calendar Plugin the-events-calendar Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter No login needed 6.12.0 – < 6.17.5.1 Fixed in 6.17.5.1 CVE-2026-84740 WPScan
4.3 Medium WP User Frontend Plugin Broken Access Control Subscriber+ Post Creation via Subscription-Gated Form < 4.3.12 Fixed in 4.3.12 CVE-2026-79618 WPScan
5.3 Medium CMP - Coming Soon & Maintenance Plugin Broken Access Control Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match No login needed < 4.1.20 Fixed in 4.1.20 CVE-2026-13413 WPScan
4.3 Medium WP Mail Logging Plugin wp-mail-logging Content Injection Unauthenticated HTML Injection No login needed < 1.17.0 Fixed in 1.17.0 CVE-2026-1661 WPScan
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter No login needed ≤ 1.8.28 CVE-2026-102565 Wordfence
6.1 Medium Giveaways and Contests by RafflePress Plugin rafflepress Open Redirect Unauthenticated Stored Open Redirect via 'parent_url' Parameter No login needed < 1.12.27 Fixed in 1.12.27 CVE-2026-97318 WPScan
5.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Information Disclosure Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page No login needed < 1.12.27 Fixed in 1.12.27 CVE-2026-97317 WPScan
6.2 Medium BuildKit Plugin woo-product-builder SQL Injection Contributor+ Stored SQLi via list_content Parameter < 1.0.29 Fixed in 1.0.29 CVE-2026-94298 WPScan
7.5 High OMGF Plugin host-webfonts-local Denial of Service Unauthenticated DoS via do_optimize No login needed < 6.3.11 Fixed in 6.3.11 CVE-2026-91828 WPScan
3.1 Low Motors – Car Dealership & Classified Listings Plugin Broken Access Control Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured < 1.4.124 Fixed in 1.4.124 CVE-2026-91023 WPScan
6.8 Medium Motors Plugin motors-car-dealership-classified-listings Cross-Site Scripting Listing Manager+ Stored XSS via Badge Color < 1.4.124 Fixed in 1.4.124 CVE-2026-91022 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only