WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR < 3.7.42 Fixed in 3.7.42 CVE-2026-81200 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Cancellation via IDOR < 8.5.5 Fixed in 8.5.5 CVE-2026-80311 WPScan
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
4.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Pending Email Change Cancellation via IDOR < 5.2.5 Fixed in 5.2.5 CVE-2026-79995 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-79615 WPScan
5.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Unauthenticated Refund Request Creation on Guest Orders No login needed 3.7.1 – < 3.8.2 Fixed in 3.8.2 CVE-2026-77701 WPScan
4.3 Medium Notifima Plugin woocommerce-product-stock-alert Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-78139 WPScan
4.3 Medium ShopApper Plugin Information Disclosure Subscriber+ Customer Data Disclosure via IDOR ≤ 0.4.62 CVE-2026-16568 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Modification via IDOR < 8.5.1 Fixed in 8.5.1 CVE-2026-77789 WPScan
4.3 Medium WP Project Manager Plugin Information Disclosure Subscriber+ User Activity Feed Disclosure via IDOR 2.2.0 – < 4.0.7 Fixed in 4.0.7 CVE-2026-74930 WPScan
5.4 Medium WP Project Manager Plugin Information Disclosure Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR < 4.0.7 Fixed in 4.0.7 CVE-2026-74929 WPScan
4.7 Medium Amelia Pro Plugin Broken Access Control Provider+ Arbitrary Provider Password Update via IDOR 9.0 – < 9.8 Fixed in 9.8 CVE-2026-14212 WPScan
5.3 Medium Fluent Boards Pro Plugin fluent-boards-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78278 Patchstack
2.7 Low Tutor LMS Plugin tutor Information Disclosure Instructor+ Cross-Instructor Private Course Disclosure via IDOR < 4.0.6 Fixed in 4.0.6 CVE-2026-14187 WPScan
2.7 Low Dokan Plugin Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount < 5.0.14 Fixed in 5.0.14 CVE-2026-16577 WPScan
6.5 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Arbitrary Media Attachment Read via IDOR < 4.5.4 Fixed in 4.5.4 CVE-2026-19417 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Cross-Patient Appointment Modification via IDOR No login needed < 4.5.4 Fixed in 4.5.4 CVE-2026-19416 WPScan
5.3 Medium YayCurrency Plugin yaycurrency Information Disclosure Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration No login needed < 3.3.5 Fixed in 3.3.5 CVE-2026-16058 WPScan
7.5 High User Verification Plugin Broken Access Control Unauthenticated Arbitrary Account Lockout via IDOR No login needed ≤ 2.0.47 CVE-2026-14861 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
4.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14196 WPScan
6.5 Medium Eventin Plugin wp-event-solution Broken Access Control Contributor+ Schedule Deletion and Modification via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13175 WPScan
7.2 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Speaker Account Deletion via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13174 WPScan
8.1 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13169 WPScan
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.7 CVE-2026-74009 Patchstack
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.19 CVE-2026-66651 Patchstack
4.3 Medium Modal Survey Plugin modal-survey Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2.2.3 CVE-2026-66634 Patchstack
5.7 Medium Manual Image Crop Plugin manual-image-crop Broken Access Control Subscriber+ Arbitrary Attachment Image Overwrite via IDOR < 1.15 Fixed in 1.15 CVE-2026-15384 WPScan
4.9 Medium WC Vendors Plugin wc-vendors SQL Injection Authenticated (Shop Manager+) SQL Injection via 'status' Parameter ≤ 2.7.0 CVE-2026-15351 Wordfence
6.5 Medium StoreEngine Plugin storeengine Path Traversal Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL ≤ 2.1.1 CVE-2026-15056 Wordfence
6.5 Medium Groundhogg Plugin groundhogg SQL Injection Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter ≤ 4.5.14 CVE-2026-18387 Wordfence
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66441 Patchstack
6.5 Medium Do Lasso Plugin lasso Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 358 CVE-2026-28155 Patchstack
3.7 Low Amelia Plugin Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed < 2.4.6 Fixed in 2.4.6 CVE-2026-14213 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Information Disclosure Subscriber+ Order Data Disclosure via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14858 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Update Modification via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14857 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Information Disclosure Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR < 4.5.2 Fixed in 4.5.2 CVE-2026-13612 WPScan
4.3 Medium Eventin Plugin wp-event-solution Information Disclosure Contributor+ Order Information Disclosure via IDOR 4.1.9 – < 4.1.20 Fixed in 4.1.20 CVE-2026-13177 WPScan
3.8 Low Amelia Pro Plugin Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR 9.0 – < 9.7 Fixed in 9.7 CVE-2026-14211 WPScan
5.4 Medium Hotel Booking Lite Plugin Broken Access Control Subscriber+ Customer Data Modification via IDOR < 6.2.3 Fixed in 6.2.3 CVE-2026-15238 WPScan
4.9 Medium CubeWP Framework Plugin cubewp-framework Information Disclosure Contributor+ Arbitrary Post and User Meta Disclosure via IDOR ≤ 1.1.30 CVE-2026-17018 WPScan
5.4 Medium Dokan Plugin Broken Access Control Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16574 WPScan
5.3 Medium WP Events Manager Plugin wp-events-manager Price Manipulation Unauthenticated Payment Bypass and Booking Status Update via IDOR No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-15148 WPScan
6.5 Medium MStore API Plugin mstore-api Information Disclosure Subscriber+ Order and Customer PII Disclosure via IDOR < 4.21.0 Fixed in 4.21.0 CVE-2026-16039 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR < 2.0.1 Fixed in 2.0.1 CVE-2026-15214 WPScan
5.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Unauthenticated Payment Bypass and Booking Confirmation via IDOR No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15147 WPScan
4.3 Medium Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66692 Patchstack
7.5 High Formidable Forms Signature Online Contract Automation Plugin forms-signature-formidable-online-contract-automation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-65523 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only