WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 101–150 of 1,023 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Themify Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action |
≤ 7.7.7 |
CVE-2026-15407 |
Wordfence | |
| 5.5 Medium | FunnelKit | Arbitrary File Deletion Admin+ Arbitrary File Deletion via Path Traversal in Template Importer |
< 3.15.0.6 Fixed in 3.15.0.6 |
CVE-2026-12979 |
WPScan | |
| 6.1 Medium | Header Footer Builder for Elementor | Cross-Site Scripting Contributor+ Stored XSS via Template Import No login needed |
< 1.2.1 Fixed in 1.2.1 |
CVE-2026-12869 |
WPScan | |
| 4.3 Medium | Landing Page Builder | Cross-Site Request Forgery Cross-Site Request Forgery to ulpb_admin_data AJAX Action No login needed |
≤ 1.5.3.6 |
CVE-2026-12409 |
Wordfence | |
| 6.4 Medium | Avada Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title |
≤ 3.15.5 |
CVE-2026-12536 |
Wordfence | |
| 6.5 Medium | Envision Page Builder | Cross-Site Scripting |
≤ 0.22 |
CVE-2026-57780 |
Patchstack | |
| 6.5 Medium | WooCommerce PDF Invoice Builder | Information Disclosure Sensitive Data Exposure |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2026-57393 |
Patchstack | |
| 6.5 Medium | Extra Product Options Builder for WooCommerce | Broken Access Control No login needed |
≤ 1.2.167 Fixed in 1.2.168 |
CVE-2026-57390 |
Patchstack | |
| 5.3 Medium | NEX-Forms | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action No login needed |
≤ 9.2.2 |
CVE-2026-9017 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Information Disclosure Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys No login needed |
≤ 4.0.11 |
CVE-2026-10865 |
Wordfence | |
| 6.4 Medium | Themify Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field |
≤ 7.7.6 |
CVE-2026-15096 |
Wordfence | |
| 6.4 Medium | Themify Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field |
≤ 7.7.6 |
CVE-2026-15097 |
Wordfence | |
| 6.5 Medium | KiviCare | SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder |
≤ 4.5.0 |
CVE-2026-15072 |
Wordfence | |
| 4.3 Medium | GW AI Website Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion |
≤ 1.0.1 |
CVE-2026-1946 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP – Page Builder Features | Broken Access Control Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication |
≤ 3.5.32 |
CVE-2026-15286 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes |
≤ 6.4.11 |
CVE-2026-15285 |
Wordfence | |
| 6.4 Medium | Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | Cross-Site Scripting Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode |
≤ 6.20.2 |
CVE-2025-14785 |
Wordfence | |
| 6.5 Medium | Livemesh Addons for WPBakery Page Builder | Cross-Site Scripting |
≤ 3.9.4 |
CVE-2026-57754 |
Patchstack | |
| 5.3 Medium | JetFormBuilder | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter No login needed |
≤ 3.6.3 |
CVE-2026-13459 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter |
≤ 5.0.8 |
CVE-2026-12090 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter |
≤ 5.0.8 |
CVE-2026-12110 |
Wordfence | |
| 6.4 Medium | Page Builder by SiteOrigin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter |
≤ 2.34.3 |
CVE-2026-13295 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request No login needed |
≤ 6.0.8.6 |
CVE-2026-9242 |
Wordfence | |
| 5.3 Medium | NEX-Forms | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class No login needed |
≤ 9.2.2 |
CVE-2026-12404 |
Wordfence | |
| 4.3 Medium | Bopo – WooCommerce Product Bundle Builder | Information Disclosure WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure |
≤ 1.1.6 Fixed in 1.2.0 |
CVE-2026-57664 |
Patchstack | |
| 6.5 Medium | Elementor Website Builder | Information Disclosure Sensitive Data Exposure |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2026-57619 |
Patchstack | |
| 6.4 Medium | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns | Cross-Site Scripting Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute |
≤ 6.1.4 |
CVE-2026-10833 |
Wordfence | |
| 5.9 Medium | Bricksable for Bricks Builder | Cross-Site Scripting |
≤ 1.6.83 Fixed in 1.6.84 |
CVE-2026-56009 |
Patchstack | |
| 6.8 Medium | JetFormBuilder | Privilege Escalation |
≤ 3.6.1 Fixed in 3.6.1.1 |
CVE-2026-54196 |
Patchstack | |
| 6.5 Medium | WPBakery Page Builder | Broken Access Control |
≤ 8.7.2 Fixed in 8.7.3 |
CVE-2026-45436 |
Patchstack | |
| 4.3 Medium | Bricks Builder | Broken Access Control |
≤ 2.1.4 Fixed in 2.2 |
CVE-2026-40723 |
Patchstack | |
| 5.4 Medium | Form Builder CP | Cross-Site Scripting Editor+ Stored XSS via form_structure |
< 1.2.47 Fixed in 1.2.47 |
CVE-2026-9278 |
WPScan | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block |
≤ 2.0.9 |
CVE-2026-3297 |
Wordfence | |
| 5.4 Medium | Contact Form & Lead Form Elementor Builder | Broken Access Control No login needed |
≤ 1.8.4 Fixed in 1.8.5 |
CVE-2023-25969 |
Patchstack | |
| 5.4 Medium | Popup Builder | Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting |
3.49 |
CVE-2019-25744 |
VulnCheck | |
| 5.4 Medium | Elementor Website Builder | Broken Access Control |
≤ 4.1.0 Fixed in 4.1.1 |
CVE-2026-49782 |
Patchstack | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter |
≤ 6.4.15 |
CVE-2026-9243 |
Wordfence | |
| 4.3 Medium | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending |
≤ 3.4.7 |
CVE-2026-4888 |
Wordfence | |
| 6.4 Medium | WPBakery Page Builder Addons by Livemesh | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.9.4 |
CVE-2026-3895 |
Wordfence | |
| 6.4 Medium | WPBakery Page Builder Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 3.9.4 |
CVE-2026-2030 |
Wordfence | |
| 6.4 Medium | Livemesh Addons for Beaver Builder | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Missing Authorization |
≤ 3.9.2 |
CVE-2026-3897 |
Wordfence | |
| 5.4 Medium | ShopLentor - WooCommerce Builder for Elementor & Gutenberg | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute |
≤ 3.3.8 |
CVE-2026-6287 |
Wordfence | |
| 4.3 Medium | Vedrixa Forms | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action |
≤ 1.1.1 |
CVE-2026-8692 |
Wordfence | |
| 6.4 Medium | Avada (Fusion) Builder | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 3.15.2 |
CVE-2026-1543 |
Wordfence | |
| 5.0 Medium | PDF for Elementor Forms + Drag And Drop Template Builder | Broken Access Control |
≤ 5.5.1 Fixed in 5.6.1 |
CVE-2026-45443 |
Patchstack | |
| 4.9 Medium | NEX-Forms – Ultimate Forms | SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter |
≤ 9.1.12 |
CVE-2026-7046 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode |
≤ 5.6.8 |
CVE-2026-3694 |
Wordfence | |
| 6.5 Medium | Taskbuilder – Project Management & Task Management Tool With Kanban Board | SQL Injection Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter |
≤ 5.0.6 |
CVE-2026-6225 |
Wordfence | |
| 6.5 Medium | Avada Builder | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter |
≤ 3.15.2 |
CVE-2026-4782 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed |
≤ 4.0.1 |
CVE-2025-14755 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.