WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
5.4 Medium AffiliateX Plugin affiliatex Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2026-65558 Patchstack
7.2 High 3D Flipbook PDF Viewer & Embedder Plugin pdf-embed-viewer Server-Side Request Forgery No login needed ≤ 1.4.2 Fixed in 1.4.4 CVE-2026-59552 Patchstack
8.6 High Printcart Web to Print Product Designer for WooCommerce Plugin Path Traversal Unauthenticated Arbitrary File Read and Server-Side Request Forgery No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-15662 WPScan
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Price Manipulation Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery No login needed < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12688 WPScan
8.8 High WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) Plugin wpo365-login Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update No login needed ≤ 43.2 CVE-2026-15212 Wordfence
7.1 High MailPoet Plugin mailpoet Cross-Site Request Forgery No login needed 5.30.0 – 5.33.0 Fixed in 5.33.1 CVE-2026-57626 Patchstack
7.1 High Popup for CF7 with Sweet Alert Plugin cf7-sweet-alert-popup Cross-Site Request Forgery No login needed ≤ 1.6.5 CVE-2026-65540 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Request Forgery No login needed ≤ 4.4.5 CVE-2026-65536 Patchstack
7.2 High PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Server-Side Request Forgery No login needed ≤ 2.2.6 CVE-2026-65516 Patchstack
5.4 Medium WP Activity Log Plugin wp-security-audit-log Cross-Site Request Forgery No login needed ≤ 5.6.4 Fixed in 5.6.5 CVE-2026-65512 Patchstack
4.4 Medium Complianz Plugin complianz-gdpr Server-Side Request Forgery ≤ 7.5.0 CVE-2026-65496 Patchstack
7.1 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65488 Patchstack
9.6 Critical Avada Core Plugin fusion-core Cross-Site Request Forgery No login needed ≤ 5.15.6 Fixed in 5.15.7 CVE-2026-65471 Patchstack
4.9 Medium JetEngine Plugin jet-engine Server-Side Request Forgery ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-65467 Patchstack
4.9 Medium JetBooking Plugin jet-booking Server-Side Request Forgery ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65466 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65464 Patchstack
4.3 Medium Zarinpal Gateway Plugin zarinpal-woocommerce-payment-gateway Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65460 Patchstack
5.4 Medium Simple Link Directory Pro Plugin simple-link-directory-pro Cross-Site Request Forgery No login needed ≤ 15.0.8 Fixed in 15.0.9 CVE-2026-61981 Patchstack
8.8 High ApusListing Theme apuslisting Cross-Site Request Forgery No login needed ≤ 1.2.63 Fixed in 1.2.64 CVE-2026-57785 Patchstack
9.6 Critical Ninja Forms File Uploads Extension Plugin ninja-forms-uploads Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed ≤ 3.3.26 CVE-2026-57784 Patchstack
4.4 Medium Photo Block Plugin photo-block Server-Side Request Forgery ≤ 1.7.1 CVE-2026-24639 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Cross-Site Request Forgery No login needed ≤ 0.6.6 CVE-2026-24537 Patchstack
9.1 Critical Kirki Plugin kirki Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via kirki_get_apis No login needed < 6.0.12 Fixed in 6.0.12 CVE-2026-13147 WPScan
4.3 Medium W3SC Elementor to Zoho CRM Plugin w3sc-elementor-to-zoho Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.2.0 CVE-2026-9734 Wordfence
7.5 High PhonePe Payment Solutions Plugin phonepe-payment-solutions Price Manipulation Unauthenticated Payment Bypass via Forged Callback No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-11575 WPScan
9.8 Critical Bricksforge Plugin Privilege Escalation Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter No login needed ≤ 3.1.8.6 CVE-2026-14956 Wordfence
8.8 High Loco Translate Plugin loco-translate Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter No login needed ≤ 2.8.5 CVE-2026-15005 Wordfence
4.3 Medium Landing Page Builder Plugin page-builder-add Cross-Site Request Forgery Cross-Site Request Forgery to ulpb_admin_data AJAX Action No login needed ≤ 1.5.3.6 CVE-2026-12409 Wordfence
4.9 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Server-Side Request Forgery ≤ 5.0.4 Fixed in 5.0.5 CVE-2026-61970 Patchstack
7.1 High ووسلام – همگام سازی ووکامرس و باسلام Plugin sync-basalam Cross-Site Request Forgery همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-61956 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Broken Authentication No login needed ≤ 1.7.08 CVE-2026-57786 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
7.2 High PDF Generator Plugin pdf-generator-for-wp Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-57407 Patchstack
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.1 High SureCart Plugin surecart Privilege Escalation Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook No login needed ≤ 4.2.3 CVE-2026-7655 Wordfence
7.2 High Planyo online reservation system Plugin planyo-online-reservation-system Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter No login needed ≤ 3.0 CVE-2026-3576 Wordfence
4.3 Medium GoodMeet Plugin goodmeet Cross-Site Request Forgery Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential' No login needed ≤ 1.1.8 CVE-2026-6440 Wordfence
6.4 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter ≤ 4.8.5 CVE-2026-12123 Wordfence
8.8 High Salon Booking System Plugin salon-booking-system Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter No login needed ≤ 10.30.32 CVE-2026-15070 Wordfence
8.8 High Divi Torque Lite Plugin addons-for-divi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint No login needed ≤ 4.2.3 CVE-2026-4275 Wordfence
5.3 Medium WP Support Plus Responsive Ticket System Plugin Broken Access Control Unauthenticated Support Ticket Access via Session Cookie Forgery No login needed ≤ 9.1.2 CVE-2026-11875 WPScan
4.7 Medium Smash Balloon Social Photo Feed – Easy Social Feeds Plugin instagram-feed Cross-Site Request Forgery Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter No login needed ≤ 6.11.1 CVE-2026-12002 Wordfence
4.3 Medium Wp Js Detect Plugin wp-js-detect Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.9 CVE-2026-9731 Wordfence
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
5.5 Medium WP Import Export Lite Plugin wp-import-export-lite Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter ≤ 3.9.30 CVE-2026-11397 Wordfence
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only